Evading Microsoft Defender for Identity: Red Team Tradecraft for Active Directory Attacks

Evading Microsoft Defender for Identity: Red Team Tradecraft for Active Directory Attacks

Source: YouTube · Altered Security · published Jul 6, 2026 · 1:28:21

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

This webinar covers red team tradecraft for evading Microsoft Defender for Identity (MDI), emphasizing that operational security extends well beyond just EDR evasion 33:05. MDI detects identity attacks primarily through behavioral anomaly detection and by flagging inherently suspicious activities, such as DCSync requests from non-DC machines 13:01.

Key Takeaways:
Adopt the right mindset: Avoid unnecessary communication with Domain Controllers and abandon the "domain admin before lunch" mentality, as targeting high-privilege accounts inherently triggers heavy scrutiny 36:56.
Evade enumeration alerts: Use the AD module or PowerView instead of SharpHound or SharpUp. Be aware that SharpHound's ExcludeDCs flag has a known bug that still triggers session enumeration alerts on the DC 43:22.
Conduct stealthy Kerberoasting: Instead of recklessly requesting tickets for all service accounts (which triggers MDI), manually enumerate a target using LDAP and request a single service ticket at a time 54:50.
Avoid credential portability: Using extracted TGTs or certificates from a new machine triggers Overpass-the-Hash alerts. Stay on the originally compromised machine and use token impersonation instead 58:12.
Leverage Silver Tickets for domain dominance: Forging a Golden Ticket is now detected regardless of the target user, but Silver Tickets remain undetected. Crafting a Silver Ticket for the DC's machine account allows you to execute DCSync without generating an alert 1:17:38.

The core takeaway is that avoiding recklessness and understanding how your tools interact with the DC is the most effective way to bypass MDI, though researchers should note these findings are primarily lab-validated 1:26:27.

Sources:

  • 33:05 Introduction to MDI evasion mindset beyond EDR
  • 36:56 Avoiding domain admins and DC communication
  • 43:22 SharpHound ExcludeDCs bug and AD module usage
  • 54:50 Stealthy Kerberoasting tradecraft
  • 58:12 Overpass-the-Hash detection limitations
  • 1:17:38 Using Silver Tickets to bypass DCSync alerts

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hi, everyone. Welcome. Welcome to hacker Summer 2026. This is the first webinar
in the series of webinars that we are going to do this month. And we are going to talk about
evading MDI, red team tradecraft for area tags. Support me. You can find me on Twitter. I'm Nicole underscore double T there. I'm the founder of Altered Security. We are an attack with laser
focus on breaking Microsoft technologies. You can find me on GitHub. I'm the creator of. And a few more tools for red teammates and of course interested
in Active Directory security. Offensive PowerShell, Azure Red team. I've been playing a lot with the. Copilot red teaming, I would say not. I mean it is a huge field now, but
me and my team, we have been playing a lot with AI in Microsoft's ecosystem,
so probably soon you will also …