Fidelis Active Directory Intercept combines an AD-aware network detection and response platform and integrated Active Directory deception technology with foundational AD log and event monitoring. Network sensors provide real-time traffic analysis to identify indicators of threats against Active Directory. Fidelis Deep Session Inspection enhances threat identification by analyzing nested and obfuscated files and can analyze encrypted traffic, both in-line and out-of-band. It provides a hierarchical view of the entire AD environment with detailed information on all Active Directory entities such as users, computers, groups, and domains. This specialized AD monitoring enables detection of sophisticated attacks that traditional security tools miss, including Active Directory reconnaissance, Kerberoasting, LLMNR poisoning, DCSync attacks, DCShadow attacks, and brute-force authentication attempts. Fidelis Active Threat Detection correlates activities with MITRE ATT&CK TTPs.