Authorized Security Lab
Active Directory Security Lab
Practice authorized AD visibility, hardening and detection.
This lab documents activity performed in an authorized environment.
Environment
Windows Server domain controller, Windows clients and SIEM agenting.
Architecture
Domain telemetry to SIEM with identity and endpoint-focused detection.
Tools
Active Directory, Windows Server, Sysmon, Wazuh
Configuration
Centralize security event logs and use least privilege.
Attack Simulation
Only controlled tests on owned lab systems.
Detection Method
Detect authentication anomalies and suspicious administrative behavior.
Investigation
Review event sequence and identity context.
Findings
Tune detection around privilege and authentication events.
Lessons Learned
Identity telemetry is critical for enterprise detection.