ACSC Guidance — Detecting and Mitigating Active Directory Compromises (September 2026 Update)
The ACSC released a September 2026 revision of Detecting and mitigating Active Directory compromises on 15 September 2026, updated with international partners. The revision covers 18 common Active Directory compromise techniques — for each, how an actor uses it, how to detect it and how to mitigate it — and adds two things: a new DCSync detection technique, and a new section on shadow credentials, the technique in which an actor with write access to an object's msDS-KeyCredentialLink attribute plants a public key that lets them authenticate as that account.
| Attribute | Detail |
|---|---|
| Publisher | ACSC (ASD) |
| Updated | 15 September 2026 (first published 26 September 2024) |
| Techniques covered | 18 |
| New in this revision | DCSync detection technique; shadow credentials section |
| Audience | Large organisations and infrastructure; small & medium business; government |
| Source | ACSC / cyber.gov.au — Tier 1/4 |
Why it lands now
Active Directory is the digital gatekeeper — it verifies users, manages permissions and enables single sign-on — so an actor who takes control of it can gain complete control of an enterprise network, frequently starting from the permissions already granted to standard users and escalating gradually by investigating the environment and discovering weaknesses. The revision arrived in the same week as the AI-orchestrated PaperCut campaign documented on this wiki, whose post-exploitation produced credential dumps and DCSync/NTDS.dit extraction. Organisations mapping their posture to ASD's Information Security Manual or the Essential Eight should treat the revised techniques as the current detection baseline.
Source
- Updated guidance on detecting and mitigating Active Directory compromises
- Detecting and mitigating Active Directory compromises (publication)
Related Pages
- Certighost Exploit Lets Low Privileged Ad Users Impersonate A Domain Controller — an AD attack chain ending in DCSync
- Ai Orchestrated Papercut Campaign Compromised 395 Organisations Most In Educatio — DCSync/NTDS.dit extraction in the same week
- Acsc Guidance Agentic Ai Harnesses The Layer Above The Model — the ACSC's other September guidance publication