+ All Categories
Home > Technology > Active Directory - Real Defense For Domain Admins

Active Directory - Real Defense For Domain Admins

Date post: 16-Nov-2014
Category:
Upload: jason-lang
View: 97 times
Download: 1 times
Share this document with a friend
Description:
A defensive talk about securing Active Directory (specifically Domain Admins) against some of the most common red team attacks.
Popular Tags:
38
Active Directory: Real Defense for Domain Admins Jason Lang
Transcript
Page 1: Active Directory - Real Defense For Domain Admins

Active Directory: Real Defense for Domain

AdminsJason Lang

Page 2: Active Directory - Real Defense For Domain Admins

Disclaimer

Page 3: Active Directory - Real Defense For Domain Admins

Goals

• Provide immediately useful content re: the defense of your Domain Admins (DAs) and Domain Controllers (DCs)

• Give you projects you can implement in one month or less.

Page 4: Active Directory - Real Defense For Domain Admins

About

• Consultant at SynerComm

• Passions: Dev (C#/PS/PY), InfoSec, Woodworking

• Twitter: @curi0usJack

• Blog: http://project500.squarespace.com/

Page 5: Active Directory - Real Defense For Domain Admins

Survey

• How many of you work in a large enterprise?

• How many work in an old enterprise (25+ yrs old)?

• How many in some kind of AD security?

• How many had a pentest some time in the last 12 months?

Page 6: Active Directory - Real Defense For Domain Admins

Did it go something like this?

Page 7: Active Directory - Real Defense For Domain Admins
Page 8: Active Directory - Real Defense For Domain Admins

Uh-oh

Page 9: Active Directory - Real Defense For Domain Admins
Page 10: Active Directory - Real Defense For Domain Admins

#1 - Test your new DAs

Page 11: Active Directory - Real Defense For Domain Admins

#2 - Limit the number of DAs

Page 12: Active Directory - Real Defense For Domain Admins
Page 13: Active Directory - Real Defense For Domain Admins

#3 - Separate DA accounts from

“everyday” accounts

Page 14: Active Directory - Real Defense For Domain Admins

#4 - Separate DA password policy

Page 15: Active Directory - Real Defense For Domain Admins

No Excuses!

Page 16: Active Directory - Real Defense For Domain Admins

#5 - Set DA logon restrictions

DCs only!

Page 17: Active Directory - Real Defense For Domain Admins
Page 18: Active Directory - Real Defense For Domain Admins
Page 19: Active Directory - Real Defense For Domain Admins

#6 - Disable Cached Creds

Page 20: Active Directory - Real Defense For Domain Admins
Page 21: Active Directory - Real Defense For Domain Admins

#7 - Be careful with DA service accounts

Page 22: Active Directory - Real Defense For Domain Admins

#7 - Service Accounts

• Delegate Delegate Delegate!

• If you must have DA service accounts:

• Treat task server like a DC

• Service Account can only login to that server

• Shut off cached creds

Page 23: Active Directory - Real Defense For Domain Admins
Page 24: Active Directory - Real Defense For Domain Admins

#8 - Microsoft Security Compliance Manager

Page 25: Active Directory - Real Defense For Domain Admins
Page 26: Active Directory - Real Defense For Domain Admins

#9 - A quick word about null sessions

Page 27: Active Directory - Real Defense For Domain Admins

https://project500.squarespace.com/journal/2014/3/13/powershell-enumerating-null-sessions-on-your-dcs

Page 28: Active Directory - Real Defense For Domain Admins

#10 - Get offensive security training!

Page 29: Active Directory - Real Defense For Domain Admins
Page 30: Active Directory - Real Defense For Domain Admins

Fail

Page 31: Active Directory - Real Defense For Domain Admins
Page 32: Active Directory - Real Defense For Domain Admins

Win

Page 33: Active Directory - Real Defense For Domain Admins
Page 34: Active Directory - Real Defense For Domain Admins
Page 35: Active Directory - Real Defense For Domain Admins
Page 36: Active Directory - Real Defense For Domain Admins

DomainLockDown: https://github.com/curi0usJack/activedirectory

Page 37: Active Directory - Real Defense For Domain Admins

Questions?

Page 38: Active Directory - Real Defense For Domain Admins

Huge Thank You’s:@DerbyCon

@TrustedSec


Recommended