Active Directory Protection & SIEM with Threat Prevention & Threat Manager

Overview

Implemented Netwrix Threat Prevention (formerly Stealth Intercept) for Active Directory security, and Netwrix Threat Manager as the SIEM. Configured playbooks and set preemptive actions against threats.

AD Threat Protection Architecture

Roles and Responsibilities

Deployment & Configuration

Security Hardening & Automation

Testing & Scenario-Based Verification

Threat Simulation

Simulated real-world AD attacks to validate detection and responses:

Documentation & Knowledge Transfer

Impact

Tools & Technologies used

Tools Platform
Operating Systems Windows Server 2019 & 2022
Database SQL Server 2019, PostgreSQL
Network simulator GNS3
Load Balancer SKUDONet & NGINX
Firewall pfSense 2.x
Replication VEEAM