Do you scan your AD for attack paths?

๐ Secure Bits ๐ก ๐๐ผ ๐๐ผ๐ ๐๐ฐ๐ฎ๐ป ๐๐ผ๐๐ฟ ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐ณ๐ผ๐ฟ ๐ฎ๐๐๐ฎ๐ฐ๐ธ ๐ฝ๐ฎ๐๐ต๐? From my experience doing security assessments โ thereโs ๐ฎ๐น๐๐ฎ๐๐ ๐ฎ๐ ๐น๐ฒ๐ฎ๐๐ ๐ผ๐ป๐ฒ ๐ฎ๐๐๐ฎ๐ฐ๐ธ ๐ฝ๐ฎ๐๐ต to Domain Admin. Always. And these donโt come from one big misconfigurationโฆ Theyโre built from multiple small issues ๐ฐ๐ต๐ฎ๐ถ๐ป๐ฒ๐ฑ ๐๐ผ๐ด๐ฒ๐๐ต๐ฒ๐ฟ. ๐ช๐ต๐ ๐๐ต๐ผ๐๐น๐ฑ ๐๐ผ๐ ๐๐ฐ๐ฎ๐ป ๐๐ผ๐๐ฟ ๐๐ ๐ฟ๐ฒ๐ด๐๐น๐ฎ๐ฟ๐น๐? ๐ […]
Final months for RC4

๐ Secure Bits ๐ก ๐๐ถ๐ป๐ฎ๐น ๐บ๐ผ๐ป๐๐ต๐ ๐ณ๐ผ๐ฟ ๐ฅ๐๐ฐ ๐ถ๐ป ๐๐ฒ๐ฟ๐ฏ๐ฒ๐ฟ๐ผ๐? Microsoft is phasing out RC4 for Kerberos service tickets โ and the timeline is out. ๐ข๐ป ๐๐ฎ๐ป ๐ญ๐ฏ, ๐ฎ๐ฌ๐ฎ๐ฒ, an update shipped that starts the journey toward stopping default issuance of ๐๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ ๐๐ถ๐ฐ๐ธ๐ฒ๐๐ with legacy encryption (like RC4). Why? Because ๐ฅ๐๐ฐ can still be selected […]
Detection of Misconfigurations & Threats in AD

๐ Secure Bits ๐ก ๐๐ผ ๐๐ผ๐ ๐ฟ๐ฒ๐ด๐๐น๐ฎ๐ฟ๐น๐ ๐ฐ๐ต๐ฒ๐ฐ๐ธ ๐๐ผ๐๐ฟ ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐ณ๐ผ๐ฟ ๐บ๐ถ๐๐ฐ๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฒ๐ฑ ๐๐๐๐? ACL misconfigurations are one of the ๐บ๐ผ๐๐ ๐ผ๐๐ฒ๐ฟ๐น๐ผ๐ผ๐ธ๐ฒ๐ฑ โ yet severe โ vulnerabilities in AD environments. They often stay hidden until a malicious actor finds themโฆ and by then, itโs too late. ๐๐ฒ๐ฟ๐ฒ ๐ฎ๐ฟ๐ฒ ๐ท๐๐๐ ๐ฎ ๐ณ๐ฒ๐ ๐ฒ๐ ๐ฎ๐บ๐ฝ๐น๐ฒ๐ ๐ผ๐ณ ๐๐ต๐ฒ๐๐ฒ: ๐น […]
Getting rid of NTLM is easier now

๐ Secure Bits ๐ก ๐๐ฒ๐๐๐ถ๐ป๐ด ๐ฟ๐ถ๐ฑ ๐ผ๐ณ ๐ก๐ง๐๐ ๐ถ๐ ๐ณ๐ถ๐ป๐ฎ๐น๐น๐ ๐ฒ๐ฎ๐๐ถ๐ฒ๐ฟ (๐ฎ๐ป๐ฑ ๐๐บ๐ฎ๐ฟ๐๐ฒ๐ฟ) In Windows 11 version 24H2 and Windows Server 2025, Microsoft introduced ๐ฒ๐ป๐ต๐ฎ๐ป๐ฐ๐ฒ๐ฑ ๐ก๐ง๐๐ ๐น๐ผ๐ด๐ด๐ถ๐ป๐ด โ and itโs a game changer for organizations trying to decommission NTLM. Letโs break it down ๐ โธป ๐ข๐๐ ๐ช๐๐ฌ ๐ ย ๐๐ฃ๐ข: โข ๐๐ฆ๐ค๐ถ๐ณ๐ช๐ต๐บ ๐๐ฆ๐ต๐ต๐ช๐ฏ๐จ๐ด > ๐๐ฅ๐ท๐ข๐ฏ๐ค๐ฆ๐ฅ ๐๐ถ๐ฅ๐ช๐ต ๐๐ฐ๐ญ๐ช๐ค๐บ […]
Windows Server Core

๐ Secure Bits ๐ก ๐๐ฎ๐๐ฒ ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ ๐๐ผ๐ฟ๐ฒ? ๐๐ฒ๐ฟ๐ฒ’๐ ๐ช๐ต๐ ๐ฌ๐ผ๐ ๐ฆ๐ต๐ผ๐๐น๐ฑ ๐๐ฐ๐๐๐ฎ๐น๐น๐ ๐จ๐๐ฒ ๐๐ Windows Server Core is one of the ๐บ๐ผ๐๐ ๐บ๐ถ๐๐๐ป๐ฑ๐ฒ๐ฟ๐๐๐ผ๐ผ๐ฑ ๐ฎ๐ป๐ฑ ๐๐ป๐ฑ๐ฒ๐ฟ๐๐๐ฒ๐ฑ “tools” in the Windows ecosystem. ๐ฅ๏ธ ๐ช๐ต๐ฎ๐ ๐ถ๐ ๐ถ๐? Itโs Windows Server โ but ๐๐ถ๐๐ต๐ผ๐๐ ๐๐ต๐ฒ ๐๐จ๐. Just PowerShell, Command Line, and sconfig. And yes, it still supports critical […]
RDP Security Features

๐ย Secure Bits ๐ก ๐๐ผ ๐๐ผ๐ ๐๐๐ฒ ๐ฅ๐๐ฃ ๐ฟ๐ฒ๐ด๐๐น๐ฎ๐ฟ๐น๐ ๐ถ๐ป ๐๐ผ๐๐ฟ ๐ฒ๐ป๐๐ถ๐ฟ๐ผ๐ป๐บ๐ฒ๐ป๐? Then you should know there are more secure ways to do it. ๐๐ ๐ฑ๐ฒ๐ณ๐ฎ๐๐น๐, your credentials are sent to the remote host during an RDP session โ which means if the machine is compromised, attackers can steal and reuse them. ๐๐๐ ๐๐ต๐ฒ๐ฟ๐ฒโ๐ ๐ด๐ผ๐ผ๐ฑ ๐ป๐ฒ๐๐ […]
RDP Restricted Admin Mode

๐ Secure Bits ๐ก ๐๐ผ ๐ฌ๐ผ๐ ๐จ๐๐ฒ ๐ฅ๐ฒ๐๐๐ฟ๐ถ๐ฐ๐๐ฒ๐ฑ ๐๐ฑ๐บ๐ถ๐ป ๐ ๐ผ๐ฑ๐ฒ ๐ณ๐ผ๐ฟ ๐ฅ๐๐ฃ? If not, you shouldโit ๐ฝ๐ฟ๐ฒ๐๐ฒ๐ป๐๐ ๐ฐ๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น ๐ฒ๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ. ๐ช๐ต๐ ๐๐ ๐๐ ๐ถ๐๐๐: Restricted Admin Mode was designed to let administrators connect to a potentially compromised device without passing their credentials to it. You must already be an administrator on the target machine, but your credentials […]
Kerberos Enforce AES

๐ Secure Bits ๐ก ๐ช๐ฎ๐ป๐ ๐๐ผ ๐ฑ๐ถ๐๐ฎ๐ฏ๐น๐ฒ ๐ฅ๐๐ฐ ๐ฎ๐ป๐ฑ ๐ฒ๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ ๐๐๐ฆ ๐ถ๐ป ๐๐ฒ๐ฟ๐ฏ๐ฒ๐ฟ๐ผ๐? You should โ butย ๐ฑ๐ผ๐ปโ๐ ๐ฑ๐ผ ๐ถ๐ ๐ฏ๐น๐ถ๐ป๐ฑ๐น๐. Enforcing strong authentication (like AES-only Kerberos) is an important part of ๐บ๐ผ๐ฑ๐ฒ๐ฟ๐ป ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ฎ๐๐ฒ๐น๐ถ๐ป๐ฒ๐ย โ just like LDAP signing or NTLM hardening. But in older environments,ย RC4 is still widely used, and flipping the switch ๐ฐ๐ฎ๐ป ๐ฏ๐ฟ๐ฒ๐ฎ๐ธ […]
Privileged Access Workstations (PAWs)

๐ Secure Bits ๐ก Why should you use Privileged Access Workstations (PAWs)? Accessing your infrastructure through a basic user device leaves your privileged account credentials in the deviceโs memory, and it is making you susceptible to keyloggers (software or hardware) that can capture these credentials. To mitigate this risk, implement PAWs in your environment and […]
Passwords in Group Policy

๐ Secure Bits ๐ก ๐๐ฟ๐ฒ ๐ฝ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ๐ ๐ต๐ถ๐ฑ๐ถ๐ป๐ด ๐ถ๐ป ๐๐ผ๐๐ฟ ๐๐ฟ๐ผ๐๐ฝ ๐ฃ๐ผ๐น๐ถ๐ฐ๐ถ๐ฒ๐? ๐๐ผ๐ ๐ผ๐น๐ฑ is your Active Directory? Are you sure there’s no history of stored credentials? ๐จ Before 2014, many admins used Group Policy Preferences (GPP) to ๐๐ฒ๐ ๐ฝ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ๐ for tasks, services, and other configurations. It was convenientโbut ๐ฑ๐ฎ๐ป๐ด๐ฒ๐ฟ๐ผ๐๐๐น๐ ๐ถ๐ป๐๐ฒ๐ฐ๐๐ฟ๐ฒ. Microsoft patched this in 2014, […]