AdminSDHolder changed detection

๐Ÿ”’ Secure Bits ๐Ÿ’ก
๐—œ๐—ณ ๐˜๐—ต๐—ฒ ๐—”๐—–๐—Ÿ ๐—ผ๐—ป ๐—”๐—ฑ๐—บ๐—ถ๐—ป๐—ฆ๐——๐—›๐—ผ๐—น๐—ฑ๐—ฒ๐—ฟ ๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ฒ๐—ฑ โ€” ๐˜„๐—ผ๐˜‚๐—น๐—ฑ ๐˜†๐—ผ๐˜‚ ๐—ธ๐—ป๐—ผ๐˜„ ๐—ฎ๐—ฏ๐—ผ๐˜‚๐˜ ๐—ถ๐˜?

Sure, itโ€™s a bit of an extreme caseโ€ฆ but really โ€” would your setup catch that?

๐Ÿ‘‰ You can monitor this manually ๐˜‚๐˜€๐—ถ๐—ป๐—ด ๐—”๐—ฑ๐˜ƒ๐—ฎ๐—ป๐—ฐ๐—ฒ๐—ฑ ๐—”๐˜‚๐—ฑ๐—ถ๐˜๐—ถ๐—ป๐—ด + ๐—ฆ๐—”๐—–๐—Ÿ and forwarding Events to your SIEM. Itโ€™s free, it works โ€” and it gives you visibility where it matters – ๐—ฏ๐˜‚๐˜ ๐—ถ๐˜ ๐—ถ๐˜€ ๐—น๐—ฎ๐—ฏ๐—ผ๐—ฟ๐—ถ๐—ผ๐˜‚๐˜€, and there are many more cases to detect.

There are ๐—ฎ๐—บ๐—ฎ๐˜‡๐—ถ๐—ป๐—ด ๐—ฐ๐—ผ๐—บ๐—บ๐—ฒ๐—ฟ๐—ฐ๐—ถ๐—ฎ๐—น ๐˜๐—ผ๐—ผ๐—น๐˜€ out there e.g. from Semperis, Forestall, Nanitor, …, โ€” that detect vulnerabilities and changes in AD (and beyond). But letโ€™s face it โ€” not everyone has the ๐—ฏ๐˜‚๐—ฑ๐—ด๐—ฒ๐˜.
โ†’ Thatโ€™s why I wanted to share ๐˜€๐—ผ๐—บ๐—ฒ๐˜๐—ต๐—ถ๐—ป๐—ด ๐—ณ๐—ฟ๐—ฒ๐—ฒ, on-prem, and surprisingly capable.

๐ŸŽฏ ๐—–๐—ฎ๐˜†๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—š๐˜‚๐—ฎ๐—ฟ๐—ฑ๐—ถ๐—ฎ๐—ป ๐—ฃ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟย โ€” Iโ€™ve been testing it lately and Iโ€™m impressed. No sponsorship here โ€” Iโ€™ve just worked with tools like these before (who remembers ATA?), seen plenty of enterprise demos, and this one ๐—ฟ๐—ฒ๐—ฎ๐—น๐—น๐˜† ๐—ฑ๐—ฒ๐—น๐—ถ๐˜ƒ๐—ฒ๐—ฟ๐˜€ ๐˜ƒ๐—ฎ๐—น๐˜‚๐—ฒย โ€” especially for smaller orgs.
โœ” Detects misconfigs, risky changes, and vulnerabilities
โœ” Runs on-prem
โœ” AD, Entra ID, Teams, Intune, Exchange Online
โœ” It is free

I tested it with a PowerShell lab setup script by Kriss Stephenโ€” fantastic for spinning up a ๐˜๐—ฒ๐˜€๐˜ ๐—”๐—— ๐˜„๐—ถ๐˜๐—ต ๐—ฟ๐—ฒ๐—ฎ๐—น๐—ถ๐˜€๐˜๐—ถ๐—ฐ ๐—บ๐—ถ๐˜€๐—ฐ๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜€.
โš ๏ธ Just donโ€™t forget to change the default company size โ€” I left it in, and came back to thousands of demo users (my bad) ๐Ÿซ 

๐—™๐—ฒ๐˜„ ๐—ฒ๐˜…๐—ฎ๐—บ๐—ฝ๐—น๐—ฒ๐˜€ ๐—ผ๐—ณ ๐˜„๐—ต๐—ฎ๐˜ ๐—ถ๐˜ ๐—ฐ๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฒ๐˜€:
โœ” Whole new structure in your AD with realistic data
โœ” Dangerous permissions
โœ” Dangerous delegations
โœ” Artifacts from attacks
โœ” …

๐Ÿ”ง Want to test your detections or evaluate tools like ADProbe? ๐—ง๐—ต๐—ถ๐˜€ ๐˜€๐—ฐ๐—ฟ๐—ถ๐—ฝ๐˜ ๐—ต๐—ฒ๐—น๐—ฝ๐˜€ ๐—ฎ ๐—น๐—ผ๐˜.

โœ… Iโ€™ll leave links to both tools in the comments for you.

๐Ÿ’ฌ ๐—›๐—ผ๐˜„ ๐—ฑ๐—ผ ๐˜†๐—ผ๐˜‚ ๐—ฑ๐—ฒ๐˜๐—ฒ๐—ฐ๐˜ ๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ฒ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—บ๐—ถ๐˜€๐—ฐ๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐—ถ๐—ป ๐—”๐——?