Documentation
README
AD OPSEC and Telemetry
Every technique leaves a trace. The goal here is not evasion. It is knowing the noise profile of each action so you can document it for the client before the engagement, pick the quieter of two functionally equivalent techniques, and correlate what you did with what their SOC saw. For a defender, read the same tables backwards: they are the events to monitor and alert on.
Two rules of engagement throughout:
- Document the noise. Tell the client what each high-signal action generated, with the event ID and the source IP, so they can find it in their logs.
- Coordinate the loud ones. DCSync, mass spraying, coercion at scale, and LSASS dumps need explicit client sign-off or an end-of-engagement window when detection no longer matters.
This is the opening of the README. Read the full README on GitHub.