Active Directory Investigation
Active Directory Investigation playbook provides tools and guidance to investigate changes and manipulation in Active Directory containers, ACLs, Schema, and objects. This playbook uses a 3rd party tool provided by Microsoft to scan the Active Directory access list, trees, and objects. Additional investigative information is provided for manual investigation.
- Pack
- Active_Directory_Query
- Tasks
- 10
Commands used
- ad-disable-account
- setIncident