CISA, Allies Catalog 17 Active Directory Attack Techniques
The updated multinational guidance signals that threat actors have converged on a common AD playbook, and the detection gaps being patched are ones Microsoft hasn't closed in the shipping product.
TL;DR
CISA and agencies from Australia, the UK, Canada, New Zealand, and the NSA updated joint guidance on detecting and mitigating Active Directory compromises, identifying 17 common threat techniques. The September 15 update expands the "Detecting DCSync" and "Shadow Credentials" sections with new detection and mitigation methods. The guidance targets permissive default settings, legacy protocol support, and diagnostic tooling gaps that make AD a high-value target. Identity administrators, security operations teams, and incident responders are urged to fold the recommendations into their defensive programs.

The guidance ("Detecting and Mitigating Active Directory Compromises") was first published in 2024 and last updated in January 2025. The fact that it's being revised again in September, with five allied intelligence and cybersecurity agencies now signed on, is itself a signal. Threat actors aren't merely targeting Active Directory; they've standardized how, and the coalition's defensive playbook is racing to catch up.
The document is blunt about why AD remains the weak point. "Active Directory is susceptible to compromise due to its permissive default settings, its complex relationships, and permissions; support for legacy protocols and a lack of tooling for diagnosing Active Directory security issues," the guidance states. That's not a new observation, but cataloging 17 discrete techniques that exploit those known weaknesses is. The update specifically expands the DCSync and Shadow Credentials sections, highlighting methods that let attackers gain access to Windows domain accounts while evading detection.
What the 17 techniques mean for defenders
Microsoft's Active Directory authenticates and authorizes users across roughly 90% of enterprise IT networks globally. It provides domain services, federation services, and certificate services, a sprawling attack surface. The guidance walks through detection events tied to each of the 17 techniques and prescribes mitigations, making it a practical checklist for identity administrators and security operations teams rather than a general advisory.
CISA's alert accompanying the update is directed squarely at practitioners: "stakeholders, particularly identity and directory service administrators, security operations teams, and incident responders" should review and incorporate the recommendations. The framing matters. This isn't an intelligence product aimed at CISOs. It's operational guidance for the people who configure domain controllers and tune SIEM rules.
The coalition's message
The NSA and cyber agencies from all Five Eyes nations (Australia, Canada, New Zealand, the United Kingdom, and the United States) have put their names on this document. That level of multinational alignment on Active Directory specifically is unusual and suggests the threat actor activity that prompted these updates was observed across allied networks in consistent patterns. The September 15 release doesn't disclose which intrusion or actor drove the revision, but the coalition's willingness to expand and reissue the guidance twice in under two years points to sustained adversary interest in AD as a primary target.
For organizations running on-premises or hybrid AD environments, the practical question is how long it takes to test and implement the mitigations across production systems, and whether the detection rules cover artifacts that may already exist in the directory from prior, undetected compromise.
Published ·Deep Fathom