logo

25 Years On, Active Directory Is Still a Prime Attack Target

ID: d98afdab-fc27-5f60-b1b9-ff2336019322

STIX ID: report--d98afdab-fc27-5f60-b1b9-ff2336019322

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-02-24

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Active Directory remains a high-value target: the report surveys evolving AD attack methods — credential theft, lateral movement, privilege escalation, AD CS misconfiguration abuse (ESC1/ESC4), NTLM relay attacks like PetitPotam, and hybrid cloud pivoting via Entra ID/Azure AD Connect — notes adversaries are automating reconnaissance and using living-off-the-land and token/OAuth abuse, and recommends stronger passwords/passphrases, MFA, disabling outdated protocols, continuous AD monitoring, immutable off-network backups, tested recovery plans, and incremental identity modernization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.