I'm reviewing activity from an IT administrator account and need to determine whether it reflects routine administration or possible compromise. The account generated extensive LDAP queries against domain controllers, USER_ENUMERATION and ENDPOINT_ENUMERATION alerts, numerous SAMR/DCE-RPC requests across different computers, and bursts of more than 10 SAMR requests within a second. There was also SMB traffic to domain controllers, frequent NTLM authentication to NPS/RADIUS servers, Entra ID and Microsoft 365 sign-ins from multiple IP addresses, a password change, and removal from Domain Admins.
Some of this could be legitimate helpdesk or infrastructure work, but the SAMR enumeration spans Finance, HR, factory, and POS systems. I'm especially concerned that the activity may represent automated internal reconnaissance rather than a person manually accessing systems.
For those investigating identity alerts, how do you distinguish expected administrative behavior from a compromised account? Which process, authentication, endpoint, and file-transfer logs would you review to determine whether the account was used for actual lateral movement?
5 Answers
Build a timeline covering the account, source devices, and IP addresses. Compare the activity with the administrator’s normal baseline and verify whether they were actually working at that time. Review domain-controller security logs, authentication events, NTLM usage, Kerberos tickets, Entra sign-in details, VPN or NPS records, endpoint logons, privilege changes, and remote-service activity such as SMB, PsExec-like services, WinRM, scheduled tasks, or RDP. A password change or removal from Domain Admins should be correlated with who initiated it and from which host.
Some SMB traffic to domain controllers is routine because clients retrieve policies and other domain data, so that signal alone does not prove compromise. The stronger indicators are unexpected source systems, a sudden change from the account’s historical behavior, enumeration of machines the administrator never manages, unusual logon locations, and evidence that the account accessed or executed something on those endpoints.
Validate the activity with the account owner and the team responsible for the relevant tooling, but don’t rely on that answer alone. If the behavior cannot be explained quickly, preserve the endpoint and identity evidence, consider disabling or restricting the account, revoke active sessions and tokens, rotate credentials, and investigate the source workstation for credential theft and collection tools. The decision should be based on the full timeline rather than a single alert.
Look at the scope and timing. An administrator usually touches a predictable set of systems, while tools such as directory-mapping or collection utilities tend to walk large parts of the environment in a short, systematic sequence. Bursts of SAMR requests across unrelated departments are worth treating seriously, especially if this behavior is new for the account. Check for archives or other collection output created around the same time.
Start with the process that generated the network activity, not just the identity. Correlate the SAMR and LDAP requests with EDR telemetry, command lines, parent processes, scheduled tasks, services, and any tools launched on the source host. Automated, domain-wide enumeration from a single executable is much more suspicious than a known management tool running from an expected admin workstation.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures