Open cardosec

Case 02B90B · Identity & AD · L3 Applied

New Domain Admin at 2am

Practise as: Incident drill

Live alertSIEM alert: event 4728 shows svc_backup was added to Domain Admins at 02:14 by a helpdesk account. No change ticket exists.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Confirm with 4728/4732/4756 and verify with the helpdesk account owner out of band; no ticket = treat as hostile
  2. Contain: remove membership, disable both accounts, reset passwords; existing TGTs live until expiry, so purge sessions and watch
  3. Investigate how the helpdesk account got that right: ACL abuse, delegated OU permissions, or credential theft
  4. Hunt what svc_backup did as DA: DC logons, new GPOs, DCSync (4662), new accounts or scheduled tasks
  5. If DA use is confirmed, escalate to full domain compromise response including krbtgt double reset

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.