Phishing to Domain Admin
The canonical Active Directory attack path: a phishing foothold on a workstation, escalated through credential theft and Kerberos abuse to full domain dominance.
Scenario
An authorized red-team engagement with permission to phish a defined list of employees. The objective is to show how a single click can lead to Domain Admin, and where the blue team could have cut the chain.
- 1
Reconnaissance
Build a target list and pretext
Collect in-scope employee email addresses and public details to craft a believable, authorized phishing pretext and identify likely-vulnerable roles.
DetectionOSINT is largely invisible, but lookalike-domain registration and inbound reconnaissance to the mail gateway can be monitored.
MitigationSecurity-awareness training, DMARC/DKIM/SPF enforcement, and monitoring for newly registered lookalike domains.
- 2
Initial Access
Land code execution via phishing
Deliver the agreed phishing lure (attachment or link) to obtain execution on a user workstation, staying strictly within the approved target list and payload rules of engagement.
DetectionMail-gateway detonation, EDR on attachment/macro execution, and proxy logs for the delivery domain.
MitigationBlock risky attachment types, disable Office macros from the internet, use MFA, and sandbox links at the gateway.
- 3
Execution
Establish a stable agent
Convert the initial execution into a resilient command-and-control channel using the host's own scripting interpreter, with care to keep the agent in scope and recoverable.
DetectionScript-block logging, suspicious parent/child process trees, and beaconing patterns in network telemetry.
MitigationConstrained-language mode, application control (WDAC/AppLocker), and egress filtering with TLS inspection.
- 4
Credential Access
Harvest credentials from the first host
Recover cached credentials and tokens from the workstation to obtain a domain user context to work from.
DetectionLSASS access by non-system processes is a high-fidelity EDR alert; Credential Guard blocks the classic technique entirely.
MitigationEnable Credential Guard, run EDR with LSASS protection, and restrict local admin rights.
- 5
Discovery
Map the domain and find a path to privilege
T1087.002 Account Discovery: Domain AccountT1018 Remote System DiscoveryT1482 Domain Trust DiscoveryEnumerate users, groups, computers and trust relationships, then analyse the data to find the shortest path from the current principal to a high-value target.
DetectionLarge LDAP queries and SAMR enumeration from a workstation are detectable; honeypot objects catch indiscriminate collection.
MitigationTier the AD administration model, restrict LDAP reconnaissance, and deploy deceptive/honeytoken objects.
- 6
Credential Access
Crack a service account via Kerberoasting
Request service tickets for accounts with SPNs and crack them offline to recover a service-account password — often a route to higher privilege.
DetectionSpikes of Kerberos TGS requests (especially RC4) for many SPNs are a well-known hunting signal.
MitigationUse group-managed service accounts with long random passwords, enforce AES, and alert on bulk TGS requests.
- 7
Lateral Movement
Move to a privileged host
T1550.002 Use Alternate Authentication Material: Pass the HashT1550.003 Use Alternate Authentication Material: Pass the TicketT1021.006 Remote Services: Windows Remote ManagementReuse recovered hashes or tickets to authenticate to systems where the compromised account has rights, hopping toward a host where a Domain Admin is logged on.
DetectionAnomalous logon types, pass-the-hash patterns, and lateral authentication from a workstation to many hosts.
MitigationEnforce the AD tiering model, deny local-admin reuse (LAPS), and block workstation-to-workstation traffic.
- 8
Domain Dominance
Compromise the domain and establish persistence
With Domain Admin-equivalent rights, demonstrate replication of directory secrets and (where authorized) a forged ticket to prove durable control — then document everything for clean-up.
DetectionNon-DC hosts performing directory replication (DCSync) is a critical alert; golden-ticket anomalies show up with careful Kerberos logging.
MitigationRestrict replication rights, monitor for DCSync from non-DCs, and rotate the krbtgt account twice after any suspected compromise.
Key takeaways
- The path from a single phished user to Domain Admin is short on a flat, untiered AD.
- Credential Guard, AD tiering and LAPS individually break several links in this chain.
- Kerberoasting and DCSync are noisy if you are logging Kerberos and directory replication — instrument for them.