Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-15 · updated: 2026-09-15 · tags: [incident, acsc, guidance, technique, australia, active-directory] · confidence: high · affected_sectors: [government, technology] · au_impact: true

ACSC Guidance — Detecting and Mitigating Active Directory Compromises (September 2026 Update)

The ACSC released a September 2026 revision of Detecting and mitigating Active Directory compromises on 15 September 2026, updated with international partners. The revision covers 18 common Active Directory compromise techniques — for each, how an actor uses it, how to detect it and how to mitigate it — and adds two things: a new DCSync detection technique, and a new section on shadow credentials, the technique in which an actor with write access to an object's msDS-KeyCredentialLink attribute plants a public key that lets them authenticate as that account.

Attribute Detail
Publisher ACSC (ASD)
Updated 15 September 2026 (first published 26 September 2024)
Techniques covered 18
New in this revision DCSync detection technique; shadow credentials section
Audience Large organisations and infrastructure; small & medium business; government
Source ACSC / cyber.gov.au — Tier 1/4

Why it lands now

Active Directory is the digital gatekeeper — it verifies users, manages permissions and enables single sign-on — so an actor who takes control of it can gain complete control of an enterprise network, frequently starting from the permissions already granted to standard users and escalating gradually by investigating the environment and discovering weaknesses. The revision arrived in the same week as the AI-orchestrated PaperCut campaign documented on this wiki, whose post-exploitation produced credential dumps and DCSync/NTDS.dit extraction. Organisations mapping their posture to ASD's Information Security Manual or the Essential Eight should treat the revised techniques as the current detection baseline.

Source

Related Pages