“Just enable MFA. It’s easy.”

๐ Secure Bits ๐ก โ๐๐๐๐ ๐ฒ๐ป๐ฎ๐ฏ๐น๐ฒ ๐ ๐๐. ๐๐โ๐ ๐ฒ๐ฎ๐๐.โ Sureโฆ if you can rely on cloud identity. A lot of environments can. But ๐บ๐ฎ๐ป๐ – often the most critical ones – ๐ฐ๐ฎ๐ป๐ป๐ผ๐ be connected to the internet at all. And that changes everything. In fully ๐ผ๐ป-๐ฝ๐ฟ๐ฒ๐บ / ๐ผ๐ณ๐ณ๐น๐ถ๐ป๐ฒ Windows environments, MFA often ends up being […]
Pick only 3 security controls for your AD

๐ย Secure Bits ๐ก ๐๐ณ ๐๐ผ๐ ๐ฐ๐ผ๐๐น๐ฑ ๐ธ๐ฒ๐ฒ๐ฝ ๐ผ๐ป๐น๐ ๐ฏ ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฐ๐ผ๐ป๐๐ฟ๐ผ๐น๐ ๐ถ๐ป ๐ฎ ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐ฒ๐ป๐๐ถ๐ฟ๐ผ๐ป๐บ๐ฒ๐ป๐ – ๐๐ต๐ฎ๐ ๐๐ผ๐๐น๐ฑ ๐๐ผ๐ ๐ฝ๐ถ๐ฐ๐ธ? Iโm curious what your โtop 3โ are (I know it depends a lot on what we are protecting, but let’s try). ๐๐ณ ๐ ๐ต๐ฎ๐ฑ ๐๐ผ ๐ฐ๐ต๐ผ๐ผ๐๐ฒ (๐ป๐ผ๐ ๐ฎ ๐๐ถ๐บ๐ฝ๐น๐ฒ ๐ฐ๐ต๐ผ๐ถ๐ฐ๐ฒ), ๐บ๐ถ๐ป๐ฒ ๐๐ผ๐๐น๐ฑ ๐ฏ๐ฒ: 1๏ธโฃย ๐ง๐ถ๐ฒ๐ฟ๐ถ๐ป๐ด […]
How long has your Active Directory been around?

๐ Secure Bits ๐ก ๐๐ผ๐ ๐น๐ผ๐ป๐ด ๐ต๐ฎ๐ ๐๐ผ๐๐ฟ ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐ฏ๐ฒ๐ฒ๐ป ๐ฎ๐ฟ๐ผ๐๐ป๐ฑ? The older the AD, the more โhistoryโ it carries. Admins change, projects come and goโฆ but the ๐น๐ฒ๐ณ๐๐ผ๐๐ฒ๐ฟ๐ ๐๐๐ฎ๐ – in the form of forgotten misconfigurations and risky settings that attackers love โ ๏ธ Once an attacker gets a foothold, one of the first […]
What’s 1 minute of security training worth?

๐ฐ ๐ช๐ต๐ฎ๐โ๐ ๐ญ ๐บ๐ถ๐ป๐๐๐ฒ ๐ผ๐ณ ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ฟ๐ฎ๐ถ๐ป๐ถ๐ป๐ด ๐๐ผ๐ฟ๐๐ต? Many AD security trainings are premium live workshops, often priced ๐ฎ๐ฏ๐ผ๐๐ฒ $๐ฏ,๐ฌ๐ฌ๐ฌ. I built ๐๐๐ถ๐น๐ฑ๐ถ๐ป๐ด ๐ฎ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐๐ผ๐๐ฟ๐๐ฒ to make this ๐ธ๐ป๐ผ๐๐น๐ฒ๐ฑ๐ด๐ฒ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐๐ถ๐ฏ๐น๐ฒ at a fraction of the cost โ with 365-day on-demand access. โ Hands-on experience โ You actually build and harden your own […]
Do you run Active Directory Certificate Services (AD CS)?

๐ ๏ธย Practical Bits ๐๐ผ ๐๐ผ๐ ๐ฟ๐๐ป ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐๐ฒ๐ฟ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ฒ ๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ๐ (๐๐ ๐๐ฆ)? When was the last time you checked it for vulnerabilities? In security assessments this isย ๐ฒ๐๐ฒ๐ฟ๐ด๐ฟ๐ฒ๐ฒ๐ปย โ itโs common to find at least one certificate template that gives a ๐จstraight path toย ๐๐ผ๐บ๐ฎ๐ถ๐ป ๐๐ฑ๐บ๐ถ๐ป. โก๏ธ Set asideย one hourย and scan your AD CS. Itโs one of the ๐ต๐ถ๐ด๐ต๐ฒ๐๐-๐ถ๐บ๐ฝ๐ฎ๐ฐ๐ […]
Do you still need a Password Policy nowadays?

๐ ๏ธ Practical Bits ๐๐ผ ๐๐ผ๐ ๐๐๐ถ๐น๐น ๐ป๐ฒ๐ฒ๐ฑ ๐ฎ ๐ฃ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ ๐ฃ๐ผ๐น๐ถ๐ฐ๐ ๐ป๐ผ๐๐ฎ๐ฑ๐ฎ๐๐? Yes โ even if you use MFA or passwordless options. In Active Directory there are always ๐ฒ๐ ๐ฐ๐ฒ๐ฝ๐๐ถ๐ผ๐ป๐: service accounts, temporary accounts, break-glass accounts, newly created usersโฆ and those still rely on passwords. Strong password + lockout policies ๐ฟ๐ฎ๐ถ๐๐ฒ ๐๐ต๐ฒ ๐ฏ๐ฎ๐ฟ against password spraying and […]
Do you know how attackers hide inside Active Directory?

๐ Secure Bits ๐ก ๐๐ผ ๐๐ผ๐ ๐ธ๐ป๐ผ๐ ๐ต๐ผ๐ ๐ฎ๐๐๐ฎ๐ฐ๐ธ๐ฒ๐ฟ๐ ๐ต๐ถ๐ฑ๐ฒ ๐ถ๐ป๐๐ถ๐ฑ๐ฒ ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐? Itโs called persistence. Attackers often want to stay in your environment long-term without being spotted – which means being a loud Domain Admin is usually not the plan. To spot this, you need to understand what options attackers have and how ACLs […]
Active Directory SPN

๐ ๏ธย [๐ฃ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฎ๐น ๐๐ถ๐๐] – ๐ฆ๐ฃ๐ก Go and check your Active Directory for SPNs. You can do so easily with any simple PowerShell script. Example: ____ Get-ADUser -LDAPFilter ‘(&(objectCategory=user)(!(samAccountName=krbtgt)(servicePrincipalName=*)))’ -Properties Name, UserPrincipalName, ServicePrincipalName | Select-Object Name, UserPrincipalName, @{N=”ServicePrincipalName”;E={$_.ServicePrincipalName -join “, “}} ____ (๐ฉ๐๐๐จ ๐๐จ ๐๐ก๐จ๐ค ๐ฅ๐๐ง๐ฉ ๐ค๐ ๐ข๐ฎ ๐ฉ๐ค๐ค๐ก ๐ผ๐ฟ๐๐ง๐ค๐๐) โOnce you have results, go through the […]
Do you use Security Baselines?

๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ Real configs. Real fixes. Windows & AD security. ๐๐ผ ๐๐ผ๐ ๐๐๐ฒ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ฎ๐๐ฒ๐น๐ถ๐ป๐ฒ๐? You should. They set a clear, enforceable standard for Windows & AD. Without baselines youโre either on defaults or on local tweaksโboth ๐น๐ฒ๐ฎ๐ฑ ๐๐ผ ๐ฑ๐ฟ๐ถ๐ณ๐, ๐ถ๐ป๐ฐ๐ผ๐ป๐๐ถ๐๐๐ฒ๐ป๐ฐ๐, ๐ฎ๐ป๐ฑ ๐ฒ๐ฎ๐๐ ๐ผ๐ฝ๐ฒ๐ป๐ถ๐ป๐ด๐ for attackers. ๐ช๐ต๐ฎ๐ โ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ฎ๐๐ฒ๐น๐ถ๐ป๐ฒ๐โ ๐ฎ๐ฟ๐ฒ: A curated set of […]
Can your Domain Admins log in to endpoints?

๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ Real configs. Real fixes. Windows & AD security. Can your ๐๐ผ๐บ๐ฎ๐ถ๐ป ๐๐ฑ๐บ๐ถ๐ป๐ ๐น๐ผ๐ด ๐ถ๐ป ๐๐ผ ๐ฒ๐ป๐ฑ๐ฝ๐ผ๐ถ๐ป๐๐? ๐ง๐ต๐ฒ๐ ๐๐ต๐ผ๐๐น๐ฑ๐ปโ๐. Disable it. Build multiple tiers with separate privileged accounts for each tier and ๐ฟ๐ฒ๐๐๐ฟ๐ถ๐ฐ๐ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐ with GPO so higher tiers cannot log on to lower tiers โ . In practice for example, your ๐ง๐ฌ (๐๐ผ๐บ๐ฎ๐ถ๐ป […]