In dieser Folge des eSecurityPlanet-Podcasts spricht Moderator Ken Underhill mit Marty Momdjian, Global Field CTO bei Semperis, über die wachsende Bedeutung der Identitätssicherheit in der heutigen Bedrohungslandschaft. Im Mittelpunkt des Gesprächs steht die Frage, wie Cyberkriminelle kritische Identitätsplattformen wie Active Directory und Microsoft Entra ID ins Visier nehmen, um Ransomware-Angriffe und andere schwerwiegende Cybervorfälle zu verüben.
Marty gibt Einblicke in die Taktiken, mit denen Angreifer die Identitätsinfrastruktur kompromittieren, in die wichtigsten Warnzeichen, auf die Sicherheitsteams achten sollten, sowie in die Maßnahmen, die Unternehmen ergreifen können, um identitätsbasierte Sicherheitsverletzungen einzudämmen und sich davon zu erholen, bevor diese zu erheblichen Betriebsstörungen eskalieren. Im Gespräch wird zudem erörtert, warum die Identitätsinfrastruktur mittlerweile als „Tier-0-Infrastruktur“ gilt, welche häufigen Lücken bei der Planung von „ incident response “ bestehen und wie wichtig es ist, die Wiederherstellung der Identitätsinfrastruktur als Teil einer umfassenderen Strategie zur Cyber-Resilienz vorzubereiten.
Ganz gleich, ob Sie in leitender Position im Bereich Cybersicherheit tätig sind, als IT-Experte arbeiten oder im Risikomanagement tätig sind – diese Folge bietet Ihnen praktische Anleitungen zur Stärkung des Identitätsschutzes, zur Verbesserung der Bereitschaft für Cyberkrisen und zur Minderung der Auswirkungen moderner Cyberangriffe.
Welcome to the E Security Planet podcast. I’m Ken Underhill. I spent over 20 years in IT and cybersecurity. And today we’re gonna be talking about a critical issue. What happens in that first 24 hours of an identity based attack? And so joining me is Marty Momdjian. He’s General Manager of Ready1 and Strategic Initiatives at Semperis. Marty helps organizations prepare for and recover from the types of incidents we’ll be talking about today. And we’re also going be talking about what security teams need to watch out for, how they can actually contain damage and how to recover quickly. So Marty, thanks again for taking some time out of your busy day to join me. Absolutely. Thank you for having me, Ken. So I wanted to just jump right into it. For several years now, we’ve heard the narrative, you know, identity is the perimeter. So why do you think that identity systems have become such a critical focus for attackers? And second part of the question, why should enterprises now look at Active Directory and Entra ID as Tier 0 infrastructure? I mean, simple answer is everything we do revolves around logging in. Right? I kind of look at it this way, every day when we wake up in the morning, workday, non-workday, what’s the first thing we do? Right? We take out our phones, we log in to check email, we log in to our phone, we log in to check our calendar, and then I get to my desk, or most of us are working, you know, from anywhere, most of the time are traveling, being in an office, you’re logging in. You’re logging into, you know, ninety percent of organisations are logging into Active Directory. Our focus on everything that we do in technology is you have to log in to do something to be productive, you know, talk to peers, customers, partners, other organisations. The main reason why it’s such a critical point right now is everything revolves around logging in for us, machine accounts, all the applications, all the infrastructure, all technology has to log in to do something. Threat actors know that, Right? What’s the number one impact that could cause you or any organisation is prevent you from being able to log in, to bring things to a grinding halt. If you can’t log in, your business can’t continue. At scale, if your entire business can’t log in, you don’t have a real business to operate at the end of the day. And it’s also one of the most complex things because of how interconnected technology is. Hundred percent. And you mentioned a little on the machine aspect there, right, the non-human identities, which really, really expands the attack surface these days. When we’re just talking about incidents, so when you’re responding to ransomware or some other type of major incident, like how often do you see identity as being attacked early by threat actors in the attack chain? And especially when we’re thinking of hybrid environments. So those hybrid AD and Entra ID environments, how often are you seeing these threat actors, like, actually attacking identity very early in the attack chain? Almost every time. Right? There there’s two aspects of it. Historically, it’s been why do I need to break in? I come from a world of incident response. Why do I need to break in when I can just log in? I can log in as you. I can log in as me. I can log in as a machine account and try to go undetected because all of our detection mechanisms in the world of cybersecurity are built on abnormalities or certain things getting happen happening at an endpoint or a server, an application, and a sensor detecting that abnormality, and then we start responding to it. But if I’m logged in as you from where you’re supposed to be, how do you really detect that? And threat actors and adversaries know if I can log in as you, I could sit in your environment, I can go do reconnaissance, I could figure out what you have, where you have it, how you have it. That’s the first aspect. The second aspect is we’re seeing a big evolution right now of threat actors not attacking the individuals as much, but attacking the underlying identity infrastructure. Why am I gonna try to compromise, you know, Underhill Incorporated as Ken when I could go compromise the underlying identity infrastructure and get to every single company that’s in that underlying identity infrastructure that’s out there in the cloud, especially in a hybrid environment. Everybody has some kind of hybrid IDP that’s hosted somewhere else, you know, whether it’s Microsoft Ping, Okta, right, great technologies, great solutions that are out there, but if I can compromise one, I can compromise all. It’s kind of the end goal, end goal as long as I can undetected. And there’s also a big shift right now where historically, we were always worried about dwell time. Right? Adversary logs in as me. They bypass MFA. They’re kind of in the environment not doing anything too crazy so they don’t get detected based off the EDR sensors and tools that are out there. Now that dwell time is shrinking because of the advent of just AI at scale, the tools they have available, same things we have available, so they’re threat actors. Right? Dwell time is significantly shrinking. So now I don’t have to just log in as you. I could log in as you, pivot, go after vulnerabilities, go after a very specific attack chain, and even when I get detected, I’m still logged in, and I’m going to gain access to multiple accounts, multiple machine accounts that detection mechanisms don’t exist for at scale. You talked a little bit about recon and the pivoting the lateral movement. In the first few hours of an identity based attack, what are attackers typically trying to accomplish inside of that identity infrastructure? And what are some of the warning signs or key things that a security team should be looking out for to kind of see like, hey, we might be having an identity based incident right now? Number one is privileged accounts, right? Lateral movement, privileged accounts. If I can get my hands on your domain admin account or any type of privileged account that can pivot to domain admin, I can get the keys to your kingdom. Number one on the list, whether it’s on prem, hybrid environment, why am I going to go after one server or application to get your critical data for exfiltration? What I could go after all of it, right? If I was the bad guy, which I’m not, but if I was, I don’t want to log in as Ken, I want to log in as Ken’s administrator to gain access to everything that Ken has access to and all the other administrators and bypass any security controls because if I get a privileged account, I can disable your security controls. That is always in the first couple of hours of a major cyber incident. Second part question, it’s not no longer are the days of, hey, I’m gonna go detect something at an endpoint and see how a bad actor got in and gained access. Now it’s at the core identity infrastructure. Right? It’s Active Directory. It’s Entra. It’s your IDP. They’re gaining access somehow, and if it’s in the cloud, you don’t have the same detection mechanisms anymore. So we’re a lot slower to respond where attackers are coming at organizations, at us, at everybody at machine speed. We’re responding at human speed because of legacy technology than what we have available. We have to shift that mindset to say, you know what? When there is some kind of abnormal behavior, we have to detect and respond a lot faster and figure out what that attack chain looks like before the threat actors do. It’s all now coming down to privileged access, privilege escalation, and attack paths for identity, and it’s all over the place, especially with hybrid environments. I don’t know anybody that doesn’t have a hybrid environment. If an identity has access on prem, it probably has access to some kind of application that’s a critical business application in some fashion in the cloud somewhere, whether it’s my private cloud or not, whether it’s public cloud, it’s SaaS, and it all comes back down to I can have all the segmentation security tools and everything in place, but if a threat actor is logged in as an individual that you can’t really detect and it’s hybrid, it becomes infinitely more complex. So now I have to, before they do, figure out what my attack paths are and put controls into place in the texture mechanisms on my attack path to each one of my applications, my SaaS infrastructure, my on prem infrastructure, and where are the codependencies on prem and in the cloud for that identity. And then all the fifty million machine accounts that we spin up and the non human identities behind that for all the workloads. Let’s pivot a little to the security leadership side. If we’re looking at just the first 24 hours of an incident, what are the most important things in your opinion that an enterprise security leader needs to quickly understand to allow them to assess a scope, the overall business impact, overall operational risk of the incident, like for them to get the data they need to then go report to other leaders on the executive team or even to the board, what do they actually need to be looking at in the first twenty four hours? My go to is don’t treat it as specific business applications or business processes that impact people or revenue. Treat it as, you know, you do tabletop exercises and simulations, and now it’s coming down to speed to respond, And what information do I need in that first 15 minutes of an incident occurring that I can make decisions and take those decisions to leadership? If a, b, and c happens, here’s the information that I need to really determine the business impact very quickly because I gotta react very quickly. Historically, over the years of incident response and crisis response, it was always, hey, I have all these metrics for severity escalation paths. I have an hour to stand up incident respond, and then I have two, three hours to figure out, do some quick forensics, figure out my impact, or I can make a business impact analysis document, have a process. All that’s gone out the window. Right? Nowadays, it’s, yeah, you did have 24 hours to figure out what is happening before you respond. Now you probably have like an hour or two max when an adversary or if it’s a, you know, nation-state-sponsored threat actor who’s very, very advanced and a real persistent threat in your environment, now it’s minutes to hours to respond. Right? Each organisation needs to figure out how fast can I detect, more importantly, how fast can I stand up my IR team, notify who needs to be notified, collect that information, and start making decisions very, very, very quickly? And what information do I need to make those decisions? Is it what’s the impact to my business? Or, hey, if I do A, B, and C, I am gonna impact the business at a smaller scale, you know, I’m gonna sever the hand to save the body and turn something off to cut off the adversary’s access while I figure out what’s going on. But my 80 percent or 70 percent of my business is gonna continue. You mentioned a little bit on the visibility challenges of of the hybrid identity environments. How does that complexity overall of the hybrid environments impact? You know, of course you mentioned a little on visibility, but you can expand on that, but also containment as well as those actual response decisions when we got that live incident. My mindset is the faster you detect, the faster you respond, the faster you contain, the faster you can recover. You should never compromise on the time it takes to containment and wait for approvals. You should contain as quickly as possible even if that includes stopping certain business services to figure out what is happening before it’s too late. The faster you detect, we know detection mechanisms are in place, then the complexity hits of, yes, I have my account, I have my applications that I use every day, which are essentially the basics of what I’m doing at work day to day. Right? I’m communicating and collaborating and doing certain things, but what else is my account tied into? It’s tied into probably ten different non human identities, all the stuff that I have to run my agents, all the stuff that I have in the background that I’m spinning up that could be governed or not. And most organisations still haven’t wrapped their head around identity governance when it comes to non human identities. It’s still so new and expanding so rapidly. It’s really understanding what’s the governance around that, and then if I am gonna disable or stop something so I can do forensics and respond quickly as possible, Instead of saying, hey, this is the business impact it’s going to cause, it’s how fast can I notify those folks that are going to be impacted so they can go to downtime? And technology is changing on a weekly and monthly, yearly basis. It’s whatever you document now is going to be outdated in six months. Put in processes in place to say I’m going to notify the stakeholders immediately, and they should probably know what to do, right? Instead of focusing on I’m going to create all this documentation that will probably be outdated. From your experience, where do enterprise incident response as well as crisis management plans, where are those most common areas where those typically break down when we’re talking about identity based incidents? The threat actors will target the incident responder account. Right? Again, back to if I was the bad guy and I gain access to an account and I want to gain access to what applications infrastructure stuff that you have, I’m not gonna go digging around and try to discover and find something anymore because I’m probably gonna get detected. What I’m essentially gonna go after is I want the incident responders or the IT person’s account. When I gain access to that account, I want to literally gain access to your incident response playbooks, your documentation for your contacts, so I can know what you’re doing, and we’re seeing this in the wild, where threat actors are gonna gain access and get your IR runbook, figure out what your bridges look like, try to join those bridges. They’re gonna get to your response documentation, your downtime documentation that you have. If they’re not offline, if they’re on SharePoint, if they’re on Teams, if cyber has access to it or your users do, so do the bad guys, more than likely. And when they gain that level of access, they’re gonna go in and they’re gonna say, okay, here’s the bridge that they’re on, I’m gonna join it and I’m gonna stay one step ahead. Or I’m gonna wipe out your runbooks and playbooks so you don’t even have them at the end of the day. A lot of organizations out there have a good handle on restoration of more traditional infrastructure, right? So applications, my endpoints go down. Why do you think that identity recovery is often more difficult than a lot of these organizations expect compared to that more traditional restoration of, you know, different infrastructure. Number one rule is if I can’t log in, can’t do incident response. Right? We always forget about the fact that there’s all these great incident response plan escalation steps, you know, create all these matrices of things that we have to do depending on the type of incident. But you forget if identity goes offline, my IR team can’t log in. They can’t actually do a response. I can’t get to my backups. I can’t get to my, you know, playbooks or runbooks and my logs and things that I need to get to. All of the cyber tools that we have require some kind of machine account in the background. Right? If those machine accounts and service accounts go offline, I don’t have my responder tools. Same thing for the crisis management team. Right? We always have this thing in our head of, oh, if I go down, I’m gonna go to my offline communication. We’re discovering more and more that relies on your production IDP to work because you have to verify the identity. They don’t have a way to communicate now. We have to shift our focus to say the first thing we’re gonna do is restore identity so I could log in, get to what I need to, talk to whoever I need to talk to and communicate with, and make sure my tools for response are actually working in the worst case scenario so I could start doing incident response. Alright? We always skip over that phase and say, I’m gonna go to my backups. Great. My machine account gets compromised for all my applications that are doing my backups. I’m gonna restore those machine accounts. What do I need for that? Active Directory and Entra. I need my IDP. Right? I need MFA to actually function so I can log in. All of that requires identity to function. All of that requires somebody to be able to log in to something to start doing the response, to start sending out notifications, to start doing x, y, and z, and we keep forgetting about the part. None of that works if my IR team can’t log in and other people can’t log in. You mentioned earlier about tabletopping. Just to kind of expand on that a little bit because you talked about here’s when an incident is kind of becoming something around, like downtown, etcetera. So for example, you were talking about table topping to know when your particular business, when you should cut off you know, the attack and, you know, keep maybe 70, 80 percent of the business still operating while dealing with that. So the question I wanted to ask is at what point, like, is there a specific point that’s kind of a generic point organizations watching this can take away, but at what point does an identity based attack become more than just like a basic security incident and kind of turns into that broader business crisis where we’re talking about the extended downtime, potential compliance issues, where we might need to pull in executive leadership or even, you know, there’s a discussion of board level risk. Like, is there a certain point that your generic organization could take away out there or is it too specific to a particular organization? It’s a mix of both. It is specific to organizations where they look at it as if this application or business or this data gets compromised, it’s, hey, I got to actually escalate this up because it’s privileged information, not just privileged access, it’s IP information, it’s corporate information, they’re consumers and so on. I look at it as a more simple aspect of if an identity is compromised that has some kind of access to privileged data, corporate data that is specific to them, automatic escalation. Right? Because you’ve got to make a quick decision to shut some type of access off, stand up incident response, do forensics, do whatever you need to do, and if there’s regulatory and compliance and stuff you have to adhere to on the state, federal, whatever level that you have to adhere to, should be one circuit breaker. My go to has always been on the cyber side, if a privileged account is compromised or if an account or an identity is compromised that has access to some kind of cybersecurity tool or collaboration tool that is involved, like my SIM, my SOAR, my EDR, my firewalls, whatever, immediate escalation because you need maximum and quick response to that. Because if a threat actor gained access to a responder account or a privileged account, that means they have a lot more access than we think they do. And at that point, you know, skip the pleasantries, incident response, escalate the crisis response, and say, get on standby. We have a threat actor in the network. We know where it’s coming from, but we gotta figure out what else they got access to, and I gotta start shutting services down, which means I gotta services down, which means I got to notify the business stakeholders in X amount of time, which means sooner or later it’s going become public. Right? Why did I shut these services down? Are my consumers impacted? You know, I remember when I did IR for healthcare, a lot of times if the EMR system was impacted, we immediately killed it and went to paper charting until we could figure out what exactly was going on in the scope. And you mentioned compliance and that ties directly to HIPAA and other compliance for healthcare. From your experience, what separates the organizations that are able to recover quickly from these types of identity based attacks, from those that are maybe have like a prolonged operational disruption, or they’ve got different types of challenges in just the recovery itself? The organizations that recover very quickly that you don’t even hear about have purpose built solutions for identity recovery and they have their processes in place, right? The ones that you see on the news, a lot of the ones that I’ve worked on didn’t think about having identity specific recovery mechanisms and processes and solutions in place. Right? The reason why Semperis even exists. Right? Purpose built recovery to say when the worst possible thing happens, I know I could get Active Directory, Entra, Okta, identities back online as quickly as possible so I can start responding and recovering everything else. The organizations that just say I have my generic backup solution or some kind of backup solution who also happens to do just identity stuff, That’s amazing. Great. But that recovery probably relies on your identity infrastructure to function, and you’re not gonna be able to recover identity. Right? You because I can’t log into it because it’s behind my IDP, which relies on Active Directory. It’s this big circular thing we kinda go through. And the other part is there’s the organizations that recover very quickly are the ones that make decisions. Big, giant, major events that I’ve worked on. When we made a decision to respond very quickly and to isolate as quickly as possible, we were able to recover a lot faster because we’re stopping, you know, we’re kinda I come from the world of healthcare. Right? We’re kinda pulling the tourniquet as hard as we can to try to save the leg at that point. And we’re saying, you know what? I might lose a couple of fingers or toes, but I know I’m gonna save part of the leg because I can respond a lot faster. I just cut off my access, but I also cut off their access, and 80 percent of things are still functioning. I’m hobbling along, but my team has time to do response and forensics and get their logs and do what they need to. Versus the organizations that are still kinda like, well, let’s go see how what the area of impact for this is. What’s the splash damage? What’s the, you know, what’s impacted? Is it small? Is it large? Like, by the time you figure that out, the adversaries are probably causing a lot of damage. And the number one thing is, let me cause the damage, exfiltrate what I can, take out your ability to be able to restore from your legacy backup infrastructure, and be able to restore your hybrid environments, and then I just have to knock out identity, and I know it’s gonna take you thirty days to rebuild that from scratch. Those are the ones that you’re seeing on the news, whether it’s healthcare or anything else. Right? They don’t have a way to actually get back to being able to log in and start doing something. So if there was one change that you would recommend, so if you had to pick one change, and you can separate it by size of organization if you want to, but for the organizations out there that are maybe watching this, if there was one change they could make to improve their overall readiness for identity based attacks, like what is that one change that you would recommend for them? Move away from tabletop exercise and actually do simulations. Right? It’s great sitting around the table and discussing the things that could go wrong and how you’re gonna do restoration. Actually, go and do a quarterly, annual, whatever you need to, and plan an actual downtime and see how long it will take you to restore identity. In an IRE environment, secure cloud infrastructure, actually go through your backups and say, I’m gonna restore Active Directory. I’m gonna restore Entra. I’m gonna restore my IDP, my MFA. I need to restore my identities for my cybersecurity tools that can help me do incident response, and go do it. Go do it in an isolated environment and see how complex it is and how long it takes because that’s the first thing you have to do before you can do everything else. Most organizations still say, oh, I have this stuff. I own this stuff. I have this process. That’s amazing. That’s if you can log in and actually do it. But until you actually test that out and get everybody into a room, go through the technical aspect of it, and see what’s gonna work and what’s not, and then escalate that to the business owners and tell them, hey, it’s gonna take me this long to restore identities, get this application back online, make sure it’s sanitized, make sure I have the forensic logs. Right? This takes a lot longer time than people expect, and actually sit around and do it, and then take it to the business owner and say, when I’m done with this, I need you, business owner, to be able to log in to it and tell me if this application is working before you let anybody else back in. There’s a big difference between RTO and RPO when it comes to sitting around the table and discussing it. It’s like fantasy football versus actually going to play football, and there’s a 350-pound dude barreling down at you while you’re running for your life. Right? It’s a whole different ballgame. Most organizations need to move away from just doing traditional tabletops and saying, you know what? Let’s simulate it and let’s make cause the chaos in our environment and see what it’s really gonna look like. Who are my vendors I need involved? What do I need to do? We cause enough of that chaos. We just kinda theorize about it. We check off a box, whether it’s for cyber insurance, compliance, legal, risk, or somebody. And then when that bad thing happens, you don’t wanna just show up and say, yeah, we did a table top. We checked off that box. But the 350-pound dude is still barreling down at me right now trying to make sure I don’t get the end goal. So long story short, like, tabletops are great. Go do it. Go actually cause some chaos. Right? Don’t break the business, but do it in an environment that you can and show others that are not IT or cybersecurity. Most non identity people don’t understand the complexity of restoring identities. Right? That’s why purpose built solutions exist out there to help you kinda do the legwork of it. But even on the Semperis side, talk about all the time, yeah, you can use our solutions to restore identity from weeks and get it down to hours, but there’s a bunch of work that needs to happen after. You still gotta do forensics. You still gotta restore machine accounts, nonhuman identities. We’re introducing AI everywhere without understanding the complexities of the identities around it and businesses are relying on those. Right? Like a tabletop can’t suffice for that. You got to actually go do it. I think that’s great advice. I also like the football analogy because I was thinking back to as a kid, I thought I was really strong and tough and I was gonna block everybody. You described a 350-pound person. There was like a 300-pound kid that came barreling at me and I got knocked unconscious. It brought that to everybody. So thanks Mark for that. That’s exactly what happens, though. Like, I’m really in the middle of incident response. Like day number four, somebody walks up and goes, why is this taking so long? Because there is a freight train coming at me right now. The minute I turn the light back on, that freight train’s gonna break through the wall and run us all over. Right? I gotta there’s a lot of work that needs to happen, and most organizations don’t realize it until it happens to them, and now you’re gonna bring out the external experts, which then we cause an even bigger problem because those responders and the experts, like, when we do IR even, we don’t know your business. What we know is very specifically, we can get you to be able to log back in. And then you gotta get your business back online. You gotta reach out to your consumers, your employees. It’s very, very complex. Moral of the story, tabletops are not good enough anymore. Right? You gotta cause that chaos to understand what the pain of it is so you can fix the problems, it always comes back to, oh, I forgot about identity. I forgot about Active Directory. Oh, wait. I can’t log in because my IDP doesn’t work. Well, it relies on Active Directory. Oh, why is my x y z cyber solution not working on my out of band communications? Because it has a machine account. Right? Fifty things have to happen for that machine account to be able to log in. Yeah. I think you brought up a good point besides just testing things, the communication. Right? Like showing here’s how long it actually takes us. I think that visibility, especially for senior leadership, it kind of helps get everyone in the company on the same page. Marty, thanks for joining us today and sharing your expertise. You shared a lot of good information and several actionable steps for organizations out there. Thanks for everyone that listened and we’ll see you next time on the E Security Planet podcast. Awesome. Thank you, Ken.
