<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Friedwart Kuhn on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/friedwart-kuhn/</link>
    <description>Recent content in Friedwart Kuhn on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 14 Jun 2024 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/friedwart-kuhn/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>TROOPERS24 Agenda Preview: Active Directory &amp; Entra ID Security Track</title>
      <link>https://insinuator.net/2024/06/troopers24-agenda-preview-active-directory-entra-id-security-track/</link>
      <pubDate>Fri, 14 Jun 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/06/troopers24-agenda-preview-active-directory-entra-id-security-track/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;are you curious about the agenda of the Active Directory- &amp;amp; Entra ID security track at TROOPERS24? Here’s a sneak peak of the already published tracks:&lt;/p&gt;&#xA;&lt;h3 id=&#34;wednesday-2024-06-26&#34;&gt;Wednesday, 2024-06-26:&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/vxs8wy&#34;&gt;A Decade of Active Directory Attacks: What We’ve Learned &amp;amp; What’s Next&lt;/a&gt; – Sean Metcalf&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/uepkle&#34;&gt;ADillesHeel: Making the Impossible Possible in AD Attack Path Analysis&lt;/a&gt; – SHANG-DE JIANG&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/jt97ha&#34;&gt;So You Performed A Forest Recovery. How Do You Reconnect Your AD Again With Azure AD?&lt;/a&gt; – Jorge de Almeida Pinto&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/8ekvxr&#34;&gt;Decrypting the Directory: A Journey into a static analysis of the Active Directory NTDS to identify misconfigurations and vulnerabilities&lt;/a&gt; – Bastien Cacace (XMCO company)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/a8zf7h&#34;&gt;Say Hello to your new cache flow!&lt;/a&gt; – Geoffrey Bertoli, Rémi Jullian&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/kzymd8&#34;&gt;Analyzing and Executing ADCS Attack Paths with BloodHound&lt;/a&gt; – by Andy Robbins, Jonas Bülow Knudsen&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h3 id=&#34;thursday-2024-06-27&#34;&gt;Thursday, 2024-06-27:&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/kynuwx&#34;&gt;The (almost) complete LDAP guide&lt;/a&gt; – Sapir Federovsky&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/z3dexp&#34;&gt;Exploiting Token-Based Authentication: Attacking and Defending Identities in the 2020s&lt;/a&gt; – Dr Nestori Syynimaa&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/3vlccy&#34;&gt;Attacking Primary Refresh Tokens using their MacOS implementation&lt;/a&gt; – Olaf Hartong, Dirk-jan Mollema&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/nvp3zs&#34;&gt;Misconfiguration Manager: Overlooked and Overprivileged&lt;/a&gt; – Duane Michael, Chris Thompson&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/jlaupj&#34;&gt;The Registry Rundown&lt;/a&gt; – Cedric Van Bockhaven, Max Grim&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The full conference agenda including timeslots will be published soon at &lt;a href=&#34;https://troopers.de/troopers24/conference/&#34;&gt;TROOPERS24&lt;/a&gt;. The trainings are already sold out, but &lt;a href=&#34;https://troopers.de/tickets/&#34;&gt;a handful of tickets is currently left&lt;/a&gt;.  Stay tuned &amp;amp; make the world a safer place!&lt;/p&gt;</description>
    </item>
    <item>
      <title>AD /Azure Security Track on Troopers 23</title>
      <link>https://insinuator.net/2023/05/ad-/azure-security-track-on-troopers-23/</link>
      <pubDate>Fri, 05 May 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/05/ad-/azure-security-track-on-troopers-23/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Hi!&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;We’re excited to announce the nearly complete composition of the Active&#xA;Directory &amp;amp; Azure Security Track on Troopers 23 with fantastic speakers!&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;“&lt;a href=&#34;https://troopers.de/troopers23/talks/ywstkv/&#34;&gt;Dumping NTHashes from Azure AD&lt;/a&gt;”&lt;br&gt;&#xA;(Nestori&#xA;Syynimaa)&lt;/p&gt;&#xA;&lt;p&gt;“&lt;a href=&#34;https://troopers.de/troopers23/talks/33fcyz/&#34;&gt;Hidden Pathways: Exploring the Anatomy of ACL-Based Active Directory Attacks and Building Strong Defenses&lt;/a&gt;”&lt;br&gt;&#xA;(Jonas&#xA;Bülow Knudsen, Alexander Schmitt)&lt;/p&gt;&#xA;&lt;p&gt;“&lt;a href=&#34;https://troopers.de/troopers23/talks/9tqyud/&#34;&gt;Priority for Effective Action – A Practical Model for quantifying the Risk of Active Directory Attacks&lt;/a&gt;”&lt;br&gt;&#xA;(Mars&#xA;Cheng, Dexter Chen)&lt;/p&gt;</description>
    </item>
    <item>
      <title>BSI veröffentlicht Hardening Guide, Protokollierungs-Empfehlung und zugehörige GPOs für Windows 10 im Rahmen der SiSyPHuS-Studie</title>
      <link>https://insinuator.net/2021/05/bsi-ver%C3%B6ffentlicht-hardening-guide-protokollierungs-empfehlung-und-zugeh%C3%B6rige-gpos-f%C3%BCr-windows-10-im-rahmen-der-sisyphus-studie/</link>
      <pubDate>Mon, 03 May 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/05/bsi-ver%C3%B6ffentlicht-hardening-guide-protokollierungs-empfehlung-und-zugeh%C3%B6rige-gpos-f%C3%BCr-windows-10-im-rahmen-der-sisyphus-studie/</guid>
      <description>&lt;p&gt;Wir freuen uns, dass das Bundesamt für Sicherheit in der Informationstechnik&#xA;(BSI) im Rahmen des gemeinsam mit ERNW durchgeführten SiSyPHuS Win10-Projekts&#xA;(&lt;strong&gt;S&lt;/strong&gt;tud&lt;strong&gt;i&lt;/strong&gt;e zu &lt;strong&gt;Sy&lt;/strong&gt;stemintegrität, &lt;strong&gt;P&lt;/strong&gt;rotokollierung, &lt;strong&gt;H&lt;/strong&gt;ärtung&#xA;&lt;strong&gt;u&lt;/strong&gt;nd &lt;strong&gt;S&lt;/strong&gt;icherheitsfunktionen in Windows 10) heute (ca. 10 Uhr) die nächsten&#xA;drei Arbeitspakete veröffentlicht:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Empfehlung zur Härtung von Windows 10 mit Bordmitteln&lt;/li&gt;&#xA;&lt;li&gt;Empfehlung zur Konfiguration der Protokollierung in Windows 10&lt;/li&gt;&#xA;&lt;li&gt;Gruppenrichtlinien zu den Konfigurationsempfehlungen für Härtung und&#xA;Protokollierung für Windows 10&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;In den Dokumenten finden sich unterschiedliche Empfehlungen für&#xA;Domänenmitglieder (mit normalem und mit hohem Schutzbedarf) und&#xA;Einzelplatzrechner. Die Dokumente bauen auf den Empfehlungen von Microsofts&#xA;Security Baseline und dem CIS Benchmark für Windows 10 auf und ergänzen diese in&#xA;von Microsoft und CIS nicht betrachteten Bereichen oder modifizieren sie dort,&#xA;wo es aus Erfahrung von ERNW im Hardening von Windows-Systemen sinnvoll ist.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Follow-Up on the Heisec Webinar on Emotet &amp;amp; Some Active Directory Security Sources</title>
      <link>https://insinuator.net/2019/08/a-follow-up-on-the-heisec-webinar-on-emotet-amp-some-active-directory-security-sources/</link>
      <pubDate>Fri, 09 Aug 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/08/a-follow-up-on-the-heisec-webinar-on-emotet-amp-some-active-directory-security-sources/</guid>
      <description>&lt;p&gt;Some weeks ago, Heinrich and I had the pleasure to participate in the heisec-Webinar &lt;a href=&#34;https://www.heise.de/security/meldung/heisec-Webinar-Emotet-bei-Heise-Lernen-aus-unseren-Fehlern-4439874.html&#34;&gt;“Emotet bei Heise – Lernen aus unseren Fehlern”&lt;/a&gt;. We really enjoyed the webinar and the (alas, due to the format: too short) discussions and we hope we could contribute to understand how to make Active Directory implementations out there a bit safer in the future.&lt;/p&gt;&#xA;&lt;p&gt;Now, I have the pleasure to announce a continuation of our talk about Active Directory security next week, Wednesday, 14^(th) of August @heisec in the format of a technical talk &lt;a href=&#34;https://www.heise-events.de/webinare/emotet_cybercrime&#34;&gt;“Emotet bei Heise – Online-Fachgespräch zum Schutz vor Cybercrime”&lt;/a&gt;. Seats are still available 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Emotet im Active Directory: Es kann jeden treffen – aber Jeder kann es dem Angreifer schwer machen!</title>
      <link>https://insinuator.net/2019/06/emotet-im-active-directory-es-kann-jeden-treffen-aber-jeder-kann-es-dem-angreifer-schwer-machen/</link>
      <pubDate>Fri, 07 Jun 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/06/emotet-im-active-directory-es-kann-jeden-treffen-aber-jeder-kann-es-dem-angreifer-schwer-machen/</guid>
      <description>&lt;p&gt;Heise berichtet aktuell öffentlich über die &lt;a href=&#34;https://www.heise.de/ct/artikel/Emotet-bei-Heise-4437807.html&#34;&gt;Emotet-Infektion im eigenen Haus&lt;/a&gt;, bei dessen Aufklärung ERNW unterstützte. &lt;a href=&#34;https://www.heise.de/newsticker/meldung/heiseshow-Emotet-trifft-Heise-Einblicke-in-einen-Trojaner-Angriff-4439850.html&#34;&gt;Damit liefert Heise Informationen&lt;/a&gt; zum Verlauf aktueller Angriffe, aber insbesondere auch wertvolle Einsichten zu Vorbeugung, Erkennung, Analyse und Gegenmaßnahmen aus eigener Erfahrung, wie sie nur selten der Öffentlichkeit preisgegeben werden.&lt;/p&gt;&#xA;&lt;p&gt;Ein Team aus Incident-Response Spezialisten der ERNW Research unterstützte Heise bei der Analyse und Rekonstruktion des Vorfalls und analysierte die Schadsoftware, um deren Ausbreitungswege nachzuvollziehen und IoCs (Indicators of Compromise) zu extrahieren. Hierdurch konnten effektive Gegenmaßnahmen entwickelt und gemeinsam mit Heise erfolgreich umgesetzt werden.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Active Directory Security Summit 2018 – Slides Online</title>
      <link>https://insinuator.net/2018/11/active-directory-security-summit-2018-slides-online/</link>
      <pubDate>Fri, 16 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/active-directory-security-summit-2018-slides-online/</guid>
      <description>&lt;p&gt;on Tuesday, 13.th of November we realized our second AD security summit with the title: “&lt;a href=&#34;https://ernw-insight.de/de/events/2018-11-13-summit18-ad/&#34;&gt;Active Directory Security: On-Prem-Security, Secure Extension into the Cloud &amp;amp; Secure Operations&lt;/a&gt;” in Heidelberg. First, we had three talks: the first one about “&lt;a href=&#34;https://ernw.de/download/AD_Summit_2018/01_AD_Summit_CoreSecPrinciples_fk_hw_v.1.2_signed.pdf&#34;&gt;Active Directory Core Security Principles &amp;amp; Best Practices&lt;/a&gt;” covering hybrid AD and AD Trusts as well (by Friedwart Kuhn &amp;amp; Heinrich Wiederkehr from ERNW), the second one a case study about the &lt;a href=&#34;https://ernw.de/download/AD_Summit_2018/SecureAD_realWorldScenario_final.pdf&#34;&gt;implementation of an ESAE Forest in a big insurance company&lt;/a&gt; (by Fabian Böhm from &lt;a href=&#34;https://www.teal-consulting.de/&#34;&gt;Teal Technology Consulting&lt;/a&gt;) and the third one about a case study with respect to the (security) challenges of a hybrid AD (by Raphael Rojas from &lt;a href=&#34;https://www.stihl.de/&#34;&gt;STIHL&lt;/a&gt;). The afternoon passed quickly with a very fruitful and vivid discussion about implementing and operating securely ESAE environments and hybrid ADs and how to deal with the high number of AD Trusts many organisations suffer from. Today we published the slides. Enjoy and stay tuned!&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to go ahead with future end of life Windows (2003) Servers</title>
      <link>https://insinuator.net/2015/02/how-to-go-ahead-with-future-end-of-life-windows-2003-servers/</link>
      <pubDate>Thu, 12 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/how-to-go-ahead-with-future-end-of-life-windows-2003-servers/</guid>
      <description>&lt;p&gt;Server operating systems with an OS, for which vendor support has ended, come with many risks that have to be considered and addressed. The primary goal should be always to decommission or migrate the majority of end-of-life (EoL) servers to OS versions, supported by the vendor. Here it should be noted that a migration to an up-to-date OS should be preferably done before your organization enters the end of life of that software 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Skeleton Key – a Nasty Piece of Malware. Some Remarks.</title>
      <link>https://insinuator.net/2015/01/skeleton-key-a-nasty-piece-of-malware.-some-remarks./</link>
      <pubDate>Thu, 15 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/skeleton-key-a-nasty-piece-of-malware.-some-remarks./</guid>
      <description>&lt;p&gt;Just recently, Dell SecureWorks Counter Threat Unit(TM) (CTU) researchers published details (see &lt;a href=&#34;http://www.secureworks.com/cyber-threat-intelligence/threats/skeleton-key-malware-analysis/&#34;&gt;http://www.secureworks.com/cyber-threat-intelligence/threats/skeleton-key-malware-analysis/&lt;/a&gt; ) on a especially nasty piece of malware that bypasses authentication on Active Directory (AD) systems which implement single-factor (password only) authentication. Once deployed the malware stays quite noiseless in the Domain Controller´s (DC) RAM, and the DC´s replication issues caused by it weren´t interpreted – in this case – during months as a hint for system compromise. Probably the malware´s modification on the LSASS process reduced the DC´s ability to perform DC-to-DC authentication, but this is only speculation and not where we would like to go today.&lt;/p&gt;</description>
    </item>
    <item>
      <title>EMET v4.0 with New Certificate Trust Feature Released</title>
      <link>https://insinuator.net/2013/07/emet-v4.0-with-new-certificate-trust-feature-released/</link>
      <pubDate>Mon, 01 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/emet-v4.0-with-new-certificate-trust-feature-released/</guid>
      <description>&lt;p&gt;Microsoft released &lt;a href=&#34;http://www.microsoft.com/en-us/download/details.aspx?id=39273&#34;&gt;EMET v4.0&lt;/a&gt;  with a new (security) feature that enables protection against fraudulent websites or compromised root certification authorities (do you remember Comodo, DigiNotar, DigiCert, Turktrust et al. ;-)?)&lt;/p&gt;&#xA;&lt;p&gt;EMET defines via “certificate trust“ a trust chain between the domain name of a website (and its associated website certificate) and a root CA certificate. This is done through so called “pinning rules”. Here is one of the default pinning rules of EMET 4.0 for the domain name &lt;em&gt;login.live.com&lt;/em&gt;:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Server 2008 R2 BSI-compliance</title>
      <link>https://insinuator.net/2012/07/windows-server-2008-r2-bsi-compliance/</link>
      <pubDate>Thu, 26 Jul 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/07/windows-server-2008-r2-bsi-compliance/</guid>
      <description>&lt;p&gt;Recommendations by the &lt;a href=&#34;https://www.bsi.bund.de/EN/Home/home_node.html&#34;&gt;German Federal Office for Information Security&lt;/a&gt; (&lt;em&gt;BSI – Bundesamt für Sicherheit in der Informationstechnik&lt;/em&gt;) are obligatory for German government agencies, civil services and authorities (like recommendations of the NIST are relevant to American government agencies and authorities). They are often used as references and security best practices in other countries as well. Hence it is hard to understand why the recommendations on how to harden Windows Server &lt;strong&gt;2008&lt;/strong&gt; based systems were published only some weeks ago and only on a preliminary draft basis (which is, obviously, better than nothing ;-)).&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
