๐ Secure Bits ๐ก
๐๐ณ ๐๐ต๐ฒ ๐๐๐ ๐ผ๐ป ๐๐ฑ๐บ๐ถ๐ป๐ฆ๐๐๐ผ๐น๐ฑ๐ฒ๐ฟ ๐ฐ๐ต๐ฎ๐ป๐ด๐ฒ๐ฑ โ ๐๐ผ๐๐น๐ฑ ๐๐ผ๐ ๐ธ๐ป๐ผ๐ ๐ฎ๐ฏ๐ผ๐๐ ๐ถ๐?
Sure, itโs a bit of an extreme caseโฆ but really โ would your setup catch that?
You can monitor this manually ๐๐๐ถ๐ป๐ด ๐๐ฑ๐๐ฎ๐ป๐ฐ๐ฒ๐ฑ ๐๐๐ฑ๐ถ๐๐ถ๐ป๐ด + ๐ฆ๐๐๐ and forwarding Events to your SIEM. Itโs free, it works โ and it gives you visibility where it matters – ๐ฏ๐๐ ๐ถ๐ ๐ถ๐ ๐น๐ฎ๐ฏ๐ผ๐ฟ๐ถ๐ผ๐๐, and there are many more cases to detect.
๐ง One solution Iโve recently tested is ๐๐ผ๐ฟ๐ฒ๐๐๐ฎ๐น๐น ๐๐ฆ๐ฃ๐ . It scans for misconfigured ACLs, dangerous permissions, and even attack paths. And last but not least, the pricing is reasonable.
And our case with AdminSDHolder? Detected.
๐งช ๐ง๐ต๐ฎ๐ป๐ธ๐ ๐๐ผ ๐ผ๐๐ฟ ๐ฐ๐ผ๐น๐น๐ฎ๐ฏ๐ผ๐ฟ๐ฎ๐๐ถ๐ผ๐ป, you can also try the tool for ๐ณ๐ฟ๐ฒ๐ฒ – LINK.If you give it a spin, let me know โ I might even be able to arrange a discount for you.
๐ฌ ๐๐ผ๐ ๐ฑ๐ผ ๐๐ผ๐ ๐ฑ๐ฒ๐๐ฒ๐ฐ๐ ๐ฐ๐ต๐ฎ๐ป๐ด๐ฒ๐ ๐ฎ๐ป๐ฑ ๐บ๐ถ๐๐ฐ๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฎ๐๐ถ๐ผ๐ป๐ ๐ถ๐ป ๐๐?
#ActiveDirectory #SecureBits #ADSecurity #Forestall #ISPM #BlueTeam #CyberSecurity #HorizonSecured Forestall Security Atanur Serkan Elmasoฤlu
