Day 19/30 · DSRM persistence
Every DC has a second local admin teams forget: the DSRM account.
One registry change lets you Pass-the-Hash it onto the DC, access that survives a domain password reset.
🛡️ Defense: monitor DsrmAdminLogonBehavior, and rotate the DSRM password.
Day 18/30 · Diamond Ticket
Golden tickets are loud now.
A Diamond asks the DC for a real TGT, then rewrites its PAC with krbtgt's key.
It looks legitimately issued, because it is.
🛡️ Defense: baseline ticket lifetime and groups.
Anomalies inside a 'real' TGT are the tell.