Incident response findings and large-scale Active Directory assessments show that attackers can often escalate from a low-privileged account to full domain compromise by chaining common identity weaknesses. Microsoft reported repeated cases of "total identity compromise" tied to excessive privilege, weak password policies, poor credential hygiene, insecure delegation, ACL abuse, Group Policy abuse, trust relationship weaknesses, and exposure of other Tier 0 assets. Separate analysis of 250 PingCastle reports found the same patterns at scale, including delegable administrator accounts, Kerberoast exposure, weak Kerberos encryption, dangerous Group Policy assignments, and exploitable Print Spooler configurations on domain controllers.
The assessments also highlighted persistent weaknesses in Active Directory Certificate Services (AD CS) and service account management. Research on Certified Pre-Owned and AD CS hardening showed that certificate template and enrollment misconfigurations can let attackers impersonate privileged users and gain durable access, while DFIR reporting found widespread service accounts with non-expiring passwords, excessive privileges, and Kerberoastable administrator accounts. Microsoft guidance points defenders toward continuous AD auditing with tools such as Defender for Identity, BloodHound, and PingCastle, along with privilege reduction, stronger authentication, hardened delegation and trust settings, and tighter governance of managed and legacy service accounts to close common escalation paths.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Microsoft published updated documentation describing how gMSAs and sMSAs work, including password management, deployment requirements, and the need to configure stronger Kerberos encryption such as AES for managed service accounts.
dfir.ch published the second part of its 250-report PingCastle analysis, documenting recurring weaknesses such as dangerous GPO-assigned privileges, delegable administrator accounts, weak Kerberos settings, Kerberoast exposure, and Print Spooler abuse paths on domain controllers.
dfir.ch published the first part of its analysis of 250 PingCastle reports, highlighting widespread AD CS misconfigurations, weak service-account governance, insecure password practices, incomplete PowerShell logging, and MachineAccountQuota abuse risk.
Microsoft Incident Response published guidance stating that most incident-response engagements involving on-premises Active Directory include total domain compromise, and outlined common escalation paths and defensive recommendations.
SpecterOps published the 'Certified Pre-Owned' whitepaper detailing attack techniques for abusing Active Directory Certificate Services and highlighting AD CS as a path to domain compromise.
Microsoft introduced group Managed Service Accounts (gMSAs) in Windows Server 2012, extending managed service account functionality across multiple servers in a domain with Windows-managed passwords.
Microsoft introduced standalone Managed Service Accounts (sMSAs) in Windows Server 2008 R2 and Windows 7, providing automatic password management and simplified SPN handling for services.
In one incident response investigation cited by dfir.ch, attackers attempted to exploit PrintNightmare (CVE-2021-34527), illustrating how Print Spooler exposure on domain controllers can support privilege escalation or remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
learn.microsoft.com
Open sourcedfir.ch
Open sourcedfir.ch
Open sourcetechcommunity.microsoft.com
Open sourcetechcommunity.microsoft.com
Open sourceposts.specterops.io
Open sourceservices.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.