Consulting Module

Module 6 โ€” On-Premises AD & Endpoint Hardening

The cloud gets the headlines. Active Directory gets compromised. Most AD forests carry a decade of accumulated privilege, service accounts with passwords that predate the organisation's current security team, and group policies nobody dares to touch. This module fixes the kill chain in the on-premises layer.

What It Delivers

๐Ÿ—‚๏ธ

Full AD Identity Census

Every user, computer, service account, and admin group enumerated and assessed. Stale accounts (no logon in 90+ days), orphaned objects (owner departed), and service accounts with non-expiring passwords flagged. The privilege map you didn't know you had.

๐Ÿ”‘

Compromised Credential Audit

AD password hashes compared against known-breached credential databases (Elysium / Have I Been Pwned corpus). Accounts using passwords that appear in breach databases identified and forced to reset โ€” before an attacker uses them. This consistently surfaces accounts that have been silently compromised for months.

๐Ÿ”„

KRBTGT Rotation and Golden Ticket Invalidation

KRBTGT account rotated twice in sequence (required to invalidate any existing Kerberos tickets, including forged golden tickets). Procedure documented for future rotations. A non-rotated KRBTGT is a persistent attacker foothold that survives every other remediation you run.

๐Ÿ’ป

LAPS and Privileged Access Workstations

Local Administrator Password Solution deployed so every machine has a unique, rotating local admin password โ€” eliminating the lateral movement path of a shared local admin credential. PAW architecture designed for admin tasks to prevent credential theft from the workstations used to manage Tier 0 systems.

๐Ÿ“ก

Sysmon Deployment and Entra Connect Hardening

Sysmon deployed to endpoints for detailed process creation, network connection, and registry change logging โ€” the telemetry source that turns a security incident from "we don't know what happened" to "we have the full timeline." Entra Connect sync account permissions tightened and sync server isolated: the bridge between on-premises and cloud is a Tier 0 asset and must be protected as one.

The Hybrid Identity Risk

In a hybrid environment, the on-premises AD and the cloud tenant are linked. Compromise of the Entra Connect sync account โ€” a common, often overlooked target โ€” gives an attacker the ability to manipulate cloud identities from on-premises. The on-premises security posture is a cloud security question. This module treats it as one.

Scope and Prerequisites

Duration45โ€“60 days
EnvironmentOn-premises AD with or without hybrid M365
PrerequisitesDomain Admin access; Module 2 (Identity) for cloud-side alignment if hybrid
Natural follow-onModule 12 (T0 Asset Protection) for crown-jewel isolation; Module 13 (Privileged Access Architecture) for PAM

The cloud is only as secure as the AD behind it

Most kill chains pass through on-premises AD even when the target is cloud resources. Module 6 closes the path.