HADES: Detecting Active Directory Attacks via Whole Network Provenance Analytics

Authors

  • Mr. N. Kiran Kumar Author
  • Mr. AATLA MADHUSUDHAN REDDY Author
  • Mr. GOLLA VENKATA NITHISH Author
  • Ms. LAKKAKULA VENKATA LAKSHMI Author
  • Ms. KOTHAPULI SIREESHA Author

DOI:

https://doi.org/10.62643/

Keywords:

1. Active Directory Security, 2. ProvenanceBased Intrusion Detection, 3. Cross-Machine Attack Tracing, 4. Authentication Anomaly Detection, 5. Advanced Persistent Threats (APT), 6. Lateral Movement Detection

Abstract

Active Directory (AD) is the backbone of identity and access management in enterprise networks and a prime target for Advanced Persistent Threat (APT) actors. While traditional intrusion detection systems (IDS) effectively detect malware-driven attacks, they struggle to identify stealthy, credential-based AD attacks that span multiple hosts. Recent provenance-based intrusion detection systems (PIDS) leverage causal analysis to expose malicious behaviors, but existing solutions are largely limited to intra-machine tracing, preventing a holistic view of attacker movement across the network. We present HADES, the first provenance-based IDS capable of accurate causality-driven cross-machine tracing for AD attack detection. HADES introduces logon session–based execution partitioning, a novel technique that enables precise attribution of activities across hosts despite the inherent challenges of distributed authentication and execution. To ensure scalability, HADES operates as an on-demand tracing system, triggering whole-network provenance analysis only upon detecting suspicious authentication behavior. For this purpose, we design a lightweight authentication anomaly detection model grounded in an extensive empirical analysis of real-world AD attacks. Furthermore, we propose an alert triage algorithm that incorporates key behavioral insights unique to AD-based attack campaigns. Comprehensive evaluation demonstrates that HADES significantly outperforms state-of-the-art open-source tools and a leading commercial AD attack detection system in both detection accuracy and attack-scope reconstruction, enabling effective identification and investigation of sophisticated AD compromises.

Downloads

Published

30-01-2026

How to Cite

HADES: Detecting Active Directory Attacks via Whole Network Provenance Analytics. (2026). International Journal of Engineering Research and Science & Technology, 22(1), 158-165. https://doi.org/10.62643/