Lesson 6/12
Mastering Active Directory auditing with AI: policies, logs and automation
Find out how to put AI to work on an advanced Active Directory audit. This video covers audit policies aligned with the ANSSI and CIS standards, log analysis, automation through PowerShell, and dealing with dormant administrator accounts.
☰
Contents
25
▾
0:00 A special introduction: using AI to audit Active Directory 0:37 Setting audit rules that meet the ANSSI and CIS standards 1:10 Which audits to run, in detail 3:03 Update cadence: the second Tuesday 3:38 Reading the audit policies and responding to attacks 4:41 Reactivating a dormant admin account / admincount 1 5:12 More on reading the audit policies 7:29 Creating the TEST-DC OU and a DC audit GPO 8:37 Delegating control on the OU 9:25 Increasing the size of the Windows EVTX logs 11:10 Setting user rights and managing the audit log 11:32 Configuring the audit policies, explained in detail 19:23 Replacing standard auditing with advanced auditing 20:27 Checking the audit settings applied on DC01 20:44 QWERTY and ASCII codes 21:57 Back to the verification 23:22 Tests: linking the GPO to the production controllers 26:49 Creating a user, and an audit script written by AI 27:38 Logging group changes 29:12 AI and PowerShell: where this goes in the cloud 30:08 Writing scripts for the logging 33:00 Changing the GPOs and auditing 34:22 Viewing and filtering the data 35:32 Matching it back to the GPO with AI 36:09 PowerShell explained: the switch statement and the full script