A reused credential provides a domain foothold
The attacker uses a credential recovered from an unrelated breach or a phishing lure that also works internally, gaining an authenticated position in Active Directory as a standard user.
Authenticate to the domain as a real, if low-privileged, user.
- MFA on all authentication surfaces, including internal ones where feasible
- Banned-password and breached-password screening
- Lockout and anomaly detection on authentication
- Authentication spikes or spraying patterns across many accounts
- Successful logon from an unusual host or time
- Sign-ins matching known-breached credential lists
- Password-spray and credential-reuse assessment
- Review of breached-password screening
- Test detection of spraying and anomalous logon
The attacker holds a legitimate domain identity to build on.