Security1 publisher2 min readPublished
Six agencies in five countries name the 17 most common Active Directory attacks
Australia's ASD ACSC wrote the guidance with CISA, the NSA, Canada's CCCS and the British and New Zealand cyber centres, pairing the 17 most common Active Directory compromise techniques with mitigations.
The Watch · Security desk

What happened
- A joint government guide sets out recommended mitigation strategies for the 17 most common techniques adversaries use to compromise Active Directory.
- Australia's ASD ACSC developed it in cooperation with CISA and the NSA in the United States, Canada's CCCS, NCSC-UK and NCSC-NZ.
- CISA rates the document as moderate in technical complexity and says it assumes only a basic understanding of cyber security.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Deferred domain hardening now has to be decided item by item: fix it, compensate for it, or write down an accepted risk against a technique six agencies named.
- capability A funding request can cite a scope authored outside the organisation and outside any vendor, which moves the internal argument to how many of the 17 items get money this year.
- exposure The attacker-path descriptions are published in the same document, so an intruder planning against a domain works from the defender's list too.
- constraint With the guide pitched at basic security knowledge, an organisation has a harder time arguing it needs specialist consultants before it can even read the list.
Six agencies across five countries put their names to the same list, and the United States is the only country that sent two of them [1][2]. That is authority an operator can use. The deliverable is mitigation strategies [1].
CISA describes the guide as moderate in technical complexity and says it assumes a basic understanding of cyber security [5]. The complexity label matters as much as the content: it puts the guide in reach of whoever holds Domain Admin day to day.
The guidance also describes how the techniques can be leveraged by malicious actors [4]. That is the half that gets used after an intrusion, because an item written that way can be matched against what a responder actually saw in domain controller logs.
In my experience, Active Directory hardening requests do not fail on principle. They fail because the scope has no edge and the owner cannot say when the work is finished. Seventeen named techniques give it an edge, and the mitigations are enumerated per technique [1].
The page does not name the 17 techniques, and "most common" is the agencies' own characterisation of them [1]. That ranking comes from five countries' incident response practice. The guide is only as good as the case work behind it, and the document summary leaves that case work out.
The guide sits on CISA's public resources site [6]. The attacker-path descriptions inside it are public on the same terms [4].
What to watch
- Whether the agencies follow the guide with detection artifacts or log queries mapped to each of the 17 techniques.
- Whether NCSC-UK or CCCS issue country-specific versions that set remediation timelines for regulated sectors.
- Whether any of the six agencies publishes the incident data behind the claim that these 17 techniques are the most common.