Domain-level access you cannot account for
The hardest response to pace correctly. Acting too early tells the operator you are there and achieves nothing durable; acting too late means rebuilding. Scope first, then act once, completely.
090 min180
- 01
Establish scope before changing anything
by 30 minDirectory changes on every domain controller rather than one, recent additions to privileged groups, accounts that acquired service principal names, and replication requests from anything that is not a domain controller.
- 02
Find the path in, not just the account
by 60 minA domain admin is an outcome. The question is which workstation or service account it came from, because that is the thing that still works after you reset the account.