Please, don’t turn your firewall off…

๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ Real configs. Real fixes. Windows & AD security. ๐ฃ๐น๐ฒ๐ฎ๐๐ฒ, ๐ฑ๐ผ๐ปโ๐ ๐๐๐ฟ๐ป ๐๐ผ๐๐ฟ ๐ณ๐ถ๐ฟ๐ฒ๐๐ฎ๐น๐น ๐ผ๐ณ๐ณโฆ It might sound surprising, but I still see this way too often: โ ๏ธ Windows Firewall completely disabled for no real reason. Sometimes it almost feels like the deployment process is: โก๏ธ Install Windows Server โก๏ธ sign in โก๏ธ […]
Does your RDP send your credentials to the target computer?

๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ Real configs. Real fixes. Windows & AD security. ๐๐ผ๐ฒ๐ ๐๐ผ๐๐ฟ ๐ฅ๐๐ฃ ๐๐ฒ๐ป๐ฑ ๐๐ผ๐๐ฟ ๐ฐ๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น๐ ๐๐ผ ๐๐ต๐ฒ ๐๐ฎ๐ฟ๐ด๐ฒ๐ ๐ฐ๐ผ๐บ๐ฝ๐๐๐ฒ๐ฟ? โ ๏ธ By default, yes. When you authenticate using a standard RDP session, your credentials are sent to the target machine. If that machine is compromised, an attacker can potentially recover them from LSASS. โ […]
Do you RDP to your Domain Controllers from your workstation?

โฑ๏ธ 60-Second Bits ๐ ๐๐ผ ๐๐ผ๐ ๐ฅ๐๐ฃ ๐๐ผ ๐๐ผ๐๐ฟ ๐๐ผ๐บ๐ฎ๐ถ๐ป ๐๐ผ๐ป๐๐ฟ๐ผ๐น๐น๐ฒ๐ฟ๐ ๐ณ๐ฟ๐ผ๐บ ๐๐ผ๐๐ฟ ๐๐ผ๐ฟ๐ธ๐๐๐ฎ๐๐ถ๐ผ๐ป? Even with ๐๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น ๐๐๐ฎ๐ฟ๐ฑ enabled, your ๐๐ผ๐บ๐ฎ๐ถ๐ป ๐๐ฑ๐บ๐ถ๐ป ๐ฐ๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น๐ can still end up in the ๐ ๐ฆ๐ง๐ฆ๐ process memory on your workstation. Credential Guard protects ๐๐ฆ๐๐ฆ๐ฆ. It does ๐ป๐ผ๐ protect credentials handled by the ๐ฅ๐๐ฃ client. If your workstation is compromised, an […]
What does your local administrator password look like?

๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ Real configs. Real fixes. Windows & AD security. ๐ช๐ต๐ฎ๐ ๐ฑ๐ผ๐ฒ๐ ๐๐ผ๐๐ฟ ๐น๐ผ๐ฐ๐ฎ๐น ๐ฎ๐ฑ๐บ๐ถ๐ป๐ถ๐๐๐ฟ๐ฎ๐๐ผ๐ฟ ๐ฝ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ ๐น๐ผ๐ผ๐ธ ๐น๐ถ๐ธ๐ฒ? And is it the same on all Windows servers or workstations? Because I still see this ๐ฎ๐น๐น ๐๐ต๐ฒ ๐๐ถ๐บ๐ฒ. โ ๏ธ One local admin password for all servers. โ ๏ธ One local admin password for all workstations. โ ๏ธ […]
What does your local group membership look like?
๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ Real configs. Real fixes. Windows & AD security. ๐ช๐ต๐ฎ๐ ๐ฑ๐ผ๐ฒ๐ ๐๐ผ๐๐ฟ ๐น๐ผ๐ฐ๐ฎ๐น ๐ด๐ฟ๐ผ๐๐ฝ ๐บ๐ฒ๐บ๐ฏ๐ฒ๐ฟ๐๐ต๐ถ๐ฝ ๐น๐ผ๐ผ๐ธ ๐น๐ถ๐ธ๐ฒ? During my security assessments, I unfortunately often see the โleft sideโ. ๐ธ Messy local group membership. ๐ธ No clear ownership. ๐ธ No defined state. ๐ธ No real control over who can access the device interactively or […]
“Just enable MFA. It’s easy.”

๐ Secure Bits ๐ก โ๐๐๐๐ ๐ฒ๐ป๐ฎ๐ฏ๐น๐ฒ ๐ ๐๐. ๐๐โ๐ ๐ฒ๐ฎ๐๐.โ Sureโฆ if you can rely on cloud identity. A lot of environments can. But ๐บ๐ฎ๐ป๐ – often the most critical ones – ๐ฐ๐ฎ๐ป๐ป๐ผ๐ be connected to the internet at all. And that changes everything. In fully ๐ผ๐ป-๐ฝ๐ฟ๐ฒ๐บ / ๐ผ๐ณ๐ณ๐น๐ถ๐ป๐ฒ Windows environments, MFA often ends up being […]
New RDP dialogs

๐ย Secure Bitsย ๐ก ๐ก๐ฒ๐ ๐ฅ๐๐ฃ ๐ฑ๐ถ๐ฎ๐น๐ผ๐ด๐ โ ๐ต๐ฎ๐๐ฒ ๐๐ผ๐ ๐๐ฒ๐ฒ๐ป ๐๐ต๐ฒ๐บ? With theย ๐๐ฝ๐ฟ๐ถ๐น ๐ฎ๐ฌ๐ฎ๐ฒ security update, the Remote Desktop Connection app (MSTSC) showsย new warnings when you open .๐ฅ๐๐ฃ ๐ณ๐ถ๐น๐ฒ๐. The point is simple: remind people thatย RDP files can be used for phishing / tricking users, and force you toย explicitly approve what the file is trying to […]
Capturing Network Traffic on Windows Server

๐ Secure Bits ๐ก ๐๐ฎ๐ฝ๐๐๐ฟ๐ถ๐ป๐ด ๐ป๐ฒ๐๐๐ผ๐ฟ๐ธ ๐๐ฟ๐ฎ๐ณ๐ณ๐ถ๐ฐ ๐ผ๐ป ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ There is an issue on a Windows Server, and I need to capture network traffic to understand what is happening. The first thought is usually: โก๏ธ Letโs install ๐ช๐ถ๐ฟ๐ฒ๐๐ต๐ฎ๐ฟ๐ธ ๐ซ But that does not always work. In many environments I work in โ especially critical […]
Do you know what proper logging in Windows looks like?

๐ย Secure Bits ๐ก ๐๐ผ ๐๐ผ๐ ๐ธ๐ป๐ผ๐ ๐๐ต๐ฎ๐ โ๐ฝ๐ฟ๐ผ๐ฝ๐ฒ๐ฟ ๐น๐ผ๐ด๐ด๐ถ๐ป๐ดโ ๐ถ๐ป ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐น๐ผ๐ผ๐ธ๐ ๐น๐ถ๐ธ๐ฒ? Most environments I see struggle with this. Logging is often leftย ๐ฑ๐ฒ๐ณ๐ฎ๐๐น๐, ๐ป๐ผ๐ถ๐๐, ๐ผ๐ฟ ๐๐ถ๐บ๐ฝ๐น๐ ๐บ๐ถ๐๐ฐ๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฒ๐ฑย โ which means you either miss real attacksโฆ or you drown in useless events. Thatโs why I builtย ๐ง๐ต๐ฟ๐ฒ๐ฎ๐๐๐ผ๐ด. ๐ฏย ThreatLog helps you ๐ฑ๐ฒ๐ฝ๐น๐ผ๐ ๐ฎ ๐ฝ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฎ๐น ๐๐๐ฑ๐ถ๐ ๐ฃ๐ผ๐น๐ถ๐ฐ๐ + ๐ฆ๐๐๐บ๐ผ๐ป […]
RDP certificate warning

๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ Real configs. Real fixes. Windows & AD security. Have you ever seen this ๐ฅ๐๐ฃ ๐ฐ๐ฒ๐ฟ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ฒ ๐๐ฎ๐ฟ๐ป๐ถ๐ป๐ด? Do you know ๐๐ต๐ฎ๐ ๐ถ๐ ๐บ๐ฒ๐ฎ๐ป๐? It means the certificate presented by the target during RDP ๐ถ๐๐ปโ๐ ๐๐ฟ๐๐๐๐ฒ๐ฑ. Often itโs just a self-signed certโwhich isnโt a huge problem: you can make it trusted or distribute your […]