Microsoft Defender for Identity
Microsoft Defender for Identity (MDI) is the cloud-powered behavioral detection platform for Active Directory. Its sensors sit on every DC, capture network traffic and Windows event logs, and feed a cloud ML backend that detects Kerberoasting, Pass-the-Hash, DCSync, Golden Tickets, and lateral movement. This covers sensor deployment, what alerts look like, detection quality, and how attackers attempt to evade it.
Members Only Content
This article is exclusively available to registered members of LazyHackers. Login or subscribe to read.