Active Directory Security

Active Directory Experts Have a Future in Security

Active Directory Experts Have a Future in Security

  • Gil Kirkpatrick
  • Apr 14, 2021

Between the growth of cloud applications and a changing threat landscape, the world of a Microsoft Active Directory (AD) professional has changed significantly over the last 20-plus years. As in any other area of IT, the drive and curiosity to level up one’s skills to keep pace with evolving technologies…

How to Defend Against Active Directory Attacks That Leave No Trace

How to Defend Against Active Directory Attacks That Leave No Trace

  • Guido Grillenmeier
  • Apr 01, 2021

Cybercriminals are using new tactics and techniques to gain access to Active Directory in novel ways, making their attacks even more dangerous—and more necessary to detect.  One of the most important parts of any cybersecurity strategy is detection. Having an ability to spot the bad guy entering, moving about, or worse—administering—your network is…

Identity Attack Watch: March 2021

Identity Attack Watch: March 2021

  • Semperis Research Team
  • Mar 26, 2021

Cyberattacks targeting Active Directory are on the upswing, putting pressure on AD, identity, and security teams to monitor the constantly shifting AD-focused threat landscape. To help IT pros better understand and guard against attacks involving AD, the Semperis Research Team offers this monthly roundup of recent cyberattacks that used identity…

Do You Know Your Active Directory Security Vulnerabilities?

Do You Know Your Active Directory Security Vulnerabilities?

  • Sean Deuby
  • Mar 18, 2021

Microsoft Active Directory security involves dealing with a mixed bag of risks, ranging from management mistakes to unpatched vulnerabilities. We often write about the fact that cyber-attackers are targeting AD to elevate privileges and gain persistence in the organization. Investigate a typical data breach, and you’ll find that stolen credentials…

DnsAdmins Revisited

DnsAdmins Revisited

  • Yuval Gordon
  • Mar 15, 2021

How Potential Attackers Can Achieve Privileged Persistence on a DC through DnsAdmins The Semperis Research Team recently expanded on previous research showing a feature abuse in the Windows Active Directory (AD) environment where users from the DnsAdmins group could load an arbitrary DLL into a DNS service running on a…

Semperis Identity Attack Watch: February 2021

Semperis Identity Attack Watch: February 2021

  • Semperis Research Team
  • Feb 26, 2021

Cyberattacks targeting Active Directory are on the upswing, putting pressure on AD, identity, and security teams to monitor the constantly shifting AD-focused threat landscape. To help IT pros better understand and guard against attacks involving AD, the Semperis Research Team offers this monthly roundup of recent cyberattacks that used AD…

Top Security Risks to Watch for in Shifting to Hybrid Identity Management

Top Security Risks to Watch for in Shifting to Hybrid Identity Management

  • Doug Davis
  • Feb 19, 2021

It's easy to see why enterprises are gravitating toward a hybrid identity management model that promises the best of both worlds—a little bit in the cloud, and a little bit on-premises. In an Active Directory-centric environment, leveraging the cloud means integrating with Azure Active Directory.   Azure Active Directory (AAD),…

Semperis Contributes to Two NIST Data Integrity Practice Guides

Semperis Contributes to Two NIST Data Integrity Practice Guides

  • Michele Crockett
  • Feb 12, 2021

NIST recommends complementary solutions, much like a team of security superheroes To succeed in protecting your company’s data against ransomware, you need to proceed as if you’re assembling a team of superheroes. Each team member has a singular power that individually appears limited. But together, they can conquer evil.  As the number of cyberattacks…