Case 02B90B · Identity & AD · L3 Applied
New Domain Admin at 2am
Practise as: Incident drill
Live alertSIEM alert: event 4728 shows svc_backup was added to Domain Admins at 02:14 by a helpdesk account. No change ticket exists.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Confirm with 4728/4732/4756 and verify with the helpdesk account owner out of band; no ticket = treat as hostile
- Contain: remove membership, disable both accounts, reset passwords; existing TGTs live until expiry, so purge sessions and watch
- Investigate how the helpdesk account got that right: ACL abuse, delegated OU permissions, or credential theft
- Hunt what svc_backup did as DA: DC logons, new GPOs, DCSync (4662), new accounts or scheduled tasks
- If DA use is confirmed, escalate to full domain compromise response including krbtgt double reset
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.