Active Directory

Active Directory Security Audit

Active Directory Audit, test and audit AD, ransomware defense, second line of defense

An Active Directory Audit is a white-box security assessment of your on-premises Active Directory that identifies misconfigurations, dangerous permissions, and attack paths leading to domain takeover, before an attacker or ransomware can exploit them.

The ransomware attacks with the biggest impact run through Active Directory: whoever takes over the domain controls every system and every file in the company. A single forgotten permission or an old misconfiguration is often all it takes. These are exactly the vulnerabilities this audit uncovers, before an attacker finds them.

Internal IT Infrastructure Penetration Test

Internal penetration test, test internal IT infrastructure, ransomware prevention

An Internal IT Infrastructure Penetration Test simulates an attacker who already has a foothold inside your network (for example after a phishing click) and tests whether they can move laterally and reach Domain Admin.

Someone on your team clicks the wrong email attachment, and an attacker is inside your network. What happens next depends on what they find there: does the attack stop at one machine, or do they move laterally and take over every system you run? This test answers that question before a real attacker does.

Kerberos: How the Authentication Protocol Works

Kerberos protocol, short explanation of Active Directory authentication

Kerberos works similarly to a passport: A passport authority issues the passport after the person has identified themselves. With this passport, they can then go to the border and prove their identity.

Active Directory Tiering: Terminal Servers and Helpdesk

Active Directory Tiering, terminal servers Tier 2, helpdesk group misconfiguration

In this blog post, I will briefly address two often overlooked vulnerabilities and misconfigurations in the Active Directory Tiering model. Specifically, I will focus on the mishandling of terminal servers and the helpdesk user group.

BloodHound Introduction for Admins

BloodHound introduction, visualize Active Directory attack paths for admins

BloodHound is a tool developed by penetration testers and red teamers to better identify and visualize attack paths in Active Directory. However, that doesn’t mean it can’t also be used effectively by admins or the blue team.

Active Directory Password Policy

Active Directory password policy, NIST vs Microsoft, VidraSec recommendation and Group Policy settings

Unfortunately, setting a good password policy for Active Directory is difficult. This is also because there are several best practices that sometimes contradict each other. In this post, I will try to address the various best practices and give my own recommendation.