top of page

CISA Warns of 17 Active Directory Attack Techniques as AI Expands Identity Risk

Sep 16
2 min read

The US Cybersecurity and Infrastructure Security Agency and five international cybersecurity agencies have released new guidance on securing Microsoft Active Directory, detailing 17 techniques attackers commonly use to compromise enterprise identity systems.


The threat list includes Kerberoasting, AS-REP Roasting, password spraying, DCSync, Golden Ticket attacks, certificate abuse and the exploitation of insecure delegation settings. None of these techniques is particularly novel. Their continued effectiveness, however, shows how legacy configurations and sprawling identity infrastructure continue to leave organizations exposed.


Microsoft Active Directory remains a central authentication and authorization system inside many enterprises. Compromising it can give an attacker access to privileged accounts, sensitive applications and connected infrastructure across an organization.


Craig Birch, principal technologist at identity resilience company Cayosoft, said the guidance highlights a persistent gap between understanding identity threats and eliminating the conditions that make them possible.


“The problem is not a lack of awareness, but rather that many organizations still have excessive privileges, legacy protocols, weak service account controls, misconfigured certificate services, delegation risks, and hidden attack paths sitting in production environments,” Birch said.


That risk is growing as companies deploy AI agents, automation tools and other non-human identities. These systems often receive broad permissions so they can access data, execute workflows and communicate with business applications. If attackers compromise one of those identities, they may be able to move through connected systems more quickly than a human intruder.


“What has changed is the blast radius,” Birch said. “As enterprises add AI agents, automation platforms, service accounts, certificates, and other non-human identities, a successful identity compromise can move faster, touch more systems, and become harder to contain.”


Birch argues that conventional identity security programs must expand beyond prevention into identity threat detection, response and recovery, sometimes called ITDR+R. That includes monitoring privileged access, certificate misuse, configuration drift and exploitable identity paths.


Recovery may prove the most consequential piece. Once attackers obtain domain-level control, defenders can no longer assume that accounts, policies or authentication infrastructure remain trustworthy.


“Organizations need a clean, isolated, and continuously validated standby Active Directory environment they can trust when production can no longer be trusted,” Birch said. “AD is still the ‘keys to the kingdom.’”


The techniques may be familiar, but AI-powered automation is making the consequences of an Active Directory compromise faster, broader and significantly more difficult to contain.

bottom of page