Applying targeted Tier-0 hygiene against the exact attack path used in Chapter 2: gMSA migration, AES-only Kerberos, password complexity, audit policy, and verifying the next attack iteration fails.
Each control here ties back to a specific finding from Chapter 2. The goal is not to fix everything in Active Directory — it is to close this attack path and prove the closure.
Drop screenshots into img/homelab/ch3/ with the filenames referenced below and they will appear here. Until then, placeholder tiles render in their place.
Results from running the same Chapter 2 attack against the hardened environment.