In this Skills 101 session, we walk through five built‑in capabilities within Change Auditor that are often overlooked but can significantly strengthen Active Directory and identity security. The session focuses on practical detections and protections that are already available in the product and demonstrates how attackers target common gaps when these features are left unused.
The video begins with a deep dive into protecting the Active Directory database, showing how attackers attempt to extract and exfiltrate NTDS.dit files, how Change Auditor detects this activity, and how database auditing and protection can prevent unauthorized access. A live demonstration highlights how to enable auditing, configure exclusions, and actively block malicious processes from accessing the database.
Next, the session covers Kerberos abuse techniques, including Service Principal Name (SPN) manipulation used in Kerberoasting and Golden Ticket–style attacks. You’ll see how SPN additions, removals, and policy changes are already audited by Change Auditor, how these events appear in the console, and why generating alerts for these changes is critical to early detection.
The presenter then introduces a consolidated way to monitor Tier 0 and privileged account activity, demonstrating how to create a single search and alert that captures high‑risk administrative actions across Active Directory. This approach reduces alert sprawl while increasing visibility into critical identity events.
Registry monitoring is also explored as a high‑signal persistence detection method. The video shows how to audit commonly abused registry keys related to autoruns, Winlogon, image file execution options (debugger abuse), and LSA injection—highlighting how these changes can indicate ransomware, backdoors, or credential theft attempts with minimal noise.
Finally, the session covers monitoring local user and group changes on member servers. Real‑world scenarios demonstrate how attackers establish persistence by creating local accounts or adding themselves to local administrator groups, and how Change Auditor captures these actions to expose lateral movement and unauthorized access.
This video is designed for Change Auditor customers who want to get more value from the platform by enabling features they already own, improving detection posture, and gaining clearer visibility into the most common identity‑based attack techniques targeting Active Directory environments.
To participate in our upcoming Skills 101 series, please visit: https://www.quest.com/skills-101-training/
Learn more about Change Auditor by visiting our official page: https://www.quest.com/change-auditor/