Seven graded decisions
- 1Alert triage · 10Which of the four alerts are real, and which one is your backup agent.
- 2Attack path · 15Read the exposure graph and pick the single edge with the least collateral damage.
- 3Hunt the directory · 10KQL over IdentityDirectoryEvents: prove who asked for replication data.
- 4Risky user remediation · 20Order matters: sessions and refresh tokens, then password, then re-registration.
- 5Detection coverage · 10Honeytoken, Lateral Movement path exemptions and what you deliberately do not exclude.
- 6Hardening the path · 20Kerberos, NTLM, delegation, Protected Users and the dMSA decision.
- 7Report & notify · 15What is known, what is not, and which clock is running.