The five eyes intelligence agencies released a guide to detect Active Directory compromises: https://www.cyber.gov.au/sites/default/files/2024-09/PROTECT-Detecting-and-Mitigating-Active-Directory-Compromises.pdf
No word on whether the publication was delayed to ensure the guide doesn’t impact their own AD intrusions.