Threat Research

AD Security Research: Breaking Trust Transitivity

AD Security Research: Breaking Trust Transitivity

  • Charlie Clark
  • Mar 14, 2023

While playing with Kerberos tickets, I discovered an issue that allowed me to authenticate to other domains within an Active Directory (AD) forest across external non-transitive trusts. This means that there is in fact no such thing as a “non-transitive trust.” The term is at best misleading and offers systems…

Identity Attack Watch: AD Security News, February 2023

Identity Attack Watch: AD Security News, February 2023

  • Semperis Research Team
  • Feb 28, 2023

As cyberattacks targeting Active Directory continue to rise, AD security, identity, and IT teams face mounting pressure to monitor the evolving AD-focused threat landscape. To help IT and identity security professionals understand and improve AD security, the Semperis Research Team publishes a monthly roundup of recent identity-related cyberattacks. This month's…

Identity Attack Watch: AD Security News, January 2023

Identity Attack Watch: AD Security News, January 2023

  • Semperis Research Team
  • Jan 31, 2023

Cyberattacks targeting Active Directory are on the upswing, putting pressure on identity and Active Directory (AD) security teams to monitor the constantly shifting AD-focused threat landscape. To help IT pros better understand and guard against attacks involving AD, the Semperis Research Team offers this monthly roundup of recent cyberattacks that…

Identity Attack Watch: December 2022

Identity Attack Watch: December 2022

  • Semperis Research Team
  • Dec 30, 2022

Cyberattacks targeting Active Directory are on the upswing, putting pressure on AD, identity, and security teams to monitor the constantly shifting AD-focused threat landscape. To help IT pros better understand and guard against attacks involving AD, the Semperis Research Team offers this monthly roundup of recent cyberattacks that used AD…

Identity Attack Watch: November 2022

Identity Attack Watch: November 2022

  • Semperis Research Team
  • Nov 30, 2022

Cyberattacks targeting Active Directory are on the upswing, putting pressure on AD, identity, and security teams to monitor the constantly shifting AD-focused threat landscape. To help IT pros better understand and guard against attacks involving AD, the Semperis Research Team offers this monthly roundup of recent cyberattacks that used AD…

SyncJacking: Hard Matching Vulnerability Enables Azure AD Account Takeover

SyncJacking: Hard Matching Vulnerability Enables Azure AD Account Takeover

  • Tomer Nahum
  • Nov 18, 2022

This post describes an abuse of hard matching synchronization in Azure AD Connect that can lead to Azure AD account takeover. These findings build on the research that Semperis published in August, which described abuse of soft matching (also known as SMTP matching). This SyncJacking vulnerability means that an attacker…

Identity Attack Watch: October 2022

Identity Attack Watch: October 2022

  • Semperis Research Team
  • Oct 31, 2022

Cyberattacks targeting Active Directory are on the upswing, putting pressure on AD, identity, and security teams to monitor the constantly shifting AD-focused threat landscape. To help IT pros better understand and guard against attacks involving AD, the Semperis Research Team offers this monthly roundup of recent cyberattacks that used AD…

Preventing a SYSVOL Horror Story

Preventing a SYSVOL Horror Story

  • Tammy Mindel
  • Oct 20, 2022

October is Cybersecurity Awareness Month, and an excellent time to bust the ghosts of configurations past. One of the actions that the Cybersecurity & Infrastructure Security Agency (CISA) and National Cybersecurity Alliance (NCA) recommend taking is “Update your software.” A perfect place to start: Rid your domains of the outdated…