Domain-level access you cannot account for

The hardest response to pace correctly. Acting too early tells the operator you are there and achieves nothing durable; acting too late means rebuilding. Scope first, then act once, completely.

Trigger. An unexplained Domain Admin, directory replication by something that is not a domain controller, or a ticket that does not match any authentication.

The first 180 minutes1 of 5 expire
090 min180
  1. 01

    Establish scope before changing anything

    by 30 min

    Directory changes on every domain controller rather than one, recent additions to privileged groups, accounts that acquired service principal names, and replication requests from anything that is not a domain controller.

  2. 02

    Find the path in, not just the account

    by 60 min

    A domain admin is an outcome. The question is which workstation or service account it came from, because that is the thing that still works after you reset the account.