“Just enable MFA. It’s easy.”

๐Ÿ”’ Secure Bits ๐Ÿ’ก โ€œ๐—๐˜‚๐˜€๐˜ ๐—ฒ๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ ๐— ๐—™๐—”. ๐—œ๐˜โ€™๐˜€ ๐—ฒ๐—ฎ๐˜€๐˜†.โ€ Sureโ€ฆ if you can rely on cloud identity. A lot of environments can. But ๐—บ๐—ฎ๐—ป๐˜† – often the most critical ones – ๐—ฐ๐—ฎ๐—ป๐—ป๐—ผ๐˜ be connected to the internet at all. And that changes everything. In fully ๐—ผ๐—ป-๐—ฝ๐—ฟ๐—ฒ๐—บ / ๐—ผ๐—ณ๐—ณ๐—น๐—ถ๐—ป๐—ฒ Windows environments, MFA often ends up being […]

Pick only 3 security controls for your AD

๐Ÿ”’ย Secure Bits ๐Ÿ’ก ๐—œ๐—ณ ๐˜†๐—ผ๐˜‚ ๐—ฐ๐—ผ๐˜‚๐—น๐—ฑ ๐—ธ๐—ฒ๐—ฒ๐—ฝ ๐—ผ๐—ป๐—น๐˜† ๐Ÿฏ ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฐ๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐˜€ ๐—ถ๐—ป ๐—ฎ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐—ฒ๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜ – ๐˜„๐—ต๐—ฎ๐˜ ๐˜„๐—ผ๐˜‚๐—น๐—ฑ ๐˜†๐—ผ๐˜‚ ๐—ฝ๐—ถ๐—ฐ๐—ธ? Iโ€™m curious what your โ€œtop 3โ€ are (I know it depends a lot on what we are protecting, but let’s try). ๐—œ๐—ณ ๐—œ ๐—ต๐—ฎ๐—ฑ ๐˜๐—ผ ๐—ฐ๐—ต๐—ผ๐—ผ๐˜€๐—ฒ (๐—ป๐—ผ๐˜ ๐—ฎ ๐˜€๐—ถ๐—บ๐—ฝ๐—น๐—ฒ ๐—ฐ๐—ต๐—ผ๐—ถ๐—ฐ๐—ฒ), ๐—บ๐—ถ๐—ป๐—ฒ ๐˜„๐—ผ๐˜‚๐—น๐—ฑ ๐—ฏ๐—ฒ: 1๏ธโƒฃย ๐—ง๐—ถ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด […]

How long has your Active Directory been around?

๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—›๐—ผ๐˜„ ๐—น๐—ผ๐—ป๐—ด ๐—ต๐—ฎ๐˜€ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐—ฏ๐—ฒ๐—ฒ๐—ป ๐—ฎ๐—ฟ๐—ผ๐˜‚๐—ป๐—ฑ? The older the AD, the more โ€œhistoryโ€ it carries. Admins change, projects come and goโ€ฆ but the ๐—น๐—ฒ๐—ณ๐˜๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐˜€ ๐˜€๐˜๐—ฎ๐˜† – in the form of forgotten misconfigurations and risky settings that attackers love โš ๏ธ Once an attacker gets a foothold, one of the first […]

What’s 1 minute of security training worth?

๐Ÿ’ฐ ๐—ช๐—ต๐—ฎ๐˜โ€™๐˜€ ๐Ÿญ ๐—บ๐—ถ๐—ป๐˜‚๐˜๐—ฒ ๐—ผ๐—ณ ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐˜๐—ฟ๐—ฎ๐—ถ๐—ป๐—ถ๐—ป๐—ด ๐˜„๐—ผ๐—ฟ๐˜๐—ต? Many AD security trainings are premium live workshops, often priced ๐—ฎ๐—ฏ๐—ผ๐˜ƒ๐—ฒ $๐Ÿฏ,๐Ÿฌ๐Ÿฌ๐Ÿฌ. I built ๐—•๐˜‚๐—ถ๐—น๐—ฑ๐—ถ๐—ป๐—ด ๐—ฎ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐—–๐—ผ๐˜‚๐—ฟ๐˜€๐—ฒ to make this ๐—ธ๐—ป๐—ผ๐˜„๐—น๐—ฒ๐—ฑ๐—ด๐—ฒ ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€๐—ถ๐—ฏ๐—น๐—ฒ at a fraction of the cost โ€” with 365-day on-demand access. โœ… Hands-on experience โ€” You actually build and harden your own […]

Do you run Active Directory Certificate Services (AD CS)?

๐Ÿ› ๏ธย Practical Bits ๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐—ฟ๐˜‚๐—ป ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐—–๐—ฒ๐—ฟ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€ (๐—”๐—— ๐—–๐—ฆ)? When was the last time you checked it for vulnerabilities? In security assessments this isย ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐—ด๐—ฟ๐—ฒ๐—ฒ๐—ปย โ€” itโ€™s common to find at least one certificate template that gives a ๐Ÿšจstraight path toย ๐——๐—ผ๐—บ๐—ฎ๐—ถ๐—ป ๐—”๐—ฑ๐—บ๐—ถ๐—ป. โžก๏ธ Set asideย one hourย and scan your AD CS. Itโ€™s one of the ๐—ต๐—ถ๐—ด๐—ต๐—ฒ๐˜€๐˜-๐—ถ๐—บ๐—ฝ๐—ฎ๐—ฐ๐˜ […]

Do you still need a Password Policy nowadays?

๐Ÿ› ๏ธ Practical Bits ๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐˜€๐˜๐—ถ๐—น๐—น ๐—ป๐—ฒ๐—ฒ๐—ฑ ๐—ฎ ๐—ฃ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ ๐—ฃ๐—ผ๐—น๐—ถ๐—ฐ๐˜† ๐—ป๐—ผ๐˜„๐—ฎ๐—ฑ๐—ฎ๐˜†๐˜€? Yes โ€” even if you use MFA or passwordless options. In Active Directory there are always ๐—ฒ๐˜…๐—ฐ๐—ฒ๐—ฝ๐˜๐—ถ๐—ผ๐—ป๐˜€: service accounts, temporary accounts, break-glass accounts, newly created usersโ€ฆ and those still rely on passwords. Strong password + lockout policies ๐—ฟ๐—ฎ๐—ถ๐˜€๐—ฒ ๐˜๐—ต๐—ฒ ๐—ฏ๐—ฎ๐—ฟ against password spraying and […]

Do you know how attackers hide inside Active Directory?

๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐—ธ๐—ป๐—ผ๐˜„ ๐—ต๐—ผ๐˜„ ๐—ฎ๐˜๐˜๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ฟ๐˜€ ๐—ต๐—ถ๐—ฑ๐—ฒ ๐—ถ๐—ป๐˜€๐—ถ๐—ฑ๐—ฒ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜†? Itโ€™s called persistence. Attackers often want to stay in your environment long-term without being spotted – which means being a loud Domain Admin is usually not the plan. To spot this, you need to understand what options attackers have and how ACLs […]

Active Directory SPN

๐Ÿ› ๏ธย [๐—ฃ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—•๐—ถ๐˜๐˜€] – ๐—ฆ๐—ฃ๐—ก Go and check your Active Directory for SPNs. You can do so easily with any simple PowerShell script. Example: ____ Get-ADUser -LDAPFilter ‘(&(objectCategory=user)(!(samAccountName=krbtgt)(servicePrincipalName=*)))’ -Properties Name, UserPrincipalName, ServicePrincipalName | Select-Object Name, UserPrincipalName, @{N=”ServicePrincipalName”;E={$_.ServicePrincipalName -join “, “}} ____ (๐™ฉ๐™๐™ž๐™จ ๐™ž๐™จ ๐™–๐™ก๐™จ๐™ค ๐™ฅ๐™–๐™ง๐™ฉ ๐™ค๐™› ๐™ข๐™ฎ ๐™ฉ๐™ค๐™ค๐™ก ๐˜ผ๐˜ฟ๐™‹๐™ง๐™ค๐™—๐™š) โ“Once you have results, go through the […]

Do you use Security Baselines?

๐——๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ โ†’ ๐—›๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐—ป๐—ฒ๐—ฑ Real configs. Real fixes. Windows & AD security. ๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐˜‚๐˜€๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—•๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€? You should. They set a clear, enforceable standard for Windows & AD. Without baselines youโ€™re either on defaults or on local tweaksโ€”both ๐—น๐—ฒ๐—ฎ๐—ฑ ๐˜๐—ผ ๐—ฑ๐—ฟ๐—ถ๐—ณ๐˜, ๐—ถ๐—ป๐—ฐ๐—ผ๐—ป๐˜€๐—ถ๐˜€๐˜๐—ฒ๐—ป๐—ฐ๐˜†, ๐—ฎ๐—ป๐—ฑ ๐—ฒ๐—ฎ๐˜€๐˜† ๐—ผ๐—ฝ๐—ฒ๐—ป๐—ถ๐—ป๐—ด๐˜€ for attackers. ๐—ช๐—ต๐—ฎ๐˜ โ€œ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—•๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€โ€ ๐—ฎ๐—ฟ๐—ฒ: A curated set of […]

Can your Domain Admins log in to endpoints?

๐——๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ โ†’ ๐—›๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐—ป๐—ฒ๐—ฑ Real configs. Real fixes. Windows & AD security. Can your ๐——๐—ผ๐—บ๐—ฎ๐—ถ๐—ป ๐—”๐—ฑ๐—บ๐—ถ๐—ป๐˜€ ๐—น๐—ผ๐—ด ๐—ถ๐—ป ๐˜๐—ผ ๐—ฒ๐—ป๐—ฑ๐—ฝ๐—ผ๐—ถ๐—ป๐˜๐˜€? ๐—ง๐—ต๐—ฒ๐˜† ๐˜€๐—ต๐—ผ๐˜‚๐—น๐—ฑ๐—ปโ€™๐˜. Disable it. Build multiple tiers with separate privileged accounts for each tier and ๐—ฟ๐—ฒ๐˜€๐˜๐—ฟ๐—ถ๐—ฐ๐˜ ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ with GPO so higher tiers cannot log on to lower tiers โœ…. In practice for example, your ๐—ง๐Ÿฌ (๐——๐—ผ๐—บ๐—ฎ๐—ถ๐—ป […]