Active Directory Security

Why Most Organizations Still Can’t Defend against DCShadow

Why Most Organizations Still Can’t Defend against DCShadow

  • Darren Mar-Elia
  • Jul 16, 2019

DCShadow is a readily available technique that allows an attacker to establish persistent privileged access in Microsoft Active Directory (AD). Specifically, DCShadow allows an attacker with privileged access to create and edit arbitrary objects in AD without anyone knowing. This allows the attacker to create backdoors all over AD that…

Group Policy Security– Tinkering with External Paths

Group Policy Security– Tinkering with External Paths

  • Darren Mar-Elia
  • Mar 05, 2019

If you’ve been following this blog, you know that about 2 and half years ago, I started talking about Group Policy’s precarious role in the typical enterprise’s security posture. Many, if not most, AD shops use GP to perform security hardening on their Windows desktops and servers. This includes everything…

NotPetya, the Russian Wiper

NotPetya, the Russian Wiper

  • Steve Mackay
  • Dec 19, 2018

You know Petya, and Sandworm, and Spyware, and Rootkits. Mimikatz and WannaCry, and backdoors and botnets.But do you recall....... the most damaging attack of all?....NotPetya the Russian Wiper, had a very nasty bite.And if you ever saw it, you would even say “Good Night!”.All of the other malware’s... used to…

Your Active Directory was compromised, is it all lost?

Your Active Directory was compromised, is it all lost?

  • David Lieberman
  • Nov 29, 2018

Following a 10-year stint in virtualization technologies, I joined Semperis and dove into the world of Active Directory. Over the last three years, which included some of the most vicious malware attacks ever documented, I think I have finally come up to speed on this part of the IAM world.…

Retake Control of Attribute Sync to Azure AD

Retake Control of Attribute Sync to Azure AD

  • Darren Mar-Elia
  • Oct 02, 2018

Keeping directory sync in sync with security best practices With Azure AD Connect, synchronizing directory data from on-premises Active Directory to Azure AD is both easy and efficient. But is it possible to have too much of a good thing? Security best practices limit sharing to a strict need-to-know basis.…

Should you upgrade to Active Directory 2016…or stay where you are?

Should you upgrade to Active Directory 2016…or stay where you are?

  • Sean Deuby
  • Sep 13, 2018

Should you upgrade your existing AD forest to Windows Server 2016 Active Directory (aka AD 2016), or should you leave it where it is? Despite the focus and activity around adopting cloud services today, the fact remains that Active Directory continues to underpin it all. In addition to longstanding dominance…

Hackers go phishing

Portrait of a 21st Century Active Directory Attacker

  • Noa Arias
  • May 07, 2018

It’s been almost 30 years since the movie “Hackers” was released and many of us, when we think of a cyberattacker, still picture a guy wearing a hoody, hanging in his basement while hacking away at a keyboard to gain notoriety. However, a lot has changed in the past three…

Kerberos at the Company Party

Kerberos at the Company Party

  • Sean Deuby
  • Mar 12, 2018

Back in 1999, I wrote a book on Windows 2000 Server in general, and Active Directory in particular. I try not to look back at what I wrote about AD back then compared to what I know now, but I remain fond of a passage that explained how the Kerberos…