Hardening Library

Security research, tutorials, and product updates from the Retrievy team

Multi-cloud security, FortiGate hardening, AD/identity risk, and configuration drift. Written by operators for operators.

16 articles match
of 34 total
What Is Active Directory Tiering and Why Does My Business Need It?
Identity Security
20 min read

What Is Active Directory Tiering and Why Does My Business Need It?

Most Active Directory environments have a tiering diagram in a compliance binder and no enforcement in production. Here's why the gap persists, and why verification after project close matters more than the initial design.

N
Ney Gelbcke Junior
Read Now
Active Directory Security Groups: What Operators Need to Know
Articles
4 min read

Active Directory Security Groups: What Operators Need to Know

Security groups are the primary access-control primitive in Active Directory, and misconfigured membership is one of the most reliable paths to privilege escalation. Here is what operators need to audit right now.

R
Retrievy Team
Read Now
Kerberoasting in 2026: Why This Attack Still Works on Your AD
Threat Intel
2 min read

Kerberoasting in 2026: Why This Attack Still Works on Your AD

Kerberoasting persists because most environments still have SPN-mapped service accounts with RC4 enabled and passwords that have not rotated in years. Here is what continuous ISPM monitoring catches and what good looks like.

R
Retrievy Team
Read Now
Domain Controller Hardening: The Seven Settings That Matter Most
Articles
4 min read

Domain Controller Hardening: The Seven Settings That Matter Most

A quarterly DC review checklist covering LDAP signing, channel binding, SMB signing, SMB v1, NTLM auditing, restricted RPC, and DCSync delegation hygiene. Each item shows what bad looks like, what good looks like, and why it matters.

R
Retrievy Team
Read Now
Active Directory Security Audit Tool: From Configured to Applied
Articles
5 min read

Active Directory Security Audit Tool: From Configured to Applied

An Active Directory security audit tool can prove a GPO exists. It cannot, on its own, prove the policy is being applied to the machines that need it. That gap is where most domains quietly stop being defensible, regardless of how clean the audit looks.

N
Ney Gelbcke Junior
Read Now