Do you know how attackers hide inside Active Directory?

๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐—ธ๐—ป๐—ผ๐˜„ ๐—ต๐—ผ๐˜„ ๐—ฎ๐˜๐˜๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ฟ๐˜€ ๐—ต๐—ถ๐—ฑ๐—ฒ ๐—ถ๐—ป๐˜€๐—ถ๐—ฑ๐—ฒ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜†? Itโ€™s called persistence. Attackers often want to stay in your environment long-term without being spotted – which means being a loud Domain Admin is usually not the plan. To spot this, you need to understand what options attackers have and how ACLs […]

From the Field: Naming Convention

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments ๐Ÿ’ฅย ๐Ÿฎ๐Ÿฏ.๐Ÿด%ย of environments I assessed ๐—ต๐—ฎ๐—ฑ ๐—ป๐—ผ ๐—ป๐—ฎ๐—บ๐—ถ๐—ป๐—ด ๐—ฐ๐—ผ๐—ป๐˜ƒ๐—ฒ๐—ป๐˜๐—ถ๐—ผ๐—ป ๐—ณ๐—ผ๐—ฟ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ฑ๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€ Sounds like a boring โ€œadmin hygieneโ€ topicโ€ฆ but it becomes a real security problem fast. ๐—ช๐—ต๐˜† ๐—ถ๐˜€ ๐—ถ๐˜ ๐—ถ๐—บ๐—ฝ๐—ผ๐—ฟ๐˜๐—ฎ๐—ป๐˜? 1๏ธโƒฃ Operationsย โ€“ you immediately know what a system/account is and where it belongs. 2๏ธโƒฃ […]

From the Field: Critical Roles

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments ๐Ÿ’ฅ ~๐Ÿฏ๐Ÿฌ%ย of environments I assessedย ๐˜€๐˜๐—ถ๐—น๐—น ๐—ฐ๐—ผ-๐—ต๐—ผ๐˜€๐˜ ๐—ฐ๐—ฟ๐—ถ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—ฟ๐—ผ๐—น๐—ฒ๐˜€ ๐—ถ๐—ป๐˜€๐˜๐—ฒ๐—ฎ๐—ฑ ๐—ผ๐—ณ ๐˜€๐—ฒ๐—ฝ๐—ฎ๐—ฟ๐—ฎ๐˜๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ๐—บ ๐—œ ๐˜€๐—ฒ๐—ฒ ๐˜๐—ต๐—ถ๐˜€ ๐—ฎ๐—น๐—น ๐˜๐—ต๐—ฒ ๐˜๐—ถ๐—บ๐—ฒ: ๐Ÿ”ธ DHCP on Domain Controllers (and yesโ€”there are someย nasty escalationย pathsย with default DHCP groups when hosted on a DC) ๐Ÿ”ธ AD CS on Domain Controllers ๐Ÿ”ธ Entra ID […]

From the Field: Patching

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments ๐Ÿ’ฅ ๐Ÿฏ๐Ÿฏ.๐Ÿฏ%ย of environments I assessed ๐—ฑ๐—ผ ๐—ป๐—ผ๐˜ ๐—ฝ๐—ฎ๐˜๐—ฐ๐—ต ๐˜๐—ต๐—ฒ๐—ถ๐—ฟ ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฑ๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€ ๐—ฟ๐—ฒ๐—ด๐˜‚๐—น๐—ฎ๐—ฟ๐—น๐˜† This one is honestly shocking. I still encounter systems that havenโ€™t been patched ๐—ณ๐—ผ๐—ฟ ๐—บ๐—ผ๐—ป๐˜๐—ต๐˜€ โ€” ๐˜€๐—ผ๐—บ๐—ฒ๐˜๐—ถ๐—บ๐—ฒ๐˜€ ๐—ฒ๐˜ƒ๐—ฒ๐—ป ๐˜†๐—ฒ๐—ฎ๐—ฟ๐˜€. And yes, I know what many administrators think: โ€œ๐™ˆ๐™ž๐™˜๐™ง๐™ค๐™จ๐™ค๐™›๐™ฉ ๐™ช๐™ฅ๐™™๐™–๐™ฉ๐™š๐™จ ๐™จ๐™ค๐™ข๐™š๐™ฉ๐™ž๐™ข๐™š๐™จ ๐™—๐™ง๐™š๐™–๐™  ๐™ฉ๐™๐™ž๐™ฃ๐™œ๐™จ, ๐™ฉ๐™๐™š๐™ฎ […]

From the Field: Windows Firewall

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments ๐Ÿ’ฅ ๐Ÿฏ๐Ÿด.๐Ÿญ%ย of environments I assessed ๐—ต๐—ฎ๐˜ƒ๐—ฒ ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—™๐—ถ๐—ฟ๐—ฒ๐˜„๐—ฎ๐—น๐—น ๐˜๐˜‚๐—ฟ๐—ป๐—ฒ๐—ฑ ๐—ข๐—™๐—™ I often joke in my courses that the first thing admins do on a new Windows device is disable the firewall. ๐—จ๐—ป๐—ณ๐—ผ๐—ฟ๐˜๐˜‚๐—ป๐—ฎ๐˜๐—ฒ๐—น๐˜†โ€ฆ itโ€™s not really a joke. Itโ€™s the sad reality. ๐Ÿงฑย ๐—ช๐—ต๐˜†? For historical reasons, […]

From the Field: Local Groups

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments ๐Ÿ’ฅ ๐Ÿฏ๐Ÿด.๐Ÿญ%ย of environments I assessedย ๐˜€๐˜๐—ถ๐—น๐—น ๐—บ๐—ฎ๐—ป๐—ฎ๐—ด๐—ฒ ๐—น๐—ผ๐—ฐ๐—ฎ๐—น ๐—ด๐—ฟ๐—ผ๐˜‚๐—ฝ๐˜€ ๐—บ๐—ฒ๐—บ๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ต๐—ถ๐—ฝ ๐—บ๐—ฎ๐—ป๐˜‚๐—ฎ๐—น๐—น๐˜† Itโ€™s aย ๐˜€๐—ถ๐—บ๐—ฝ๐—น๐—ฒ ๐—ณ๐—ถ๐˜… โ€” with aย ๐—ฏ๐—ถ๐—ด ๐—ถ๐—บ๐—ฝ๐—ฎ๐—ฐ๐˜. ๐— ๐—ฎ๐—ป๐˜‚๐—ฎ๐—น๐—น๐˜† ๐—ฐ๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐—น๐—ถ๐—ป๐—ด ๐—น๐—ผ๐—ฐ๐—ฎ๐—น ๐—ด๐—ฟ๐—ผ๐˜‚๐—ฝ ๐—บ๐—ฒ๐—บ๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ต๐—ถ๐—ฝ ๐—น๐—ฒ๐—ฎ๐—ฑ๐˜€ ๐˜๐—ผ: ๐Ÿ”น Unmapped privileges ๐Ÿ”น Untracked admin access ๐Ÿ”น Messy permissions that attackers love Years later, no one remembers who has access […]

From the Field: AD CS

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments ๐Ÿ’ฅ In ๐Ÿฐ๐Ÿฎ.๐Ÿต%ย of infrastructures Iโ€™ve assessed, ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐—–๐—ฒ๐—ฟ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€ (๐—”๐—— ๐—–๐—ฆ) ๐—ฎ๐—ฟ๐—ฒ ๐˜€๐˜๐—ถ๐—น๐—น ๐—ถ๐—บ๐—ฝ๐—น๐—ฒ๐—บ๐—ฒ๐—ป๐˜๐—ฒ๐—ฑ ๐˜‚๐˜€๐—ถ๐—ป๐—ด ๐—ฎ ๐˜€๐—ถ๐—ป๐—ด๐—น๐—ฒ-๐˜๐—ถ๐—ฒ๐—ฟ ๐—ต๐—ถ๐—ฒ๐—ฟ๐—ฎ๐—ฟ๐—ฐ๐—ต๐˜† Let me borrow a line straight from ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ on this one: โ€œ๐˜–๐˜ฏ๐˜ฆ-๐˜ต๐˜ช๐˜ฆ๐˜ณ ๐˜ฉ๐˜ช๐˜ฆ๐˜ณ๐˜ข๐˜ณ๐˜ค๐˜ฉ๐˜บ ๐˜ช๐˜ด ๐˜ฏ๐˜ฐ๐˜ต ๐˜ณ๐˜ฆ๐˜ค๐˜ฐ๐˜ฎ๐˜ฎ๐˜ฆ๐˜ฏ๐˜ฅ๐˜ฆ๐˜ฅ ๐˜ง๐˜ฐ๐˜ณ ๐˜ข๐˜ฏ๐˜บ ๐˜ฑ๐˜ณ๐˜ฐ๐˜ฅ๐˜ถ๐˜ค๐˜ต๐˜ช๐˜ฐ๐˜ฏ ๐˜ด๐˜ค๐˜ฆ๐˜ฏ๐˜ข๐˜ณ๐˜ช๐˜ฐ. ๐˜ˆ ๐˜ค๐˜ฐ๐˜ฎ๐˜ฑ๐˜ณ๐˜ฐ๐˜ฎ๐˜ช๐˜ด๐˜ฆ ๐˜ฐ๐˜ง ๐˜ต๐˜ฉ๐˜ช๐˜ด ๐˜ด๐˜ช๐˜ฏ๐˜จ๐˜ญ๐˜ฆ ๐˜Š๐˜ˆ […]

From the Field: AD Sites and Services

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments ๐Ÿ’ฅ ๐Ÿฐ๐Ÿฎ.๐Ÿต%ย of infrastructures Iโ€™ve assessed ๐—ฑ๐—ผ ๐—ป๐—ผ๐˜ ๐—ฝ๐—ฟ๐—ผ๐—ฝ๐—ฒ๐—ฟ๐—น๐˜† ๐—ฐ๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฒ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐—ฆ๐—ถ๐˜๐—ฒ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€ ๐—œ ๐—ผ๐—ณ๐˜๐—ฒ๐—ป ๐˜€๐—ฒ๐—ฒ ๐˜๐˜„๐—ผ ๐—ฐ๐—ฎ๐˜€๐—ฒ๐˜€: โ–ช๏ธ admins configure it โ€œhow they feel,โ€ or โ–ช๏ธ they donโ€™t configure it at all. Both are wrong. If you have multiple sites (DCs in multiple […]

From the Field: Role Separation

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments ๐Ÿ’ฅ ๐Ÿฐ๐Ÿฎ.๐Ÿต%ย of infrastructures Iโ€™ve assessed ๐—ฟ๐˜‚๐—ป๐˜€ ๐—บ๐˜‚๐—น๐˜๐—ถ๐—ฝ๐—น๐—ฒ ๐—ฟ๐—ผ๐—น๐—ฒ๐˜€/๐˜€๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€ ๐—ผ๐—ป ๐˜๐—ต๐—ฒ๐—ถ๐—ฟ ๐—ฑ๐—ผ๐—บ๐—ฎ๐—ถ๐—ป ๐—ฐ๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐—น๐—ฒ๐—ฟ๐˜€ ๐Ÿšซ ๐—ง๐—ต๐—ถ๐˜€ ๐—ถ๐˜€ ๐—ณ๐—ฎ๐—ฟ ๐˜๐—ผ๐—ผ ๐—ฐ๐—ผ๐—บ๐—บ๐—ผ๐—ป โ€” especially in smaller environments โ€” but itโ€™s one of the fastest ways to weaken your security posture. Domain Controllers should normally host only two services: โœ… […]

From the Field: Windows Server Core

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments ๐Ÿ’ฅ ๐Ÿณ๐Ÿญ.๐Ÿฐ%ย of infrastructures Iโ€™ve assessed ๐—ฑ๐—ผ ๐—ป๐—ผ๐˜ ๐˜‚๐˜€๐—ฒ ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐—–๐—ผ๐—ฟ๐—ฒ ๐—ฒ๐—ฑ๐—ถ๐˜๐—ถ๐—ผ๐—ป To be honest, I donโ€™t even remember seeing it in use by most customers โ€” the 28.6% might just be environments I secured myself in the past and later reassessed. So, is there […]