Active Directory Security Assessment: What to Check First
A working scope for an Active Directory security assessment, covering ADCS templates, Kerberoasting exposure, GPO drift, and the delegation chains attackers actually use.
Multi-cloud security, FortiGate hardening, AD/identity risk, and configuration drift. Written by operators for operators.
A working scope for an Active Directory security assessment, covering ADCS templates, Kerberoasting exposure, GPO drift, and the delegation chains attackers actually use.
Kerberoasting persists because most environments still have SPN-mapped service accounts with RC4 enabled and passwords that have not rotated in years. Here is what continuous ISPM monitoring catches and what good looks like.