Windows Server Active Directory: Offensive and Defensive Security Strategies

Active Directory (AD) is a critical component in enterprise IT, yet misconfigurations have led to severe real-world breaches through lateral movement, credential theft, and privilege escalation, highlighting the urgent need for improved AD security strategies. This research explores offensive and de...

وصف كامل

محفوظ في:
التفاصيل البيبلوغرافية
المؤلف الرئيسي: KHAN, ADIL (author)
منشور في: 2025
الموضوعات:
الوصول للمادة أونلاين:https://bspace.buid.ac.ae/handle/1234/3249
الوسوم: إضافة وسم
لا توجد وسوم, كن أول من يضع وسما على هذه التسجيلة!
_version_ 1862980610882011136
author KHAN, ADIL
author_facet KHAN, ADIL
author_role author
dc.contributor.none.fl_str_mv Dr Suleiman Yerima
dc.creator.none.fl_str_mv KHAN, ADIL
dc.date.none.fl_str_mv 2025-08-11T16:03:23Z
2025-06
dc.format.none.fl_str_mv application/pdf
dc.identifier.none.fl_str_mv 22002339
https://bspace.buid.ac.ae/handle/1234/3249
dc.language.none.fl_str_mv en
dc.publisher.none.fl_str_mv The British University in Dubai (BUiD)
dc.subject.none.fl_str_mv Windows Server
Active Directory
Cybersecurity
Penetration Testing
Defense
Offensive Security
Authentication
Group Policy
MITRE ATT&CK
dc.title.none.fl_str_mv Windows Server Active Directory: Offensive and Defensive Security Strategies
dc.type.none.fl_str_mv Dissertation
description Active Directory (AD) is a critical component in enterprise IT, yet misconfigurations have led to severe real-world breaches through lateral movement, credential theft, and privilege escalation, highlighting the urgent need for improved AD security strategies. This research explores offensive and defensive security approaches within Windows Server AD environments by simulating real-world cyberattacks and evaluating detection capabilities using modern monitoring tools. Unlike prior studies that often isolate theoretical attack techniques or passive defenses, this investigation adopts a practical, lab-based methodology in which offensive tools such as Mimikatz, BloodHound, PowerSploit, and Impacket are executed against deliberately misconfigured AD setups. The proposed defensive approach combines endpoint telemetry from Sysmon with centralized correlation and alerting through the Wazuh SIEM, complemented by Microsoft Defender Antivirus for baseline comparison. All telemetry is mapped to the MITRE ATT&CK framework for structured analysis. Each attack scenario is assessed for detection effectiveness and latency, revealing that while most attacks are identified within one to four seconds, stealthier techniques such as DCSync evade automated detection and are only observable through manual log inspection. The findings highlight the prevalence of AD misconfigurations—including excessive user privileges, weak service account protections, and inadequate Kerberos hardening—which enable credential theft and lateral movement. The study also emphasizes the importance of tuning detection rules, maintaining comprehensive log visibility, and integrating host-based and SIEM-level analytics to improve organizational preparedness. By addressing key gaps in existing literature—such as the lack of empirical simulations, limited benchmarking of detection latency, and insufficient MITRE ATT&CK alignment—this research offers an integrated framework and evidence-based guidance to strengthen enterprise resilience and inform AD security best practices.
id budr_ecf73cc5fad6e3e48949e88a0d836350
identifier_str_mv 22002339
language_invalid_str_mv en
network_acronym_str budr
network_name_str The British University in Dubai repository
oai_identifier_str oai:bspace.buid.ac.ae:1234/3249
publishDate 2025
publisher.none.fl_str_mv The British University in Dubai (BUiD)
repository.mail.fl_str_mv
repository.name.fl_str_mv
repository_id_str
spelling Windows Server Active Directory: Offensive and Defensive Security StrategiesKHAN, ADILWindows ServerActive DirectoryCybersecurityPenetration TestingDefenseOffensive SecurityAuthenticationGroup PolicyMITRE ATT&CKActive Directory (AD) is a critical component in enterprise IT, yet misconfigurations have led to severe real-world breaches through lateral movement, credential theft, and privilege escalation, highlighting the urgent need for improved AD security strategies. This research explores offensive and defensive security approaches within Windows Server AD environments by simulating real-world cyberattacks and evaluating detection capabilities using modern monitoring tools. Unlike prior studies that often isolate theoretical attack techniques or passive defenses, this investigation adopts a practical, lab-based methodology in which offensive tools such as Mimikatz, BloodHound, PowerSploit, and Impacket are executed against deliberately misconfigured AD setups. The proposed defensive approach combines endpoint telemetry from Sysmon with centralized correlation and alerting through the Wazuh SIEM, complemented by Microsoft Defender Antivirus for baseline comparison. All telemetry is mapped to the MITRE ATT&CK framework for structured analysis. Each attack scenario is assessed for detection effectiveness and latency, revealing that while most attacks are identified within one to four seconds, stealthier techniques such as DCSync evade automated detection and are only observable through manual log inspection. The findings highlight the prevalence of AD misconfigurations—including excessive user privileges, weak service account protections, and inadequate Kerberos hardening—which enable credential theft and lateral movement. The study also emphasizes the importance of tuning detection rules, maintaining comprehensive log visibility, and integrating host-based and SIEM-level analytics to improve organizational preparedness. By addressing key gaps in existing literature—such as the lack of empirical simulations, limited benchmarking of detection latency, and insufficient MITRE ATT&CK alignment—this research offers an integrated framework and evidence-based guidance to strengthen enterprise resilience and inform AD security best practices.The British University in Dubai (BUiD)Dr Suleiman Yerima2025-08-11T16:03:23Z2025-06Dissertationapplication/pdf22002339https://bspace.buid.ac.ae/handle/1234/3249enoai:bspace.buid.ac.ae:1234/32492025-08-11T16:03:51Z
spellingShingle Windows Server Active Directory: Offensive and Defensive Security Strategies
KHAN, ADIL
Windows Server
Active Directory
Cybersecurity
Penetration Testing
Defense
Offensive Security
Authentication
Group Policy
MITRE ATT&CK
title Windows Server Active Directory: Offensive and Defensive Security Strategies
title_full Windows Server Active Directory: Offensive and Defensive Security Strategies
title_fullStr Windows Server Active Directory: Offensive and Defensive Security Strategies
title_full_unstemmed Windows Server Active Directory: Offensive and Defensive Security Strategies
title_short Windows Server Active Directory: Offensive and Defensive Security Strategies
title_sort Windows Server Active Directory: Offensive and Defensive Security Strategies
topic Windows Server
Active Directory
Cybersecurity
Penetration Testing
Defense
Offensive Security
Authentication
Group Policy
MITRE ATT&CK
url https://bspace.buid.ac.ae/handle/1234/3249