Why Changing Passwords Doesnt End an Active Directory Breach
Resetting a password doesnt always remove attackers from Active Directory Specops Software explains how cached credentials and Kerberos tickets can keep attackers authenticated after a reset