Detection Engineering
Active Directory
SIEM
Red/Blue Team
Multi-Stage Active Directory Attack Detection
A realistic AD lab simulating a full Windows attack chain: Initial Access (Reverse Shell), Privilege Escalation (SeImpersonatePrivilege), Credential Dumping (LSASS), and Lateral Movement (Pass-the-Hash). Includes custom Sigma rules mapped to MITRE ATT&CK with full ELK implementation.
Sigma Rules
MITRE ATT&CK
ELK Stack
Sysmon
Pass-the-Hash
Lab Architecture
DC: Windows Server 2019/2022
Client: Windows 10/11
SIEM: Ubuntu + ELK Stack
Attacker: Ubuntu + Metasploit/Impacket
Attack Chain
1. Initial Access - Reverse Shell (T1059)
2. Privilege Escalation - SeImpersonate (T1134)
3. Credential Dumping - LSASS (T1003.001)
4. Lateral Movement - Pass-the-Hash (T1550.002)
Detection Rules
Reverse Shell Detection (Sysmon Event 3)
Privilege Escalation Detection (Sysmon Event 1)
LSASS Dump Detection (Sysmon Event 1, 11)
Pass-the-Hash Detection (Security Event 4624)
Key Outcomes
All 4 attack stages successfully detected
4 Custom Sigma Rules Created
100% MITRE ATT&CK Coverage
Windows Defender remained enabled