๐ Secure Bits ๐ก
๐๐ผ ๐๐ผ๐ ๐ฟ๐ฒ๐ด๐๐น๐ฎ๐ฟ๐น๐ ๐ฐ๐ต๐ฒ๐ฐ๐ธ ๐๐ผ๐๐ฟ ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐ณ๐ผ๐ฟ ๐บ๐ถ๐๐ฐ๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฒ๐ฑ ๐๐๐๐?
ACL misconfigurations are one of the ๐บ๐ผ๐๐ ๐ผ๐๐ฒ๐ฟ๐น๐ผ๐ผ๐ธ๐ฒ๐ฑ โ yet severe โ vulnerabilities in AD environments. They often stay hidden until a malicious actor finds themโฆ and by then, itโs too late.
๐๐ฒ๐ฟ๐ฒ ๐ฎ๐ฟ๐ฒ ๐ท๐๐๐ ๐ฎ ๐ณ๐ฒ๐ ๐ฒ๐
๐ฎ๐บ๐ฝ๐น๐ฒ๐ ๐ผ๐ณ ๐๐ต๐ฒ๐๐ฒ:
๐น ๐๐๐ฆ๐๐ป๐ฐ โ permissions that let an account replicate data (including secrets) from the AD DS database.
๐น ๐๐๐ฆ๐ต๐ฎ๐ฑ๐ผ๐ โ the ability to push changes to AD from a compromised machine acting as a rogue Domain Controller.
๐น ๐ฆ๐บ๐ฎ๐น๐น๐ฒ๐ฟ ๐ฑ๐ฒ๐น๐ฒ๐ด๐ฎ๐๐ถ๐ผ๐ป๐ โ write access, password resets, read LAPS password, GPO edit permissions, and many other privileges/permissions that can become escalation paths to full AD DS control.
๐น ๐๐ ๐๐ฆ (๐๐ฆ๐-๐ป) โ misconfigurations in Active Directory Certificate Services enabling escalation from a basic user/computer.
These flaws are ๐ฑ๐ฎ๐ป๐ด๐ฒ๐ฟ๐ผ๐๐ because ๐ฎ๐ป๐ authenticated user in your domain can abuse them โ often from just a regular workstation.
๐ฆ๐ผ ๐ต๐ผ๐ ๐ฑ๐ผ ๐๐ผ๐ ๐ฝ๐ฟ๐ผ๐๐ฒ๐ฐ๐ ๐๐ผ๐๐ฟ๐๐ฒ๐น๐ณ?
๐ก๏ธ Donโt delegate privileges unless you ๐ณ๐๐น๐น๐ ๐๐ป๐ฑ๐ฒ๐ฟ๐๐๐ฎ๐ป๐ฑ their security impact.
๐ก๏ธ ๐ฅ๐ฒ๐ด๐๐น๐ฎ๐ฟ๐น๐ ๐๐ฐ๐ฎ๐ป your environment for ACL misconfigurations โ just like attackers do during recon.
You can do this ๐บ๐ฎ๐ป๐๐ฎ๐น๐น๐ (e.g. with PowerShell), but for more comprehensive and continuous detection, you might want to ๐๐๐ฒ ๐ฎ ๐๐ผ๐ผ๐น.
๐ง One solution Iโve recently tested is ๐๐ผ๐ฟ๐ฒ๐๐๐ฎ๐น๐น ๐๐ฆ๐ฃ๐ .
Iโve been working directly with the Forestall team, and after some testing, I can confidently say the ๐ฝ๐ฟ๐ผ๐ฑ๐๐ฐ๐ ๐ฑ๐ฒ๐น๐ถ๐๐ฒ๐ฟ๐. It scans for misconfigured ACLs, dangerous permissions, and even attack paths.
๐ ๐ ๐ผ๐ฟ๐ฒ ๐ฑ๐ฒ๐๐ฎ๐ถ๐น๐ย are in the link provided in the comments.
๐งช ๐ง๐ต๐ฎ๐ป๐ธ๐ ๐๐ผ ๐ผ๐๐ฟ ๐ฐ๐ผ๐น๐น๐ฎ๐ฏ๐ผ๐ฟ๐ฎ๐๐ถ๐ผ๐ป, you can also try it for ๐ณ๐ฟ๐ฒ๐ฒ – just write a comment, and I will make it happen. If you give it a spin, let me know โ I might even be able to arrange a discount for you.
Are you regularly checking your AD for these misconfigurations?
