Skip to content
Search
paperAugust 2026Unreviewed

Analyzing Structural and Semantic Barriers to Automated Adversary Emulation in Active Directory

Anita Ding, Anthony J. Rose, Mark G. Reith

National Aerospace and Electronics Conference

Abstract

Active Directory (AD) underpins enterprise identity management and is among the most heavily targeted assets in modern enterprise networks. When red teams emulate attackers targeting it, they typically chain BloodHound for relationship mapping, Impacket for protocol manipulation, and Responder for credential interception. Despite rapid advances in Large Language Models (LLMs), reliably automating this BIR workflow is still difficult, and the difficulty is not primarily one of reasoning. We analy

Categories

Framework mappings

Suggested from the entry's categories.

Cite

@inproceedings{ding2026analyzing,
  title = {{Analyzing Structural and Semantic Barriers to Automated Adversary Emulation in Active Directory}},
  author = {Anita Ding and Anthony J. Rose and Mark G. Reith},
  year = {2026},
  month = aug,
  booktitle = {National Aerospace and Electronics Conference},
  doi = {10.1109/NAECON70028.2026.11675755},
  url = {https://www.semanticscholar.org/paper/183de1e3c5e49190a7e327d47f55739e55b4be4f}
}