In June we were the red team. In July we took the same lab and sat in the blue-team seat. Same environment, same attack chain, completely different lens — because the fastest way to learn detection is to watch an attack you already understand, from the other side of the keyboard.
This Cover6 Community session attacks an Active Directory lab on Cover6 infrastructure and watches the alerts fire in real time. Use this post as your read-ahead, then come back to it as a reference for the Event IDs and the detections.
Why AD is the prize
In most organizations, Active Directory is the keys to the kingdom. It decides who can log in where, who is an admin, and what every account is allowed to touch. That’s exactly why attackers go after it, and why a SOC analyst who can read AD logs is worth a great deal. The good news: almost everything an attacker does in AD leaves a trace in the Windows Security log. You just have to know which events to watch.
The Event IDs to know
You don’t need to memorize the whole catalog. A handful of Windows Security Event IDs carry most of the signal:
- 4624 — successful logon. The baseline. The Logon Type tells you how (interactive, network, remote desktop), which is half the story.
- 4625 — failed logon. Clusters of these are the classic brute-force signature.
- 4672 — special privileges assigned. An account just logged on with admin-level rights. Worth knowing every time it isn’t expected.
- 4720 — a user account was created. New accounts you didn’t provision are a red flag.
- 4768 / 4769 — Kerberos tickets. A TGT request (4768) and a service-ticket request (4769). These are the heart of Kerberoasting detection, below.
- 4688 — a process was created. Command-line auditing here is gold for spotting what actually ran.
- 4698 — a scheduled task was created. A common persistence move.
- 7045 — a service was installed. Another persistence favorite.
- 1102 — the audit log was cleared. Attackers covering their tracks. This one should always get attention.
Learn what normal looks like for each, and the abnormal starts to jump out.
Reading the attacks from the defender’s side
Three red-team techniques, seen from the blue-team seat:
- BloodHound attack paths. BloodHound maps the shortest route from a low-privilege account to Domain Admin. As a defender, the same map tells you which accounts and relationships are dangerous and worth watching — the choke points an attacker would aim for are the ones you harden and monitor first.
- Kerberoasting. An attacker requests service tickets (4769) for accounts with service principal names, then cracks them offline for the password. The detection signal: one account requesting a burst of service tickets, especially with weaker encryption types, in a short window. That pattern in your 4769 events is the tell.
- Golden Ticket. An attacker who has forged a Kerberos ticket-granting ticket can impersonate anyone. Indicators include tickets with anomalous lifetimes, logons that skip the normal TGT request, and account/domain mismatches in the ticket data. It’s subtle, which is exactly why knowing the indicators matters.
The theme: every one of these is loud if you’re listening on the right channel.
Work it in a live lab, free
Reading about AD detection is one thing; pulling these events in a real SIEM is another. First Watch gives you a live Splunk lab and your first SOC shift — free, in your browser, nothing to install. It’s the place to go hunt the patterns from this post for yourself.
👉 Start here, free: https://www.cover6solutions.com/product/cover6-first-watch-free-access/
Where this path leads
Active Directory forensics is core SOC Analyst work on Chrysalus. Build your free profile and add your First Watch investigation as a project.
- Read the SOC Analyst Roadmap 2026.
- Want the deeper version? The SOC Analyst Prep Labs take this from fundamentals to job-ready.
- Use the Cover6 Field Manual as a free reference, and browse every Cover6 course.
- Join The 6, our free newsletter, to catch the next session.
Watch the replay
We ran this live in the Cover6 Community — the same AD lab from June, attacked and then hunted in real time. Planning to attend a future meetup? Use this post as your read-ahead, and catch the replay above.
