Nullpath

AD Tiering & Hardening Baseline

concept active-directoryhardeningmitigations updated 13 Jun 2026 · 2 min

AD Tiering & Hardening Baseline

A set of architectural mitigations that recur across nearly every AD attack page in this wiki. None of these stop a single technique outright — they limit blast radius and make credential theft less likely to escalate to domain compromise.

The controls

Takeaway

Almost every technique in this wiki is mitigated by some combination of: don’t let weak/crackable secrets exist (gMSA, AES, password policy) + don’t let a low-tier compromise reach high-tier credentials (tiering, PAWs, Protected Users, Credential Guard, LAPS) + detect anomalous use of legitimate protocols (honeytokens, 4768/4769 correlation, RC4 downgrade monitoring).