From the Field: AD Management

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments

๐Ÿ’ฅ ๐Ÿฐ๐Ÿณ.๐Ÿฒ%ย of infrastructures Iโ€™ve assessed ๐—ฑ๐—ผ๐—ปโ€™๐˜ ๐—ต๐—ฎ๐˜ƒ๐—ฒ ๐—ฎ ๐—ฐ๐—ฒ๐—ป๐˜๐—ฟ๐—ฎ๐—น ๐—ฝ๐—ผ๐—ถ๐—ป๐˜ ๐—ณ๐—ผ๐—ฟ ๐—บ๐—ฎ๐—ป๐—ฎ๐—ด๐—ถ๐—ป๐—ด ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜†

That means no PAW. No separation of duties. No controlled management plane.

And yes โ€”ย ๐—ฝ๐—น๐—ฎ๐—ถ๐—ป๐˜๐—ฒ๐˜…๐˜ ๐—”๐—— ๐—ฎ๐—ฑ๐—บ๐—ถ๐—ป ๐—ฐ๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น๐˜€ ๐—ฎ๐—ฟ๐—ฒ ๐—ผ๐—ณ๐˜๐—ฒ๐—ป ๐—ท๐˜‚๐˜€๐˜ ๐—ผ๐—ป๐—ฒ ๐—ฅ๐——๐—ฃ ๐˜€๐—ฒ๐˜€๐˜€๐—ถ๐—ผ๐—ป ๐—ฎ๐˜„๐—ฎ๐˜† from being harvested.

Too many places still ๐—บ๐—ฎ๐—ป๐—ฎ๐—ด๐—ฒ ๐—”๐—— ๐—ณ๐—ฟ๐—ผ๐—บ ๐—ฎ ๐—ฟ๐—ฒ๐—ด๐˜‚๐—น๐—ฎ๐—ฟ ๐˜‚๐˜€๐—ฒ๐—ฟ ๐˜„๐—ผ๐—ฟ๐—ธ๐˜€๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ปย โ€” no jump host, no PAW, no isolation.

๐Ÿ‘‰ That massively expands your attack surface because highly privileged credentials are being used on untrusted devices.

๐Ÿšจ Big no-no.

Let’s say a good start could be someย Jump Point/Jump Host/Administration Host, whatever you want to call it, but it ๐˜€๐˜๐—ถ๐—น๐—น ๐—ฑ๐—ผ๐—ฒ๐˜€ ๐—ป๐—ผ๐˜ ๐—ฝ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜ ๐˜†๐—ผ๐˜‚ ๐—ณ๐—ฟ๐—ผ๐—บ ๐—ฎ๐—น๐—น ๐˜๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜๐˜€…

๐—”๐—ถ๐—บ ๐—ณ๐—ผ๐—ฟ ๐—ฎ ๐—ฃ๐—ฟ๐—ถ๐˜ƒ๐—ถ๐—น๐—ฒ๐—ด๐—ฒ๐—ฑ ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—ช๐—ผ๐—ฟ๐—ธ๐˜€๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ป (๐—ฃ๐—”๐—ช)ย model:

โ–ช๏ธ Isolate all privileged tasks from day-to-day user machines

โ–ช๏ธ You donโ€™t need a separate physical box for every admin tier โ€” virtualization is fine, and you can even combine it with cloud (great talk on this topic from Jake and Eric at Blue Team Con!)

โ–ช๏ธ Host hardware running those VMs must be trusted. If the underlying device is compromised, virtualizing wonโ€™t help.

๐—”๐—ป๐—ฑ ๐—ฟ๐—ฒ๐—บ๐—ฒ๐—บ๐—ฏ๐—ฒ๐—ฟ:

PAWs are only one piece. Implement them alongside a Tiering Model so privileges and management paths are strictly separated before you start moving accounts and services around.