<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Active Directory on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/active-directory/</link>
    <description>Recent content in Active Directory on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 11 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/active-directory/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>#TROOPERS26 AD &amp; Entra ID Security Track</title>
      <link>https://insinuator.net/2026/08/troopers26-ad-entra-id-security-track/</link>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/08/troopers26-ad-entra-id-security-track/</guid>
      <description>&lt;p&gt;The #TROOPERS26 ‘AD &amp;amp; Entra ID Security’ track delivered an incredible experience – much like the entire conference! We were thrilled to host some of the brightest minds in identity research alongside a highly engaged audience who brought valuable insights to the roundtable discussions. While the presentation slides have already been published on the TROOPERS website, several speakers have shared complementary tools, in-depth blog posts, and active social media threads. To make things easy, we’ve compiled a comprehensive list of all these fantastic resources from the track below.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Hello for Business - Faceplant: Planting Biometric Templates</title>
      <link>https://insinuator.net/2025/08/windows-hello-for-business-faceplant-planting-biometric-templates/</link>
      <pubDate>Fri, 29 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/08/windows-hello-for-business-faceplant-planting-biometric-templates/</guid>
      <description>&lt;p&gt;We are back from Black Hat USA, where we presented our research on&#xA;&lt;a href=&#34;https://www.blackhat.com/us-25/briefings/schedule/index.html#windows-hell-no-for-business-45865&#34;&gt;Windows Hello for Business&lt;/a&gt;&#xA;(&lt;a href=&#34;http://i.blackhat.com/BH-USA-25/Presentations/US-25-David-Windows-Hello-No-for-Business-Wendsday.pdf&#34;&gt;Slides&lt;/a&gt;)&#xA;once more. In the last two blog posts, we have discussed the&#xA;&lt;a href=&#34;https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/&#34;&gt;architecture of WHfB and past attacks&lt;/a&gt;,&#xA;as well as how the&#xA;&lt;a href=&#34;https://insinuator.net/2025/07/windows-hello-for-business-the-face-swap/&#34;&gt;database works and how to swap identities&lt;/a&gt; in&#xA;the database.&lt;/p&gt;&#xA;&lt;p&gt;First, a few words regarding my experience at Black Hat: for me, it was the&#xA;first time attending the conference and then directly as a speaker. I thoroughly&#xA;enjoyed Black Hat. It took a while to get used to the size of the conference and&#xA;the vibe of Las Vegas. What was especially interesting for me was connecting&#xA;with other researchers. One thing that stood out was meeting with the team from&#xA;MSRC and putting faces to the team itself. It feels way more personal to know&#xA;who you’re talking to when you know the people handling your cases. During&#xA;TROOPERS I typically have the chance to connect with many researchers, mainly&#xA;from Europe. At Black Hat US, on the other hand, it is possible to connect more&#xA;with the US scene and meet people you haven’t seen in a long time! Seeing&#xA;familiar faces again is always nice, as opposed to putting them into your&#xA;biometric template database. One nice detail was that some international&#xA;researchers are aware of the research BSI (German: “Bundesamt für Sicherheit in&#xA;der Informationstechnik” – “German federal office for IT security”) is&#xA;facilitating. The results of our presentation stem from the “Windows Dissected”&#xA;project we are performing on behalf of the BSI.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TROOPERS25 AD &amp; Entra ID Security Track</title>
      <link>https://insinuator.net/2025/08/troopers25-ad-entra-id-security-track/</link>
      <pubDate>Thu, 14 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/08/troopers25-ad-entra-id-security-track/</guid>
      <description>&lt;p&gt;The #TROOPERS25 ‘AD &amp;amp; Entra ID Security’ track was a blast – as was the whole&#xA;conference 😉 –  bringing together some of the smartest researchers in the field&#xA;and a great audience of practitioners willing to share their experiences during&#xA;the &lt;a href=&#34;https://troopers.de/roundtables/&#34;&gt;roundtable&lt;/a&gt;. The slides of the talks have&#xA;been released in the interim on the &lt;a href=&#34;https://troopers.de&#34;&gt;TROOPERS website&lt;/a&gt;, but&#xA;since many speakers published additional blogposts or released tools, we provide&#xA;a compilation of resources from the track in the following.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Hello for Business - The Face Swap</title>
      <link>https://insinuator.net/2025/07/windows-hello-for-business-the-face-swap/</link>
      <pubDate>Tue, 15 Jul 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/07/windows-hello-for-business-the-face-swap/</guid>
      <description>&lt;p&gt;In the&#xA;&lt;a href=&#34;https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/&#34;&gt;last blog post&lt;/a&gt;,&#xA;we discussed the full authentication flow using Windows Hello for Business&#xA;(WHfB) with face recognition to authenticate against an Active Directory with&#xA;Kerberos and showcased existing and new vulnerabilities. In this blog post, we&#xA;dive into the architectural challenges WHfB faces and explore how we can exploit&#xA;them.&lt;/p&gt;&#xA;&lt;p&gt;The majority of the work was conducted in the context of the “Windows Dissected”&#xA;project. This project, funded by the BSI (German: “Bundesamt für Sicherheit in&#xA;der Informationstechnik” – the German Federal Office for Information Security),&#xA;has the goal to perform ” various in-depth security analyses of&#xA;security-critical components and functions in Windows.” Over the next years we&#xA;will discuss these results here once they are published.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Hello for Business – Past and Present Attacks</title>
      <link>https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/</link>
      <pubDate>Fri, 20 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/</guid>
      <description>&lt;p&gt;Windows Hello for Business is a key component of Microsoft’s passwordless&#xA;authentication strategy. It enables user authentication not only during system&#xA;sign-in but also in conjunction with new and advanced features such as Personal&#xA;Data Encryption, Administrator Protection, and Recall. Rather than depending on&#xA;traditional passwords, Windows Hello leverages a PIN or biometric methods – such&#xA;as fingerprint or facial recognition – to unlock cryptographic keys protected by&#xA;the Trusted Platform Module (TPM).&lt;/p&gt;</description>
    </item>
    <item>
      <title>DogWhisperer&#39;s SharpHound Cheat Sheet</title>
      <link>https://insinuator.net/2021/05/dogwhisperers-sharphound-cheat-sheet/</link>
      <pubDate>Tue, 04 May 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/05/dogwhisperers-sharphound-cheat-sheet/</guid>
      <description>&lt;p&gt;BloodHound data collection, aka &lt;strong&gt;Sharphound&lt;/strong&gt;, is quite a complex beast.&lt;br&gt;&#xA;When giving BloodHound workshops, the part where I get the most questions is&#xA;always data collection.&lt;br&gt;&#xA;How is the BloodHound data collected? &lt;strong&gt;What methods do what?&lt;/strong&gt; Who am I talking&#xA;to? How do I fly under the radar?&lt;/p&gt;&#xA;&lt;p&gt;These are all very relevant questions when you think about it.&lt;br&gt;&#xA;After all, the rest is just a gorgeous UI sitting on top of a cool data model,&#xA;but the only bit of BloodHound code that ever touches the targeted network is&#xA;SharpHound. And so questions about it should be mandatory.&lt;br&gt;&#xA;Now even thought I’ve been working with BloodHound for quite a while, there is&#xA;always this moment where I have to check before answering… (I feel the older I&#xA;get, the quicker I understand, but the less I remember… but that’s another story&#xA;I guess…)&lt;/p&gt;</description>
    </item>
    <item>
      <title>Doing it Server-Side with CypherDog 4.0</title>
      <link>https://insinuator.net/2020/09/doing-it-server-side-with-cypherdog-4.0/</link>
      <pubDate>Thu, 17 Sep 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/09/doing-it-server-side-with-cypherdog-4.0/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Arrroooo… Bloodhound Crew!!&lt;/strong&gt; Heard the news? &lt;strong&gt;CypherDog 4.0 is out&lt;/strong&gt; and it’s full of new features…&lt;/p&gt;&#xA;&lt;p&gt;Now a couple of you might be thinking “Hey there, wait a minute… didn’t CypherDog 3.0 come out not that long ago..??”, and I am happy to see some of you are paying attention…&lt;br&gt;&#xA;Indeed, when Bloodhound 3 came out, I quickly updated CypherDog 2 to CypherDog 3 to be compatible with it.&lt;br&gt;&#xA;But Bloodhound 3 is compatible with neo4j 3 and 4, however the neo4j REST API has been deprecated in neo4j 4 and CypherDog 3 relied on it.&lt;br&gt;&#xA;Long story short, CypherDog 4.0 is a full rewrite compatible with the new &lt;strong&gt;neo4j 4 HTTP API&lt;/strong&gt;, and since I was refactoring the whole thing, I added some cool new features to the tool.&lt;br&gt;&#xA;The idea was to be able to do more with less keystrokes, and to do it server-side…&lt;br&gt;&#xA;And so I made a meme.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dog Whisperer Update</title>
      <link>https://insinuator.net/2020/03/dog-whisperer-update/</link>
      <pubDate>Thu, 26 Mar 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/03/dog-whisperer-update/</guid>
      <description>&lt;p&gt;With the current situation, it’s not easy to find the right angle to start this blog post, so I won’t even try… but with Troopers cancelled, my Bloodhound workshop went down the drain, and I didn’t get a chance to meet or catch up with all of you and share my latest BloodHound adventures. So I decided to write a quick post to share all this…&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;Whipsererlogo3.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;As you might have heard, BloodHound 3 was released last month, so I thought it was time to update the &lt;strong&gt;Dog Whisperers Handbook&lt;/strong&gt;.&lt;br&gt;&#xA;It’s basically a quick intro to BloodHound and Cypher, with a lot of links to resources for further learning.&lt;br&gt;&#xA;You can download the latest version &lt;a href=&#34;https://www.ernw.de/download/ERNW_DogWhisperer3.pdf&#34;&gt;here&lt;/a&gt;. Hope you enjoy it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blue Hands On Bloodhound</title>
      <link>https://insinuator.net/2019/10/blue-hands-on-bloodhound/</link>
      <pubDate>Fri, 18 Oct 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/10/blue-hands-on-bloodhound/</guid>
      <description>&lt;p&gt;Hi there,&lt;/p&gt;&#xA;&lt;p&gt;SadProcessor here, happy to be back on the Insinuator to share with you some of my latest BloodHound adventures and experiments…&lt;/p&gt;&#xA;&lt;p&gt;TL;DR Well too bad for you…&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;WorkShop.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Before diving into a bit of code and some &lt;strong&gt;BloodHound data manipulation&lt;/strong&gt;,&lt;br&gt;&#xA;I would like to thank the BruCon Crew for having me over last week for &lt;strong&gt;BruCON0x0B&lt;/strong&gt;.&lt;br&gt;&#xA;I had the pleasure of delivering a 4h &lt;strong&gt;BloodHound &amp;amp; Cypher workshop&lt;/strong&gt; in the lovely city of Gent [in a fantastic training room], and I am pleased with the interaction &amp;amp; feedback I had with the attendees.&lt;br&gt;&#xA;I was also very happy to see almost as many Blues as Reds in the room [as well as regular security folks!!], all together having a play with BloodHound &amp;amp; Cypher.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Follow-Up on the Heisec Webinar on Emotet &amp;amp; Some Active Directory Security Sources</title>
      <link>https://insinuator.net/2019/08/a-follow-up-on-the-heisec-webinar-on-emotet-amp-some-active-directory-security-sources/</link>
      <pubDate>Fri, 09 Aug 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/08/a-follow-up-on-the-heisec-webinar-on-emotet-amp-some-active-directory-security-sources/</guid>
      <description>&lt;p&gt;Some weeks ago, Heinrich and I had the pleasure to participate in the heisec-Webinar &lt;a href=&#34;https://www.heise.de/security/meldung/heisec-Webinar-Emotet-bei-Heise-Lernen-aus-unseren-Fehlern-4439874.html&#34;&gt;“Emotet bei Heise – Lernen aus unseren Fehlern”&lt;/a&gt;. We really enjoyed the webinar and the (alas, due to the format: too short) discussions and we hope we could contribute to understand how to make Active Directory implementations out there a bit safer in the future.&lt;/p&gt;&#xA;&lt;p&gt;Now, I have the pleasure to announce a continuation of our talk about Active Directory security next week, Wednesday, 14^(th) of August @heisec in the format of a technical talk &lt;a href=&#34;https://www.heise-events.de/webinare/emotet_cybercrime&#34;&gt;“Emotet bei Heise – Online-Fachgespräch zum Schutz vor Cybercrime”&lt;/a&gt;. Seats are still available 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>DirectoryRanger 1.5.0 Is Available</title>
      <link>https://insinuator.net/2019/06/directoryranger-1.5.0-is-available/</link>
      <pubDate>Thu, 13 Jun 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/06/directoryranger-1.5.0-is-available/</guid>
      <description>&lt;p&gt;The next major release of DirectoryRanger is now available for customers, and for everyone who would like to try it ;-). Current attacks show that quite often the topic of Active Directory Security is not on the security agenda, but it should be, and this was the reason for us to build the tool and, of course, to maintain and improve it. So what are the major new features released with DirectoryRanger 1.5.0? Here we go:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Emotet im Active Directory: Es kann jeden treffen – aber Jeder kann es dem Angreifer schwer machen!</title>
      <link>https://insinuator.net/2019/06/emotet-im-active-directory-es-kann-jeden-treffen-aber-jeder-kann-es-dem-angreifer-schwer-machen/</link>
      <pubDate>Fri, 07 Jun 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/06/emotet-im-active-directory-es-kann-jeden-treffen-aber-jeder-kann-es-dem-angreifer-schwer-machen/</guid>
      <description>&lt;p&gt;Heise berichtet aktuell öffentlich über die &lt;a href=&#34;https://www.heise.de/ct/artikel/Emotet-bei-Heise-4437807.html&#34;&gt;Emotet-Infektion im eigenen Haus&lt;/a&gt;, bei dessen Aufklärung ERNW unterstützte. &lt;a href=&#34;https://www.heise.de/newsticker/meldung/heiseshow-Emotet-trifft-Heise-Einblicke-in-einen-Trojaner-Angriff-4439850.html&#34;&gt;Damit liefert Heise Informationen&lt;/a&gt; zum Verlauf aktueller Angriffe, aber insbesondere auch wertvolle Einsichten zu Vorbeugung, Erkennung, Analyse und Gegenmaßnahmen aus eigener Erfahrung, wie sie nur selten der Öffentlichkeit preisgegeben werden.&lt;/p&gt;&#xA;&lt;p&gt;Ein Team aus Incident-Response Spezialisten der ERNW Research unterstützte Heise bei der Analyse und Rekonstruktion des Vorfalls und analysierte die Schadsoftware, um deren Ausbreitungswege nachzuvollziehen und IoCs (Indicators of Compromise) zu extrahieren. Hierdurch konnten effektive Gegenmaßnahmen entwickelt und gemeinsam mit Heise erfolgreich umgesetzt werden.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers &amp;amp; Chill…</title>
      <link>https://insinuator.net/2019/04/troopers-amp-chill/</link>
      <pubDate>Fri, 26 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/troopers-amp-chill/</guid>
      <description>&lt;p&gt;As promised in my &lt;a href=&#34;https://insinuator.net/2019/03/the-mmm-in-community/&#34;&gt;previous post&lt;/a&gt;, I am back for an overview of the &lt;strong&gt;Troopers19 – Active Directory&lt;/strong&gt; related talks… Videos have been published and it’s popcorn time… So if you are into stories about Kingdoms and Crown Jewels, grab your loved one [or a drink…] and turn the lights down low, ’cause tonight it’s “Troopers &amp;amp; Chill…”&lt;/p&gt;&#xA;&lt;p&gt;Warning: Don’t watch it all in one go… or you will start to feel some anxiety and pain…&lt;br&gt;&#xA;and then the Flying Dutchman will move to the cloud… And at that point we are not insured anymore.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2019 – Year Of The Blue Dog…</title>
      <link>https://insinuator.net/2019/01/2019-year-of-the-blue-dog/</link>
      <pubDate>Mon, 28 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/2019-year-of-the-blue-dog/</guid>
      <description>&lt;p&gt;Back from Holidays, you started the year well motivated to &lt;strong&gt;make the world a safer place&lt;/strong&gt;.&lt;br&gt;&#xA;However, sitting at your desk today  you realize nothing really changed since last year, and you are surfing the web, feeling a bit blue, trying to avoid that pile of emails waiting for you and wondering how you could &lt;strong&gt;gain some visibility on your domain in order to better defend it&lt;/strong&gt;.&lt;br&gt;&#xA;No worries, emails can wait a bit longer. All you need is some fresh air and something cool to keep your defensive mind motivated for the year,  and I might have just what you need; so put on your shoes and let me take you on a 15 minute Cypher walk with a cool blue dog…&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR19 Active Directory Security Track</title>
      <link>https://insinuator.net/2019/01/%23tr19-active-directory-security-track/</link>
      <pubDate>Wed, 23 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/%23tr19-active-directory-security-track/</guid>
      <description>&lt;p&gt;As some of you might recall we’ve introduced a dedicated “Active Directory Security Track” at last year’s &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt;. For Troopers19 we’ve expanded it to two days (as the SAP Security Track was discontinued), and in the following I’ll provide a list of talks in the track.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Vincent Le Toux: You “try” to detect mimikatz&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Abstract: This is 2019 and you still “try” to detect mimikatz. “Try”, because after many years, this post exploitation tool continues to be successful.&lt;br&gt;&#xA;As a contributor to mimikatz and also a blue team guy, I’m asking myself why antivirus vendors are unable to catch it after many years.&lt;br&gt;&#xA;How can a tool be blocked if nobody does not know what this tool is doing? Because surprisingly, it is known only for credential collection but mimikatz is a lot more.&lt;br&gt;&#xA;To mitigate the lack of antivirus vendor, should we buy new fancy EDR tool or try a technical approach? Apply a Framework? Rely on Compliance? Use a SIEM to collect logs and apply correlation? In sumarry, can we detect mimikatz?&lt;br&gt;&#xA;In this presentation we will try to understand why mimikatz has such power and especially some weakness related to credential gathering and active directory will be exposed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Whitepaper 67: Active Directory Trust Considerations</title>
      <link>https://insinuator.net/2018/12/ernw-whitepaper-67-active-directory-trust-considerations/</link>
      <pubDate>Tue, 11 Dec 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/12/ernw-whitepaper-67-active-directory-trust-considerations/</guid>
      <description>&lt;p&gt;Last week &lt;a href=&#34;https://twitter.com/HarmJ0y&#34;&gt;Will “harmj0y” Schroeder&lt;/a&gt; published an excellent technical article titled &lt;a href=&#34;https://www.harmj0y.net/blog/redteaming/not-a-security-boundary-breaking-forest-trusts/&#34;&gt;“Not A Security Boundary: Breaking Forest Trusts”&lt;/a&gt; in which he lays out how a highly critical security compromise can be achieved across a forest boundary, resulting from a combination of default AD (security) settings and a novel attack method. His post is a follow-up to the DerbyCon talk “The Unintended Risks of Trusting Active Directory” which he had given together with &lt;a href=&#34;https://twitter.com/tifkin_&#34;&gt;Lee Christensen&lt;/a&gt; and &lt;a href=&#34;https://twitter.com/enigma0x3&#34;&gt;Matt Nelson&lt;/a&gt; at DerbyCon (video &lt;a href=&#34;http://www.irongeek.com/i.php?page=videos/derbycon8/track-2-03-the-unintended-risks-of-trusting-active-directory-lee-christensen-will-schroeder-matt-nelson&#34;&gt;here&lt;/a&gt;). They will also discuss this at the upcoming &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt; Active Directory Security Track (details on some more talks, including &lt;a href=&#34;https://twitter.com/PyroTek3&#34;&gt;Sean Metcalf’s&lt;/a&gt; one, can be found in &lt;a href=&#34;https://insinuator.net/2018/11/first-talks-of-troopers19-accepted/&#34;&gt;this post&lt;/a&gt; or &lt;a href=&#34;https://insinuator.net/2018/12/and-five-talks-more-were-accepted-at-troopers19/&#34;&gt;this one&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>DirectoryRanger 1.1.0 Introduces Informational Audit Checks</title>
      <link>https://insinuator.net/2018/12/directoryranger-1.1.0-introduces-informational-audit-checks/</link>
      <pubDate>Mon, 03 Dec 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/12/directoryranger-1.1.0-introduces-informational-audit-checks/</guid>
      <description>&lt;p&gt;With version 1.1.0 our tool DirectoryRanger introduces a new feature: informational audit checks. These checks do not have a severity rating because they are just “for your information” and the included information might or might not contain security issues, depending on other facts. But these checks can help to reduce your Active Directory attack surface by pointing you to some aspects which need your attention and at least require to be discussed and documented (and they might also imply governance measures like a risk acceptance).&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Dog Whisperer’s Handbook</title>
      <link>https://insinuator.net/2018/11/the-dog-whisperers-handbook/</link>
      <pubDate>Mon, 19 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/the-dog-whisperers-handbook/</guid>
      <description>&lt;p&gt;Generally speaking, I’m more of a Cat type of guy, but I have to say I really love BloodHound. And if you do too, you are in for a treat…&lt;br&gt;&#xA;Last week, the &lt;a href=&#34;https://twitter.com/ERNW_Insight&#34;&gt;ERNW Insight&lt;/a&gt; &lt;strong&gt;Active Directory Security Summit&lt;/strong&gt; took place in Heidelberg. (&lt;a href=&#34;https://insinuator.net/2018/11/active-directory-security-summit-2018-slides-online/&#34;&gt;More Info&lt;/a&gt;)&lt;br&gt;&#xA;For this occasion, &lt;a href=&#34;https://twitter.com/Enno_Insinuator&#34;&gt;@Enno_Insinuator&lt;/a&gt; asked me if I would like to deliver a &lt;strong&gt;BloodHound Workshop&lt;/strong&gt;, and of course I accepted the challenge…&lt;/p&gt;&#xA;&lt;p&gt;We had a full class, I had a blast training it, and I hope the trainees enjoyed it as much as I did.&lt;br&gt;&#xA;But that’s not all…&lt;br&gt;&#xA;Another part of the deal was that I had to write a &lt;strong&gt;Training Guide&lt;/strong&gt; that we would then &lt;strong&gt;share with the Community&lt;/strong&gt; (aka you).&lt;br&gt;&#xA;So here it is, fresh from the Heidelberg press and available for download:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Active Directory Security Summit 2018 – Slides Online</title>
      <link>https://insinuator.net/2018/11/active-directory-security-summit-2018-slides-online/</link>
      <pubDate>Fri, 16 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/active-directory-security-summit-2018-slides-online/</guid>
      <description>&lt;p&gt;on Tuesday, 13.th of November we realized our second AD security summit with the title: “&lt;a href=&#34;https://ernw-insight.de/de/events/2018-11-13-summit18-ad/&#34;&gt;Active Directory Security: On-Prem-Security, Secure Extension into the Cloud &amp;amp; Secure Operations&lt;/a&gt;” in Heidelberg. First, we had three talks: the first one about “&lt;a href=&#34;https://ernw.de/download/AD_Summit_2018/01_AD_Summit_CoreSecPrinciples_fk_hw_v.1.2_signed.pdf&#34;&gt;Active Directory Core Security Principles &amp;amp; Best Practices&lt;/a&gt;” covering hybrid AD and AD Trusts as well (by Friedwart Kuhn &amp;amp; Heinrich Wiederkehr from ERNW), the second one a case study about the &lt;a href=&#34;https://ernw.de/download/AD_Summit_2018/SecureAD_realWorldScenario_final.pdf&#34;&gt;implementation of an ESAE Forest in a big insurance company&lt;/a&gt; (by Fabian Böhm from &lt;a href=&#34;https://www.teal-consulting.de/&#34;&gt;Teal Technology Consulting&lt;/a&gt;) and the third one about a case study with respect to the (security) challenges of a hybrid AD (by Raphael Rojas from &lt;a href=&#34;https://www.stihl.de/&#34;&gt;STIHL&lt;/a&gt;). The afternoon passed quickly with a very fruitful and vivid discussion about implementing and operating securely ESAE environments and hybrid ADs and how to deal with the high number of AD Trusts many organisations suffer from. Today we published the slides. Enjoy and stay tuned!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Active Directory Security Summit 2018, 13th. of November of 2018</title>
      <link>https://insinuator.net/2018/09/active-directory-security-summit-2018-13th.-of-november-of-2018/</link>
      <pubDate>Mon, 03 Sep 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/09/active-directory-security-summit-2018-13th.-of-november-of-2018/</guid>
      <description>&lt;p&gt;I have the pleasure to announce the Active Directory Security Summit 2018 at 13^(th). of November of 2018. The summit covers current Active Directory security related topics such as challenging tasks of hybrid Active Directory operations as well as new security best practices and some ‘evergreens’ – Admin Tiering implementations (what about Exchange and DNS…??), ESAE operations etc. 😉&lt;/p&gt;&#xA;&lt;p&gt;The primary objective of the Active Directory Security Summit is to bring experts together:&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 Active Directory Security Track, Part 1</title>
      <link>https://insinuator.net/2018/03/%23tr18-active-directory-security-track-part-1/</link>
      <pubDate>Thu, 22 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-active-directory-security-track-part-1/</guid>
      <description>&lt;p&gt;This is the first post discussing talks of the &lt;em&gt;Active Directory Security Track&lt;/em&gt; of &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;this year’s Troopers&lt;/a&gt; which took place last week in Heidelberg (like in the last nine years ;-). It featured, amongst others, a new track focused on Microsoft AD and its security properties &amp;amp; implications. &lt;a href=&#34;https://www.troopers.de/troopers18/agenda/#agenda-day--2018-03-15&#34;&gt;This&lt;/a&gt; was the agenda.&lt;/p&gt;&#xA;&lt;p&gt;The idea for this special track was born out of two considerations:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;we had noted there’s a lot of stuff going on in the space, both on the offense and on the defense side. And in pretty much every incident analysis &amp;amp; response project we were brought in recently Active Directory played a huge role…&lt;/li&gt;&#xA;&lt;li&gt;already in the early phase of the CfP several interesting submissions came in (maybe due to the fact that some big guns of the field had voiced &lt;a href=&#34;https://twitter.com/mattifestation/status/906180147203645440&#34;&gt;very&lt;/a&gt; &lt;a href=&#34;https://twitter.com/christruncer/status/845321214788849666&#34;&gt;kind&lt;/a&gt; &lt;a href=&#34;https://twitter.com/harmj0y/status/710229755795144704&#34;&gt;words&lt;/a&gt; &lt;a href=&#34;https://twitter.com/subTee/status/972191912277901312&#34;&gt;in&lt;/a&gt; &lt;a href=&#34;https://twitter.com/Cneelis/status/845321978089295872&#34;&gt;the&lt;/a&gt; &lt;a href=&#34;https://twitter.com/PyroTek3/status/918214609273868288&#34;&gt;past&lt;/a&gt;)… and creating an extra track simply relieved us from the burden to make a tough choice between those.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;As this was the first Troopers since its creation where I didn’t have any official roles and out of personal interest (in a very distant past I happened to be the co-author of the first German book on &lt;a href=&#34;https://www.amazon.de/Security-unter-Windows-NT-4/dp/3778526707/&#34;&gt;Windows NT4 Security&lt;/a&gt;)  I decided to spend the majority of conference day 2 in the AD track. In hindsight I’m tempted to say that the track was a huge success: brilliant talks, pretty much always a packed room, and quite good discussions after the talks. (yes, of course I’m biased, what makes you think that?).&lt;/p&gt;</description>
    </item>
    <item>
      <title>White Paper on Multi-Factor Authentication in Microsoft Windows Environments</title>
      <link>https://insinuator.net/2018/01/white-paper-on-multi-factor-authentication-in-microsoft-windows-environments/</link>
      <pubDate>Mon, 29 Jan 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/01/white-paper-on-multi-factor-authentication-in-microsoft-windows-environments/</guid>
      <description>&lt;p&gt;A new ERNW whitepaper was just published. I wrote this whitepaper in the course of my bachelor thesis and it examines multi-factor authentication in Microsoft Windows environments:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Credential theft and the subsequent reuse of stolen credentials are a significant problem in today’s information security. To counter the associated risks, a planned approach is required as part of a comprehensive security architecture program. This includes the implementation of multi-factor authentication as an important building block. This whitepaper covers the relevant steps of implementing a multi-factor authentication system in an enterprise environment and closes with a security evaluation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Active Directory Security &amp; Secure Operations July 18, 2017</title>
      <link>https://insinuator.net/2017/06/active-directory-security-secure-operations-july-18-2017/</link>
      <pubDate>Thu, 01 Jun 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/06/active-directory-security-secure-operations-july-18-2017/</guid>
      <description>&lt;p&gt;&lt;em&gt;The following post is in German as it is covering an Event with German as the main language.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;&lt;strong&gt;INSIGHT SUMMIT 2017 präsentiert Active Directory Security &amp;amp; Secure Operations&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Inspiriert durch die erfolgreichen Round Table Sessions der TROOPERS freuen wir uns Ihnen heute mit dem Active Directory Insight Summit 2017 eine weitere Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit vorzustellen.&lt;br&gt;&#xA;Die Veranstaltung beginnt am Morgen mit einer Hinführung zum Thema Active Directory Sicherheit gefolgt von Fallstudien und Vorträgen durch interne und externe Referenten aus Wirtschaft und Industrie. Im Anschluss werden alle Teilnehmer in zwei Gruppen aufgeteilt, die nacheinander an beiden Round Table Sessions teilnehmen (jeder Teilnehmer kann an beiden Sessions teilnehmen). In den Round Table Sessions werden unter Expertenmoderation typische Problemstellungen und Lösungsansätze diskutiert.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS16 Training Teaser: Dos and Don’ts of Secure Active Directory Administration</title>
      <link>https://insinuator.net/2016/01/troopers16-training-teaser-dos-and-donts-of-secure-active-directory-administration/</link>
      <pubDate>Wed, 27 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/troopers16-training-teaser-dos-and-donts-of-secure-active-directory-administration/</guid>
      <description>&lt;p&gt;In the last few years, attack techniques which fall in the categories of “Credential Theft” or “Credential Reuse” have grown into one of the biggest threats to Microsoft Windows environments. Microsoft has stated more than one time, that nearly almost all of their customers that run Active Directory have experienced “Pass-the-Hash” (PtH) attacks recently.&lt;a href=&#34;#_ftn1&#34;&gt;[1]&lt;/a&gt; Once an attacker gains an initial foothold on a single system in the environment it takes often less than 48 hours until the entire Active Directory infrastructure is compromised. To defend against this kind of attacks, a well-planned approach is required as part of a comprehensive security architecture and operations program. As breach has to be assumed&lt;a href=&#34;#_ftn2&#34;&gt;[2]&lt;/a&gt;, this includes a preventative mitigating control strategy, where technical and organizational controls are implemented, as well as preparations against insider attacks. This is mainly achieved by partitioning the credential flow in order to firstly limit their exposure and secondly limit their usefulness if an attacker was able to get them. Although we spoke last year at Troopers 15 about “How to Efficiently Protect Active Directory from Credential Theft &amp;amp; Large Scale Compromise”&lt;a href=&#34;#_ftn3&#34;&gt;[3]&lt;/a&gt;, we would like to summarize exemplary later in this post Active Directory pentest findings that we classified in four categories in order to better understand what goes typically wrong and thus has to be addressed. For a better understanding of the overall security goals, we classified the findings as to belonging as a security best practice violation of the following categories:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat Talks &amp; Papers related to Windows/Active Directory Security</title>
      <link>https://insinuator.net/2015/08/black-hat-talks-papers-related-to-windows/active-directory-security/</link>
      <pubDate>Fri, 07 Aug 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/08/black-hat-talks-papers-related-to-windows/active-directory-security/</guid>
      <description>&lt;p&gt;This year’s Black Hat US saw a number of quite interesting talks in the context of Windows or Active Directory Security. For those of you too lazy to search for themselves 😉 and for our own Windows/AD Sec team (who couldn’t send anyone to Vegas due to heavy project load) I’ve compiled a little list of those.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://twitter.com/pdjstone&#34;&gt;Paul Stone&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://twitter.com/NoxrNet&#34;&gt;Alex Chapman&lt;/a&gt;: WSUSPect – Compromising the Windows Enterprise via Windows Update&lt;br&gt;&#xA;Slides &lt;a href=&#34;https://www.blackhat.com/docs/us-15/materials/us-15-Stone-WSUSpect-Compromising-Windows-Enterprise-Via-Windows-Update.pdf&#34;&gt;here&lt;/a&gt;.&lt;br&gt;&#xA;Whitepaper &lt;a href=&#34;http://www.contextis.com/media/documents/CTX_WSUSpect_White_Paper.pdf&#34;&gt;here&lt;/a&gt;. (Attention: on the BH website there’s an older this. the above link leads to the latest one).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Doc “Best Practices for Securing Active Directory”</title>
      <link>https://insinuator.net/2013/06/microsoft-doc-best-practices-for-securing-active-directory/</link>
      <pubDate>Wed, 05 Jun 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/06/microsoft-doc-best-practices-for-securing-active-directory/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;MS just &lt;a href=&#34;http://blogs.technet.com/b/security/archive/2013/06/03/microsoft-releases-new-mitigation-guidance-for-active-directory.aspx&#34;&gt;released&lt;/a&gt; a new guide on securing Active Directory. At the first glance seems a fairly comprehensive document to me.&lt;/p&gt;&#xA;&lt;p&gt;At this occasion I may furthermore draw your attention to our (German language) &lt;a href=&#34;https://www.ernw.de/wp-content/uploads/ERNW_Newsletter_40_AD_SRV2008R2_BSI_compliant_de_signed.pdf&#34;&gt;newsletter no. 40&lt;/a&gt; covering hardening MS Windows Server 2008 + AD.&lt;/p&gt;&#xA;&lt;p&gt;have a good one,&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
