
Shadow Credentials: Abusing msDS-KeyCredentialLink in Active Directory
Shadow Credentials abuse msDS-KeyCredentialLink to create a key-based authentication path in Active Directory. Learn the mechanics, detection, remediation, and validation steps.
Expert insights on Active Directory and Azure security vulnerabilities, hardening guides, and remediation best practices.
Explore detailed pages for Active Directory, Entra ID, ETC Collector deployment, and side-by-side product comparisons.
Review the landing page focused on Tier 0, Kerberos, delegation, ADCS, and remediation priorities.
See the Entra ID page covering Conditional Access, MFA, PIM, app permissions, and guest exposure.
Compare PingCastle with ETC Collector for recurring AD audits and standalone collection workflows.
Compare Purple Knight with ETC Collector for AD plus Entra ID reviews and recurring follow-up.
Review ETC Collector, its local deployment modes, and how teams run standalone or recurring audits.