Goal
Ship dart_playbook/identity-centric-v1.yaml for AD-centric attacks
where the entire kill chain pivots on identity primitives.
Why specialized
Classic AD attack chains (per Sean Metcalf, adsecurity.org):
AS-REP Roasting (T1558.004)
↓
Kerberoasting (T1558.003)
↓
LSASS dump via comsvcs.dll (T1003.001) ← BlackSuit / Akira
↓
Pass-the-Hash / Pass-the-Ticket (T1550)
↓
Golden Ticket (T1558.001) for persistence
↓
Domain dominance + recovery denial
senior-analyst-v2.yaml covers these techniques but doesn't
specialize the phase-2 timeline order around AD events specifically.
Reference
- Sean Metcalf — AD attack methodology
- The DFIR Report — BlackSuit + Akira chain analyses
- JPCERT/CC — Detecting Lateral Movement through Tracking Event Logs
- CISA AA24-109A (Akira advisory, Nov 2025)
Acceptance
Goal
Ship
dart_playbook/identity-centric-v1.yamlfor AD-centric attackswhere the entire kill chain pivots on identity primitives.
Why specialized
Classic AD attack chains (per Sean Metcalf, adsecurity.org):
AS-REP Roasting (T1558.004)
↓
Kerberoasting (T1558.003)
↓
LSASS dump via comsvcs.dll (T1003.001) ← BlackSuit / Akira
↓
Pass-the-Hash / Pass-the-Ticket (T1550)
↓
Golden Ticket (T1558.001) for persistence
↓
Domain dominance + recovery denial
senior-analyst-v2.yamlcovers these techniques but doesn'tspecialize the phase-2 timeline order around AD events specifically.
Reference
Acceptance