Look for a chain, not a single alert. Suspicious signs include web shell activity, remote shell use, credential dumping, Restricted Admin mode being enabled, unexpected RDP from server accounts, and access to NTDS.dit. Missing or truncated application logs are also important. Together, these signals suggest the attacker has moved from foothold to domain-level control and is harvesting credentials for further spread.
From foothold to domain compromise: what changes in the attacker’s behaviour?
The key shift is that the intruder stops behaving like a single-host intruder and starts behaving like an identity thief and a domain administrator. At this stage, you are looking for actions that create durable control, especially credential access, reuse across hosts, and movement from an initial access path into systems that can expose directory data, authentication material, or broad administrative reach.
That is why the most useful signs are not isolated anomalies. A web shell, remote shell use, credential dumping, RDP from unusual accounts, or access to directory database files all point to an attacker building the ability to authenticate elsewhere, not just maintaining a beachhead on one machine.
One useful lens is to ask whether the activity increases the attacker’s blast radius. If the answer is yes, for example because the account can pivot into other servers, dump more secrets, or reach domain data, the incident has likely moved beyond simple compromise and into domain-level control.
Which signals most strongly suggest domain-level control?
The strongest indicators usually cluster around authentication abuse, directory access, and lateral movement. Web shells and remote shells matter because they give the attacker repeatable execution. Credential dumping matters because it often precedes reuse of admin or service credentials. Restricted Admin mode, unexpected RDP from server accounts, and access to Cisco Yanluowang breach 2022 style patterns are especially concerning when they appear together, because they suggest the attacker is using trusted paths to move laterally and reach higher-value identities.
Access to NTDS.dit is a particularly serious marker because it usually implies the attacker has reached a point where domain credential material is available. That is not a generic compromise symptom, it is a sign that the adversary may be able to harvest the directory secrets needed to impersonate users, pivot into privileged systems, and persist after the initial foothold is removed.
Missing or truncated logs are also meaningful. When logging suddenly degrades at the same time as remote execution or credential access, it often means the attacker is trying to hide the path from foothold to domain control. In practice, the best signal is the combination: execution plus credential access plus reduced visibility.
Why the pattern matters more than any single alert
A single alert can be noisy. A chain of related activity is what tells you the intruder has probably crossed the line from opportunistic access to controlled intrusion. For example, remote shell activity on one host, followed by credential dumping, then unexpected administrative logon paths, and finally access to domain database material, is a coherent compromise sequence rather than a disconnected set of issues.
This is why attack-chain context matters. MITRE ATT&CK Enterprise Matrix is useful here because it lets analysts map what they see to credential access, lateral movement, and privilege escalation techniques instead of treating each event as an isolated incident. The same chain often explains why the attacker can keep re-entering the environment even after obvious endpoints are cleaned up.
The operational question is whether the actor has found a path to reusable access. If the answer is yes, the incident should be treated as a domain compromise candidate, not just an endpoint event. That changes the response posture because the attacker may already have the means to re-authenticate from a different machine or account.
Risk and Threat Considerations
Once an attacker can dump credentials or reach directory data, the risk shifts from local persistence to broad identity compromise. The main danger is that legitimate trust paths, not malware alone, become the attacker’s transport layer, which makes detection harder and remediation more expensive.
Failure mechanism: The attacker abuses a foothold to collect reusable secrets or directory material, then uses trusted remote access methods and compromised accounts to blend into normal administration.
Impact: The domain may be treated as compromised even if only one initial host was identified, because the attacker can impersonate users, move laterally, and return after partial cleanup.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1003 — OS Credential Dumping | Credential dumping is a primary sign of post-access escalation and domain compromise. |
| T1021 — Remote Services | Unexpected RDP and remote shell use indicate trusted remote access abused for lateral movement. | |
| Recommendation — Map credential-dumping alerts to T1003 and hunt for follow-on lateral movement. Track unexpected remote service use as a lateral-movement indicator and isolate the source host. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Review, Analysis, and Reporting | Truncated logs and correlated events require audit review to confirm the attack chain. |
| Recommendation — Review audit records across hosts and accounts to reconstruct the intrusion sequence. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Missing or truncated logs are a direct control failure when domain compromise is suspected. |
| Recommendation — Protect centralized logs and alert on gaps that coincide with suspicious execution or credential access. | ||
| ISO/IEC 27001:2022 | A.8.15 — Logging | Logging integrity is central when attackers erase traces during escalation. |
| Recommendation — Preserve and monitor logs so log loss itself becomes a high-confidence incident signal. | ||
Practitioner Guidance
What to prioritise: Correlate shell activity, credential access, admin logons, and directory database access in one timeline before deciding whether the event is isolated. A single indicator is rarely enough; the escalation decision should be based on the sequence.
What to verify: Check whether the accounts involved could reach privileged hosts, whether remote access came from unusual source systems, and whether log gaps line up with the suspected intrusion window. If the attacker touched NTDS.dit or equivalent directory data, assume credential exposure until disproven.
Practitioner takeaway: The clearest boundary is not “malware present” versus “no malware,” but whether the attacker has obtained reusable trust, because reusable trust is what turns an intrusion into a domain compromise.
Related resources from NHI Mgmt Group
- What are the signs that an intruder is moving from initial access into lateral movement on enterprise networks?
- What are the signs that Active Directory attack activity is moving from initial access to wider compromise?
- What happens when attackers use compromised identity or access paths to move from initial access to deeper compromise?
- What are the signs that an attacker is expanding access after the first compromise?