Almost every enterprise intrusion of any size runs through identity at some point, and in a Windows shop that means Active Directory and its cloud extension, Entra ID. The posts here work through the attack paths that matter in practice, Kerberos ticket abuse, delegation, DCSync and Golden SAML, OAuth consent phishing, and pair each with the detection logic and hardening that actually closes it rather than a generic checklist. They assume you run this environment and need to defend it on Monday.
3 posts in this topic
Weaponizing OAuth Misconfigurations: How Attackers Abuse Trust to Bypass Security Controls
How attackers weaponise OAuth: consent phishing, device-code abuse, refresh-token persistence, and BEC, with SIEM detections and hardening for each.
Kerberos Abuse in Active Directory: Attacks, Detection & Hardening
Kerberoasting, AS-REP roasting, Golden and Silver Tickets, and delegation abuse in Active Directory, with the commands, detections, and hardening for each.
Active Directory Security in Hybrid Enterprise Environments: Attacks, Detection & Hardening
Securing hybrid Active Directory and Entra ID: Kerberoasting, DCSync, Golden SAML, and token theft, with the commands, detections, and hardening for each.