[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f12Pl8GqYf6R5Bk4k0uMFcsLy4yiJAGJjt5d1uvKWRqU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"a6dda3a0-4e6b-4db8-bb09-3ab4eb6dda45","identity-based-attacks-exploit-stolen-credentials-and-excessive-privileges","cb52ce27-82c1-49cd-ad0a-b6ebf0ec3892","Identity-Based Attacks Exploit Stolen Credentials and Excessive Privileges","Identity-based attacks such as Pass-the-Hash and Kerberoasting succeed primarily because organizations lack unified visibility into who has access to what, and which identities carry excessive or misconfigured privileges within Active Directory environments. Attackers leverage these gaps to move laterally and escalate privileges without triggering traditional security controls. The problem is compounded when identity posture is managed in silos, disconnected from asset context and exploitability data, making it difficult to prioritize the riskiest attack paths. Without continuous monitoring and correlation of identity risk signals, security teams are left reacting after compromise rather than preventing it.","**Immediate actions:**\n- Audit all Active Directory accounts to identify and remove excessive privileges, stale accounts, and misconfigured service principal names (SPNs) susceptible to Kerberoasting.\n- Enforce multi-factor authentication (MFA) across all privileged and remote-access accounts to reduce the impact of stolen credentials.\n- Deploy credential monitoring tools to detect use of compromised credentials in real time.\n\n**Long-term improvements:**\n- Implement a least-privilege access model with regular access reviews to ensure users and service accounts hold only the permissions required for their role.\n- Integrate identity posture management with asset context and vulnerability data to build a unified risk model that prioritizes high-impact attack paths.\n- Adopt Privileged Access Workstations (PAWs) and tiered administration models to limit lateral movement opportunities within Active Directory.\n\n**Detection measures:**\n- Enable detailed logging of authentication events, ticket-granting service (TGS) requests, and privilege escalation attempts across all domain controllers.\n- Configure SIEM alerting for anomalous identity behaviors such as unusual Kerberos ticket requests, credential spraying, and off-hours privileged access.\n- Conduct regular purple team exercises simulating Pass-the-Hash and Kerberoasting techniques to validate detection coverage and response playbooks.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 5 – Account Management","CIS Control 6 – Access Control Management","CIS Control 8 – Audit Log Management","NIST SP 800-53 AC-2 (Account Management)","NIST SP 800-53 AC-6 (Least Privilege)","NIST SP 800-53 IA-5 (Authenticator Management)","NIST SP 800-53 AU-12 (Audit Record Generation)","MITRE ATT&CK T1550.002 – Pass the Hash","MITRE ATT&CK T1558.003 – Kerberoasting","NIST CSF ID.AM-3 (Asset Management)","NIST CSF PR.AC-4 (Access Permissions and Authorizations)","published","2026-07-14T18:20:20.740618+00:00","2026-07-14T18:20:20.422+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fblog.qualys.com\u002Fproduct-tech\u002F2026\u002F07\u002F14\u002Fhow-qualys-etm-identity-detects-responds-to-identity-based-attacks","how-qualys-etm-identity-detects-identity-based-attacks-faster-ea4400","How Qualys ETM Identity Detects Identity-Based Attacks Faster",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":44,"name":45,"slug":46,"description":47,"color":48},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[]]