Domain dominance: persistence after Domain Admin

Reaching Domain Admin is a milestone, not the finish line. Domain dominance is the tradecraft of staying in - surviving password resets, re-imaging, and incident response - by capturing key material that outlives any single account. Understanding these is as much a defender’s job as an operator’s, because each one changes what “contained” has to mean.

The persistence primitives

Why they’re hard to evict

Every one of these captures something structural - a domain-wide key, a replication right, a CA - rather than an account. Reset the obvious credentials and the foothold remains. That’s why real remediation after a DA compromise is heavy: rotate krbtgt twice, audit and revoke replication rights, treat the CA as compromised, and in the worst cases rebuild trust from a known-good state.

What to watch

Assume the keys, then verify visibility. Dominance is only durable against a defender who doesn’t know these exist.