Identity Attack Watch: September 2021

Identity Attack Watch Image

Cyberattacks targeting Active Directory are on the upswing, putting pressure on AD, identity, and security teams to monitor the constantly shifting AD-focused threat landscape. To help IT pros better understand and guard against attacks involving AD, the Semperis Research Team offers this monthly roundup of recent cyberattacks that used AD to introduce or propagate malware. …

How Attackers Can Use Active Directory Primary Group Membership for Defense Evasion

Identity systems—particularly Active Directory, which is the primary identity store for most businesses—are constantly under attack by cybercriminals because they are the gateway to an organization’s critical information systems, including valuable customer data. Here we’ll explore a little-known Discretionary Access Control List (DACL) tactic that attackers can use to hide membership from a group and …