How long has your Active Directory been around?

๐Ÿ”’ Secure Bits ๐Ÿ’ก

๐—›๐—ผ๐˜„ ๐—น๐—ผ๐—ป๐—ด ๐—ต๐—ฎ๐˜€ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐—ฏ๐—ฒ๐—ฒ๐—ป ๐—ฎ๐—ฟ๐—ผ๐˜‚๐—ป๐—ฑ?

The older the AD, the more โ€œhistoryโ€ it carries. Admins change, projects come and goโ€ฆ but the ๐—น๐—ฒ๐—ณ๐˜๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐˜€ ๐˜€๐˜๐—ฎ๐˜† – in the form of forgotten misconfigurations and risky settings that attackers love โš ๏ธ

Once an attacker gets a foothold, one of the first things they do is ask:

โ€œWhat does this Active Directory hide?โ€

๐—›๐—ฒ๐—ฟ๐—ฒ ๐—ฎ๐—ฟ๐—ฒ ๐—ฎ ๐—ณ๐—ฒ๐˜„ simple, often overlooked issues I still see during assessments:

๐Ÿ”ธ ๐—ฃ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ ๐—ป๐—ฒ๐˜ƒ๐—ฒ๐—ฟ ๐—ฒ๐˜…๐—ฝ๐—ถ๐—ฟ๐—ฒ๐˜€ + password last changed 10+ years ago

Even worse when itโ€™s a privileged/service account with an SPN.

๐Ÿ”ธ ๐—ฆ๐˜๐—ผ๐—ฟ๐—ฒ ๐—ฝ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ ๐˜‚๐˜€๐—ถ๐—ป๐—ด ๐—ฟ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ถ๐—ฏ๐—น๐—ฒ ๐—ฒ๐—ป๐—ฐ๐—ฟ๐˜†๐—ฝ๐˜๐—ถ๐—ผ๐—ป

I honestly donโ€™t see a valid reason for this today.

๐Ÿ”ธ ๐—”๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜ ๐—น๐—ถ๐—บ๐—ถ๐˜๐—ฒ๐—ฑ ๐˜๐—ผ ๐—ž๐—ฒ๐—ฟ๐—ฏ๐—ฒ๐—ฟ๐—ผ๐˜€ ๐——๐—˜๐—ฆ ๐—ฒ๐—ป๐—ฐ๐—ฟ๐˜†๐—ฝ๐˜๐—ถ๐—ผ๐—ป ๐˜๐˜†๐—ฝ๐—ฒ๐˜€

Weโ€™re fighting to remove RC4โ€ฆ DES should have been gone long ago.

๐Ÿ”ธ ๐——๐—ผ ๐—ป๐—ผ๐˜ ๐—ฟ๐—ฒ๐—พ๐˜‚๐—ถ๐—ฟ๐—ฒ ๐—ž๐—ฒ๐—ฟ๐—ฏ๐—ฒ๐—ฟ๐—ผ๐˜€ ๐—ฝ๐—ฟ๐—ฒ๐—ฎ๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป

This makes the account vulnerable to offline cracking-style attacks (and yes – I still see it).

These ๐—ฎ๐—ฟ๐—ฒ๐—ปโ€™๐˜ ๐—ฒ๐˜…๐—ผ๐˜๐—ถ๐—ฐ ๐˜ƒ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐—ถ๐—ฒ๐˜€. Theyโ€™re just old โ€œcheckboxโ€ settings that no one revisits – and they quietly turn into attack paths.

โธป

You can do a one-time cleanup, of course. But the real problem is ๐—ฑ๐—ฟ๐—ถ๐—ณ๐˜: things get changed over time and nobody notices.

โœ… Thatโ€™s why I started collaborating with Forestall Security and their ISPM platform – its main value is ๐—ฐ๐—ผ๐—ป๐˜๐—ถ๐—ป๐˜‚๐—ผ๐˜‚๐˜€ ๐—บ๐—ผ๐—ป๐—ถ๐˜๐—ผ๐—ฟ๐—ถ๐—ป๐—ด ๐—ผ๐—ณ ๐—”๐—— misconfigurations and threats, so you can catch risky changes before they become a finding (or an incident).

๐Ÿงช ๐—ช๐—ฎ๐—ป๐˜ ๐˜๐—ผ ๐˜๐—ฟ๐˜† ๐—ถ๐˜?

Because of the collaboration you can get a ๐—ณ๐—ฟ๐—ฒ๐—ฒ ๐˜๐—ฟ๐—ถ๐—ฎ๐—นย – comment or DM me.

When was the last time you checked your AD for these settings?