Authorized Security Lab

Active Directory Security Lab

Practice authorized AD visibility, hardening and detection.

This lab documents activity performed in an authorized environment.

Environment

Windows Server domain controller, Windows clients and SIEM agenting.

Architecture

Domain telemetry to SIEM with identity and endpoint-focused detection.

Tools

Active Directory, Windows Server, Sysmon, Wazuh

Configuration

Centralize security event logs and use least privilege.

Attack Simulation

Only controlled tests on owned lab systems.

Detection Method

Detect authentication anomalies and suspicious administrative behavior.

Investigation

Review event sequence and identity context.

Findings

Tune detection around privilege and authentication events.

Lessons Learned

Identity telemetry is critical for enterprise detection.