Do you know how attackers hide inside Active Directory?

๐ Secure Bits ๐ก ๐๐ผ ๐๐ผ๐ ๐ธ๐ป๐ผ๐ ๐ต๐ผ๐ ๐ฎ๐๐๐ฎ๐ฐ๐ธ๐ฒ๐ฟ๐ ๐ต๐ถ๐ฑ๐ฒ ๐ถ๐ป๐๐ถ๐ฑ๐ฒ ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐? Itโs called persistence. Attackers often want to stay in your environment long-term without being spotted – which means being a loud Domain Admin is usually not the plan. To spot this, you need to understand what options attackers have and how ACLs […]
From the Field: Naming Convention

๐ ๐๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ถ๐ฒ๐น๐ฑ โ Real-World Findings from Security Assessments ๐ฅย ๐ฎ๐ฏ.๐ด%ย of environments I assessed ๐ต๐ฎ๐ฑ ๐ป๐ผ ๐ป๐ฎ๐บ๐ถ๐ป๐ด ๐ฐ๐ผ๐ป๐๐ฒ๐ป๐๐ถ๐ผ๐ป ๐ณ๐ผ๐ฟ ๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐๐ ๐ฎ๐ป๐ฑ ๐ฑ๐ฒ๐๐ถ๐ฐ๐ฒ๐ Sounds like a boring โadmin hygieneโ topicโฆ but it becomes a real security problem fast. ๐ช๐ต๐ ๐ถ๐ ๐ถ๐ ๐ถ๐บ๐ฝ๐ผ๐ฟ๐๐ฎ๐ป๐? 1๏ธโฃ Operationsย โ you immediately know what a system/account is and where it belongs. 2๏ธโฃ […]
From the Field: Critical Roles

๐ ๐๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ถ๐ฒ๐น๐ฑ โ Real-World Findings from Security Assessments ๐ฅ ~๐ฏ๐ฌ%ย of environments I assessedย ๐๐๐ถ๐น๐น ๐ฐ๐ผ-๐ต๐ผ๐๐ ๐ฐ๐ฟ๐ถ๐๐ถ๐ฐ๐ฎ๐น ๐ฟ๐ผ๐น๐ฒ๐ ๐ถ๐ป๐๐๐ฒ๐ฎ๐ฑ ๐ผ๐ณ ๐๐ฒ๐ฝ๐ฎ๐ฟ๐ฎ๐๐ถ๐ป๐ด ๐๐ต๐ฒ๐บ ๐ ๐๐ฒ๐ฒ ๐๐ต๐ถ๐ ๐ฎ๐น๐น ๐๐ต๐ฒ ๐๐ถ๐บ๐ฒ: ๐ธ DHCP on Domain Controllers (and yesโthere are someย nasty escalationย pathsย with default DHCP groups when hosted on a DC) ๐ธ AD CS on Domain Controllers ๐ธ Entra ID […]
From the Field: Patching

๐ ๐๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ถ๐ฒ๐น๐ฑ โ Real-World Findings from Security Assessments ๐ฅ ๐ฏ๐ฏ.๐ฏ%ย of environments I assessed ๐ฑ๐ผ ๐ป๐ผ๐ ๐ฝ๐ฎ๐๐ฐ๐ต ๐๐ต๐ฒ๐ถ๐ฟ ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฑ๐ฒ๐๐ถ๐ฐ๐ฒ๐ ๐ฟ๐ฒ๐ด๐๐น๐ฎ๐ฟ๐น๐ This one is honestly shocking. I still encounter systems that havenโt been patched ๐ณ๐ผ๐ฟ ๐บ๐ผ๐ป๐๐ต๐ โ ๐๐ผ๐บ๐ฒ๐๐ถ๐บ๐ฒ๐ ๐ฒ๐๐ฒ๐ป ๐๐ฒ๐ฎ๐ฟ๐. And yes, I know what many administrators think: โ๐๐๐๐ง๐ค๐จ๐ค๐๐ฉ ๐ช๐ฅ๐๐๐ฉ๐๐จ ๐จ๐ค๐ข๐๐ฉ๐๐ข๐๐จ ๐๐ง๐๐๐ ๐ฉ๐๐๐ฃ๐๐จ, ๐ฉ๐๐๐ฎ […]
From the Field: Windows Firewall

๐ ๐๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ถ๐ฒ๐น๐ฑ โ Real-World Findings from Security Assessments ๐ฅ ๐ฏ๐ด.๐ญ%ย of environments I assessed ๐ต๐ฎ๐๐ฒ ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐๐ถ๐ฟ๐ฒ๐๐ฎ๐น๐น ๐๐๐ฟ๐ป๐ฒ๐ฑ ๐ข๐๐ I often joke in my courses that the first thing admins do on a new Windows device is disable the firewall. ๐จ๐ป๐ณ๐ผ๐ฟ๐๐๐ป๐ฎ๐๐ฒ๐น๐โฆ itโs not really a joke. Itโs the sad reality. ๐งฑย ๐ช๐ต๐? For historical reasons, […]
From the Field: Local Groups

๐ ๐๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ถ๐ฒ๐น๐ฑ โ Real-World Findings from Security Assessments ๐ฅ ๐ฏ๐ด.๐ญ%ย of environments I assessedย ๐๐๐ถ๐น๐น ๐บ๐ฎ๐ป๐ฎ๐ด๐ฒ ๐น๐ผ๐ฐ๐ฎ๐น ๐ด๐ฟ๐ผ๐๐ฝ๐ ๐บ๐ฒ๐บ๐ฏ๐ฒ๐ฟ๐๐ต๐ถ๐ฝ ๐บ๐ฎ๐ป๐๐ฎ๐น๐น๐ Itโs aย ๐๐ถ๐บ๐ฝ๐น๐ฒ ๐ณ๐ถ๐ โ with aย ๐ฏ๐ถ๐ด ๐ถ๐บ๐ฝ๐ฎ๐ฐ๐. ๐ ๐ฎ๐ป๐๐ฎ๐น๐น๐ ๐ฐ๐ผ๐ป๐๐ฟ๐ผ๐น๐น๐ถ๐ป๐ด ๐น๐ผ๐ฐ๐ฎ๐น ๐ด๐ฟ๐ผ๐๐ฝ ๐บ๐ฒ๐บ๐ฏ๐ฒ๐ฟ๐๐ต๐ถ๐ฝ ๐น๐ฒ๐ฎ๐ฑ๐ ๐๐ผ: ๐น Unmapped privileges ๐น Untracked admin access ๐น Messy permissions that attackers love Years later, no one remembers who has access […]
From the Field: AD CS

๐ ๐๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ถ๐ฒ๐น๐ฑ โ Real-World Findings from Security Assessments ๐ฅ In ๐ฐ๐ฎ.๐ต%ย of infrastructures Iโve assessed, ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐๐ฒ๐ฟ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ฒ ๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ๐ (๐๐ ๐๐ฆ) ๐ฎ๐ฟ๐ฒ ๐๐๐ถ๐น๐น ๐ถ๐บ๐ฝ๐น๐ฒ๐บ๐ฒ๐ป๐๐ฒ๐ฑ ๐๐๐ถ๐ป๐ด ๐ฎ ๐๐ถ๐ป๐ด๐น๐ฒ-๐๐ถ๐ฒ๐ฟ ๐ต๐ถ๐ฒ๐ฟ๐ฎ๐ฟ๐ฐ๐ต๐ Let me borrow a line straight from ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ on this one: โ๐๐ฏ๐ฆ-๐ต๐ช๐ฆ๐ณ ๐ฉ๐ช๐ฆ๐ณ๐ข๐ณ๐ค๐ฉ๐บ ๐ช๐ด ๐ฏ๐ฐ๐ต ๐ณ๐ฆ๐ค๐ฐ๐ฎ๐ฎ๐ฆ๐ฏ๐ฅ๐ฆ๐ฅ ๐ง๐ฐ๐ณ ๐ข๐ฏ๐บ ๐ฑ๐ณ๐ฐ๐ฅ๐ถ๐ค๐ต๐ช๐ฐ๐ฏ ๐ด๐ค๐ฆ๐ฏ๐ข๐ณ๐ช๐ฐ. ๐ ๐ค๐ฐ๐ฎ๐ฑ๐ณ๐ฐ๐ฎ๐ช๐ด๐ฆ ๐ฐ๐ง ๐ต๐ฉ๐ช๐ด ๐ด๐ช๐ฏ๐จ๐ญ๐ฆ ๐๐ […]
From the Field: AD Sites and Services

๐ ๐๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ถ๐ฒ๐น๐ฑ โ Real-World Findings from Security Assessments ๐ฅ ๐ฐ๐ฎ.๐ต%ย of infrastructures Iโve assessed ๐ฑ๐ผ ๐ป๐ผ๐ ๐ฝ๐ฟ๐ผ๐ฝ๐ฒ๐ฟ๐น๐ ๐ฐ๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฒ ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐ฆ๐ถ๐๐ฒ๐ ๐ฎ๐ป๐ฑ ๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ๐ ๐ ๐ผ๐ณ๐๐ฒ๐ป ๐๐ฒ๐ฒ ๐๐๐ผ ๐ฐ๐ฎ๐๐ฒ๐: โช๏ธ admins configure it โhow they feel,โ or โช๏ธ they donโt configure it at all. Both are wrong. If you have multiple sites (DCs in multiple […]
From the Field: Role Separation

๐ ๐๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ถ๐ฒ๐น๐ฑ โ Real-World Findings from Security Assessments ๐ฅ ๐ฐ๐ฎ.๐ต%ย of infrastructures Iโve assessed ๐ฟ๐๐ป๐ ๐บ๐๐น๐๐ถ๐ฝ๐น๐ฒ ๐ฟ๐ผ๐น๐ฒ๐/๐๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ๐ ๐ผ๐ป ๐๐ต๐ฒ๐ถ๐ฟ ๐ฑ๐ผ๐บ๐ฎ๐ถ๐ป ๐ฐ๐ผ๐ป๐๐ฟ๐ผ๐น๐น๐ฒ๐ฟ๐ ๐ซ ๐ง๐ต๐ถ๐ ๐ถ๐ ๐ณ๐ฎ๐ฟ ๐๐ผ๐ผ ๐ฐ๐ผ๐บ๐บ๐ผ๐ป โ especially in smaller environments โ but itโs one of the fastest ways to weaken your security posture. Domain Controllers should normally host only two services: โ […]
From the Field: Windows Server Core

๐ ๐๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ถ๐ฒ๐น๐ฑ โ Real-World Findings from Security Assessments ๐ฅ ๐ณ๐ญ.๐ฐ%ย of infrastructures Iโve assessed ๐ฑ๐ผ ๐ป๐ผ๐ ๐๐๐ฒ ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ ๐๐ผ๐ฟ๐ฒ ๐ฒ๐ฑ๐ถ๐๐ถ๐ผ๐ป To be honest, I donโt even remember seeing it in use by most customers โ the 28.6% might just be environments I secured myself in the past and later reassessed. So, is there […]