Back to Intel

Intel Node

Containing a domain compromise: How predictive shielding shut down lateral movement

criticalransomware2026-04-17T14:51:01+00:00source excerpt
ransomwareapttradecraftwindowsidentity

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Domain compromise accelerates fast. Predictive shielding slowed it down. This real-world attack shows how exposure-based containment stopped credential abuse and broke the threat actor's momentum. The post Containing a domain compromise: How predictive shielding shut down lateral movement appeared first on Microsoft Security Blog .

In this article Predictive shielding overview Attack chain overview How predictive shielding changed the outcome MITRE ATT&CK® techniques observed Learn more In identity-based attack campaigns, any initial access activity can turn an already serious intrusion into a critical incident once it allows a threat actor to obtain domain-administration rights. At that point, the attacker effectively controls the Active Directory domain: they can change group memberships and Access Control Lists (ACLs), mint Kerberos tickets, replicate directory secrets, and push policy through mechanisms like Group Policy Objects (GPOs), among others.

Read Original Source