Using Smart Cards in Active Directory? Don’t forget the NT hash.

⏱️ 60-Second Bits 🔒 𝗨𝘀𝗶𝗻𝗴 𝗦𝗺𝗮𝗿𝘁 𝗖𝗮𝗿𝗱𝘀 𝗶𝗻 𝗔𝗰𝘁𝗶𝘃𝗲 𝗗𝗶𝗿𝗲𝗰𝘁𝗼𝗿𝘆? 𝗗𝗼𝗻’𝘁 𝗳𝗼𝗿𝗴𝗲𝘁 𝘁𝗵𝗲 𝗡𝗧 𝗛𝗮𝘀𝗵. Many administrators assume Smart Cards eliminate password-related risks. They don’t. By default, 𝗦𝗺𝗮𝗿𝘁 𝗖𝗮𝗿𝗱 𝗹𝗼𝗴𝗼𝗻 replaces the password with a random 𝗡𝗧 𝗛𝗮𝘀𝗵, but that hash can remain unchanged indefinitely. To reduce the risk: ✅ Enable 𝗡𝗧 𝗛𝗮𝘀𝗵 𝗥𝗼𝘁𝗮𝘁𝗶𝗼𝗻 so the hash changes automatically based on your […]

How to prepare for Security Baselines & Tiering Model – without breaking everything?

🔒 Secure Bits 💡 𝗛𝗼𝘄 𝘁𝗼 𝗽𝗿𝗲𝗽𝗮𝗿𝗲 𝗳𝗼𝗿 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗕𝗮𝘀𝗲𝗹𝗶𝗻𝗲𝘀 & 𝗧𝗶𝗲𝗿𝗶𝗻𝗴 𝗠𝗼𝗱𝗲𝗹 – 𝘄𝗶𝘁𝗵𝗼𝘂𝘁 𝗯𝗿𝗲𝗮𝗸𝗶𝗻𝗴 𝗲𝘃𝗲𝗿𝘆𝘁𝗵𝗶𝗻𝗴? Implementing Security Baselines and the Tiering Model can significantly improve your Windows Infrastructure security. But let’s be honest — if you’re working with an 𝗼𝗹𝗱𝗲𝗿 𝗼𝗿 𝗺𝗲𝘀𝘀𝘆 𝗲𝗻𝘃𝗶𝗿𝗼𝗻𝗺𝗲𝗻𝘁, this change can turn into chaos quickly. 𝗜𝗻 𝗮 𝗻𝗲𝘄, 𝗰𝗹𝗲𝗮𝗻 𝗲𝗻𝘃𝗶𝗿𝗼𝗻𝗺𝗲𝗻𝘁? […]

Does your RDP send your credentials to the target computer?

𝗗𝗲𝗳𝗮𝘂𝗹𝘁 → 𝗛𝗮𝗿𝗱𝗲𝗻𝗲𝗱 Real configs. Real fixes. Windows & AD security. 𝗗𝗼𝗲𝘀 𝘆𝗼𝘂𝗿 𝗥𝗗𝗣 𝘀𝗲𝗻𝗱 𝘆𝗼𝘂𝗿 𝗰𝗿𝗲𝗱𝗲𝗻𝘁𝗶𝗮𝗹𝘀 𝘁𝗼 𝘁𝗵𝗲 𝘁𝗮𝗿𝗴𝗲𝘁 𝗰𝗼𝗺𝗽𝘂𝘁𝗲𝗿? ⚠️ By default, yes. When you authenticate using a standard RDP session, your credentials are sent to the target machine. If that machine is compromised, an attacker can potentially recover them from LSASS. ✅ […]

Do you RDP to your Domain Controllers from your workstation?

⏱️ 60-Second Bits 🔒 𝗗𝗼 𝘆𝗼𝘂 𝗥𝗗𝗣 𝘁𝗼 𝘆𝗼𝘂𝗿 𝗗𝗼𝗺𝗮𝗶𝗻 𝗖𝗼𝗻𝘁𝗿𝗼𝗹𝗹𝗲𝗿𝘀 𝗳𝗿𝗼𝗺 𝘆𝗼𝘂𝗿 𝘄𝗼𝗿𝗸𝘀𝘁𝗮𝘁𝗶𝗼𝗻? Even with 𝗖𝗿𝗲𝗱𝗲𝗻𝘁𝗶𝗮𝗹 𝗚𝘂𝗮𝗿𝗱 enabled, your 𝗗𝗼𝗺𝗮𝗶𝗻 𝗔𝗱𝗺𝗶𝗻 𝗰𝗿𝗲𝗱𝗲𝗻𝘁𝗶𝗮𝗹𝘀 can still end up in the 𝗠𝗦𝗧𝗦𝗖 process memory on your workstation. Credential Guard protects 𝗟𝗦𝗔𝗦𝗦. It does 𝗻𝗼𝘁 protect credentials handled by the 𝗥𝗗𝗣 client. If your workstation is compromised, an […]

New official Tiering Model guide from Microsoft!

🔒 Secure Bits 💡 𝗡𝗲𝘄 𝗼𝗳𝗳𝗶𝗰𝗶𝗮𝗹 𝗧𝗶𝗲𝗿𝗶𝗻𝗴 𝗠𝗼𝗱𝗲𝗹 𝗴𝘂𝗶𝗱𝗲 𝗳𝗿𝗼𝗺 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁! Really, not a joke! I was not expecting to live long enough to see something like this. Jokes aside, a few months ago Microsoft published not only new 𝗱𝗼𝗰𝘂𝗺𝗲𝗻𝘁𝗮𝘁𝗶𝗼𝗻 called “Tier model for Active Directory Domain Services”, but earlier this year also a 𝗚𝗶𝘁𝗛𝘂𝗯 𝗽𝗿𝗼𝗷𝗲𝗰𝘁 […]

Why should I use ADProbe? How is it different?

🔒 𝗦𝗲𝗰𝘂𝗿𝗲 𝗕𝗶𝘁𝘀 𝗪𝗵𝘆 𝘀𝗵𝗼𝘂𝗹𝗱 𝗜 𝘂𝘀𝗲 𝗔𝗗𝗣𝗿𝗼𝗯𝗲? 𝗛𝗼𝘄 𝗶𝘀 𝗶𝘁 𝗱𝗶𝗳𝗳𝗲𝗿𝗲𝗻𝘁? That is something people ask me quite often. So let me explain why I created ADProbe in the first place. ➡️ ADProbe started during my 𝗔𝗰𝘁𝗶𝘃𝗲 𝗗𝗶𝗿𝗲𝗰𝘁𝗼𝗿𝘆 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗮𝘀𝘀𝗲𝘀𝘀𝗺𝗲𝗻𝘁𝘀. At the beginning, it was not really a “tool”. It was just me using PowerShell to […]

Do you have any historic passwords in your AD?

🛠️ 𝗣𝗿𝗮𝗰𝘁𝗶𝗰𝗮𝗹 𝗕𝗶𝘁𝘀 𝗗𝗼 𝘆𝗼𝘂 𝗵𝗮𝘃𝗲 𝗮𝗻𝘆 𝗵𝗶𝘀𝘁𝗼𝗿𝗶𝗰 𝗽𝗮𝘀𝘀𝘄𝗼𝗿𝗱𝘀 𝗶𝗻 𝘆𝗼𝘂𝗿 𝗔𝗗? I am sure nobody uses passwords anymore, right? 🔹 Everything is passwordless. 🔹 Everybody has MFA. 🔹 No old accounts. 🔹 No forgotten service accounts. 🔹 Nothing to worry about. Well… in Active Directory, that is usually 𝗻𝗼𝘁 𝘁𝗵𝗲 𝗿𝗲𝗮𝗹𝗶𝘁𝘆. It is worth […]

Do your services still run under regular domain user accounts?

𝗗𝗲𝗳𝗮𝘂𝗹𝘁 → 𝗛𝗮𝗿𝗱𝗲𝗻𝗲𝗱 Real configs. Real fixes. Windows & AD security. Do your services still run under 𝗿𝗲𝗴𝘂𝗹𝗮𝗿 𝗱𝗼𝗺𝗮𝗶𝗻 𝘂𝘀𝗲𝗿 𝗮𝗰𝗰𝗼𝘂𝗻𝘁𝘀? That’s the classic 𝘁𝗿𝗮𝗽 🧨. Over-privileged accounts, passwords that never change, SPNs that make them 𝗸𝗲𝗿𝗯𝗲𝗿𝗼𝗮𝘀𝘁𝗮𝗯𝗹𝗲—and on Windows services, the credential ends up in the registry and can be retrieved in plain text. All of […]

If the ACL on AdminSDHolder changed – would you know about it?

🔒 Secure Bits 💡 𝗜𝗳 𝘁𝗵𝗲 𝗔𝗖𝗟 𝗼𝗻 𝗔𝗱𝗺𝗶𝗻𝗦𝗗𝗛𝗼𝗹𝗱𝗲𝗿 𝗰𝗵𝗮𝗻𝗴𝗲𝗱 — 𝘄𝗼𝘂𝗹𝗱 𝘆𝗼𝘂 𝗸𝗻𝗼𝘄 𝗮𝗯𝗼𝘂𝘁 𝗶𝘁? Sure, it’s a bit of an extreme case… but really — would your setup catch that? You can monitor this manually 𝘂𝘀𝗶𝗻𝗴 𝗔𝗱𝘃𝗮𝗻𝗰𝗲𝗱 𝗔𝘂𝗱𝗶𝘁𝗶𝗻𝗴 + 𝗦𝗔𝗖𝗟 and forwarding Events to your SIEM. It’s free, it works — and it […]

Never-ending battle with passwords

🔒 Secure Bits 💡 𝗜 𝘀𝗲𝗲 𝘁𝗵𝗶𝘀 𝗮𝗹𝗹 𝘁𝗵𝗲 𝘁𝗶𝗺𝗲 𝗱𝘂𝗿𝗶𝗻𝗴 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗮𝘀𝘀𝗲𝘀𝘀𝗺𝗲𝗻𝘁𝘀 ⚠️ Short passwords. “Complex” passwords that are actually predictable. Long passwords that end up in Notepad / Excel / sticky notes. It’s a 𝗻𝗲𝘃𝗲𝗿-𝗲𝗻𝗱𝗶𝗻𝗴 𝗯𝗮𝘁𝘁𝗹𝗲 – and we can’t fix it by endlessly increasing password length. ✅ The only real way forward […]