Active Directory's Dark Side: Underbelly Threats and Shadowy Permissions

Active Directory's Dark Side: Underbelly Threats and Shadowy Permissions

In this episode of Guardians of the Directory, Craig Birch and Derek Melber delve into the complexities of Active Directory security, focusing on the stealthy threats posed by shadow permissions, DC Shadow, and DC Sync. They discuss the historical context of these vulnerabilities, the role of applications in creating shadow permissions, and the importance of cleaning up orphaned SIDs. The conversation also covers best practices for managing service accounts and highlights critical areas within Active Directory that administrators should monitor. The episode concludes with actionable recommendations for improving security posture. Key Takeaways

  • Active Directory is a critical component of identity infrastructure.
  • Shadow permissions can be exploited by attackers without detection.
  • Many organizations lack visibility into their Active Directory permissions.
  • Cleaning up orphaned SIDs is essential for security.
  • Service accounts should have strong passwords and limited privileges.
  • Regular audits of Active Directory are necessary to identify risks.
  • Applications can inadvertently create shadow permissions.
  • Understanding the baseline permissions is crucial for security.
  • PowerShell can be a powerful tool for managing Active Directory.
  • Start with small changes to improve security posture.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(18)

Hybrid Identity is Broken: Rethinking AD, Entra ID & the Bridge in Between

Hybrid Identity is Broken: Rethinking AD, Entra ID & the Bridge in Between

Welcome to another episode of Guardians of the Directory, where we pull back the curtain on the real-world challenges in securing and managing Active Directory and hybrid identity environments. In thi...

21 Elo 202541min

Blueprinting Zero Trust From: Strategy to Execution with Jerry Chapman

Blueprinting Zero Trust From: Strategy to Execution with Jerry Chapman

Welcome back to Guardians of the Directory! In this episode, Craig Birch is joined once again by Zero Trust expert Jerry Chapman for a deep dive into the Zero Trust Blueprint—a practical model to help...

26 Kesä 202530min

AdminSDHolder in Active Directory: Hidden Risks and Persistent Threats

AdminSDHolder in Active Directory: Hidden Risks and Persistent Threats

In this episode of Directory Insights in 10 Minutes, Craig Birch breaks down the often-misunderstood AdminSDHolder object in Active Directory and why it's a high-value target for attackers. Learn how ...

1 Touko 20256min

Admin Accounts with SPNs — Hidden Risk Behind Kerberoasting

Admin Accounts with SPNs — Hidden Risk Behind Kerberoasting

🔍 Admin Accounts with SPNs — Hidden Risk Behind Kerberoasting | Directory Insights in 10 MinutesIn this episode, Craig Birch breaks down a major Active Directory security blind spot: Kerberoasting vi...

15 Huhti 20255min

Kerberos Pre-Auth: Hidden AD Risk

Kerberos Pre-Auth: Hidden AD Risk

In this episode of Directory Insights in 10 Minutes, Craig Birch breaks down one of the most overlooked Active Directory misconfigurations: the "Do not require Kerberos pre-authentication" setting.🔍 ...

9 Huhti 20257min

Directory Insights in 10 Minutes: Remediating DES Encryption in Active Directory

Directory Insights in 10 Minutes: Remediating DES Encryption in Active Directory

Welcome to another episode of Directory Insights in 10 Minutes, powered by Guardians of the Directory. In this quick-hitting session, host Craig Birch walks through the process of identifying and reme...

1 Huhti 20254min

Directory Insights in 10 Minutes Reversible Password Encryption – A Hidden Risk

Directory Insights in 10 Minutes Reversible Password Encryption – A Hidden Risk

Summary:In this episode of Directory Insights in 10 Minutes, we dive into a critical yet often overlooked Active Directory misconfiguration—Allowing Password Storage with Reversible Encryption.This se...

18 Maalis 20254min

Directory Insights in 10 minutes: Password Not Required - The Hidden Risk

Directory Insights in 10 minutes: Password Not Required - The Hidden Risk

Episode OverviewIn this episode of Directory Insights in 10 Minutes, we’re exposing a dangerous yet overlooked Active Directory misconfiguration—PasswordNotRequired.Most AD admins assume password poli...

11 Maalis 20255min