Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Active Directory - Advanced Auditing
Rating: 4.7 out of 5(5 ratings)
244 students

Active Directory - Advanced Auditing

Active Directory, Windows Infrastructure, Advanced Audit Policy
Created byDavid Horák
Last updated 11/2025
English
English [Auto],

What you'll learn

  • Configure Advanced Audit Policy to log meaningful Windows & AD events
  • Use Sysmon with a real-world configuration baseline
  • Validate logs and reduce noise using practical techniques
  • Understand auditing strategy with ThreatLog — a custom tool to generate optimized baselines
  • By the end, you'll know what to log, how to tune it, and how to spot real threats without wasting SIEM budget or resources.

Course content

1 section5 lectures47m total length
  • Introduction2:41

    Explore hands-on steps to build and harden a secure Active Directory, including installing Active Directory, configuring virtualization, security baselines, tiering, protected users, and integrating roles.

  • Active Directory - Advanced Auditing44:15

    Configure tailored advanced auditing baselines for Active Directory using Threat Log and Sysmon, map Mitre Attack Framework techniques to event IDs, and generate domain controller and member baselines.

  • Knowledge Check
  • Building a Secure Active Directory - Full Version0:15
  • Free Content0:08
  • One more Lecture0:04

Requirements

  • Beginner-friendly, but basic knowledge of Active Directory and Windows OS is recommended for the best learning experience
  • No prior security expertise is required—everything will be explained in depth

Description

Active Directory Advanced Auditing - mini course

Log What Matters. Detect What Matters.

Most environments either log too little — missing key attacks — or log too much, drowning in irrelevant data.


In this focused mini-course, you'll learn how to configure Advanced Audit Policy, use Sysmon effectively, and deploy ThreatLog, a tailored auditing toolkit built for defenders who care about both security and efficiency.


You’ll see exactly how to:

Configure Advanced Audit Policy to log meaningful Windows & AD events

Use Sysmon with a real-world configuration baseline

Validate logs and reduce noise using practical techniques

Understand auditing strategy with ThreatLog — a custom tool to generate optimized baselines


This course includes step-by-step walkthroughs, deployment tips, and lessons from real pentests and blue team audits.


By the end, you'll know what to log, how to tune it, and how to spot real threats without wasting SIEM budget or resources.


This course is a Free Trial of the Building a Secure Active Directory course, which gives you a hands-on practical experience building and hardening your own Active Directory environment.


Want to go deeper? Check out our full Building a Secure Active Directory Course - link at the end of the course.


Thank you and enjoy the course,

David
Horizon Secured


Who this course is for:

  • Windows Administrators securing enterprise environments
  • Cybersecurity Engineers analyzing authentication security
  • IT & Security Professionals responsible for AD hardening
  • Anyone managing or securing Windows Infrastructure and looking for a deep technical understanding & best practices