Anatomy of a Silent Domain Takeover

Imported from official source

Cybersecurity Classified by Officially

Key Takeaways

  • Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint.
  • The evidence is already in the logs; what is missing is the narrative linking five benign-looking Windows events into a single attack.
  • A full domain takeover can be completed in 54 minutes, from the first password spray to the forged Golden Ticket, with each individual event appearing normal.
  • Detection catches the move; posture management explains why it was possible and what to fix. Neither layer alone stops a modern identity attack.
  • Qualys AD Real-Time Monitoring, the live detection engine inside Qualys Enterprise TruRisk Management (ETM) Identity, stamps every event with the identity, source Internet Protocol (IP), and Logon ID behind it, so one QQL pivot rebuilds the entire 54-minute path in a single view.
One password. Fifty-four minutes. Domain Admin. Every step used a legitimate protocol, so Active Directory (AD) Real-Time Monitoring stamps each alert with the identity behind it, and a QQL (Qualys Query Language) pivot rebuilds the entire path.

At 08:14, the attacker did not drop malware. They did not exploit a zero-day. They simply guessed one password that worked.

That is what makes modern Active Directory (AD) attacks so dangerous: every step appears to be normal Windows behavior. A failed login. A successful login. A Kerberos ticket request. A replication event. A service ticket with no obvious owner. Individually, each event can disappear into the noise. Together, they tell the story of a domain takeover.

The Rise of The Login-Based Breach

The attacker never had to be sophisticated, only patient enough to wait for a login prompt. That is why identity is now the battleground.

This is an extract. The publication continues at the source.

Read the original at the source: https://blog.qualys.com/product-tech/2026/09/02/anatomy-of-a-silent-domain-takeover-ad-real-time-monitoring

Officially imported this from Qualys’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Qualys — imported from official source
Official source
https://blog.qualys.com/feed RSS
Imported
September 20, 2026 19:52
Versions
1 recorded
Identity
https://blog.qualys.com/?p=42093

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.