
Evading Microsoft Defender for Identity: Red Team Tradecraft for Active Directory Attacks
Source: YouTube · Altered Security · published Jul 6, 2026 · 1:28:21
This webinar covers red team tradecraft for evading Microsoft Defender for Identity (MDI), emphasizing that operational security extends well beyond just EDR evasion 33:05. MDI detects identity attacks primarily through behavioral anomaly detection and by flagging inherently suspicious activities, such as DCSync requests from non-DC machines 13:01.
Key Takeaways:
• Adopt the right mindset: Avoid unnecessary communication with Domain Controllers and abandon the "domain admin before lunch" mentality, as targeting high-privilege accounts inherently triggers heavy scrutiny 36:56.
• Evade enumeration alerts: Use the AD module or PowerView instead of SharpHound or SharpUp. Be aware that SharpHound's ExcludeDCs flag has a known bug that still triggers session enumeration alerts on the DC 43:22.
• Conduct stealthy Kerberoasting: Instead of recklessly requesting tickets for all service accounts (which triggers MDI), manually enumerate a target using LDAP and request a single service ticket at a time 54:50.
• Avoid credential portability: Using extracted TGTs or certificates from a new machine triggers Overpass-the-Hash alerts. Stay on the originally compromised machine and use token impersonation instead 58:12.
• Leverage Silver Tickets for domain dominance: Forging a Golden Ticket is now detected regardless of the target user, but Silver Tickets remain undetected. Crafting a Silver Ticket for the DC's machine account allows you to execute DCSync without generating an alert 1:17:38.
The core takeaway is that avoiding recklessness and understanding how your tools interact with the DC is the most effective way to bypass MDI, though researchers should note these findings are primarily lab-validated 1:26:27.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hi, everyone. Welcome. Welcome to hacker Summer 2026. This is the first webinar
in the series of webinars that we are going to do this month. And we are going to talk about
evading MDI, red team tradecraft for area tags. Support me. You can find me on Twitter. I'm Nicole underscore double T there. I'm the founder of Altered Security. We are an attack with laser
focus on breaking Microsoft technologies. You can find me on GitHub. I'm the creator of. And a few more tools for red teammates and of course interested
in Active Directory security. Offensive PowerShell, Azure Red team. I've been playing a lot with the. Copilot red teaming, I would say not. I mean it is a huge field now, but
me and my team, we have been playing a lot with AI in Microsoft's ecosystem,
so probably soon you will also …