This is the first post discussing talks of the Active Directory Security Track
of this year’s Troopers which took place
last week in Heidelberg (like in the last nine years ;-). It featured, amongst
others, a new track focused on Microsoft AD and its security properties &
implications.
This was
the agenda.
The idea for this special track was born out of two considerations:
we had noted there’s a lot of stuff going on in the space, both on the offense
and on the defense side. And in pretty much every incident analysis & response
project we were brought in recently Active Directory played a huge role…
already in the early phase of the CfP several interesting submissions came in
(maybe due to the fact that some big guns of the field had voiced
verykindwordsinthepast)… and creating
an extra track simply relieved us from the burden to make a tough choice
between those.
As this was the first Troopers since its creation where I didn’t have any
official roles and out of personal interest (in a very distant past I happened
to be the co-author of the first German book on
Windows NT4 Security)
I decided to spend the majority of conference day 2 in the AD track. In
hindsight I’m tempted to say that the track was a huge success: brilliant talks,
pretty much always a packed room, and quite good discussions after the talks.
(yes, of course I’m biased, what makes you think that?).
A new ERNW whitepaper was just published. I wrote this whitepaper in the course
of my bachelor thesis and it examines multi-factor authentication in Microsoft
Windows environments:
Credential theft and the subsequent reuse of stolen credentials are a
significant problem in today’s information security. To counter the associated
risks, a planned approach is required as part of a comprehensive security
architecture program. This includes the implementation of multi-factor
authentication as an important building block. This whitepaper covers the
relevant steps of implementing a multi-factor authentication system in an
enterprise environment and closes with a security evaluation.
The following post is in German as it is covering an Event with German as the
main language.
INSIGHT SUMMIT 2017 präsentiert Active Directory Security & Secure
Operations
Inspiriert durch die erfolgreichen Round Table Sessions der TROOPERS freuen wir
uns Ihnen heute mit dem Active Directory Insight Summit 2017 eine weitere
Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit
vorzustellen.
Die Veranstaltung beginnt am Morgen mit einer Hinführung zum Thema Active
Directory Sicherheit gefolgt von Fallstudien und Vorträgen durch interne und
externe Referenten aus Wirtschaft und Industrie. Im Anschluss werden alle
Teilnehmer in zwei Gruppen aufgeteilt, die nacheinander an beiden Round Table
Sessions teilnehmen (jeder Teilnehmer kann an beiden Sessions teilnehmen). In
den Round Table Sessions werden unter Expertenmoderation typische
Problemstellungen und Lösungsansätze diskutiert.
In the last few years, attack techniques which fall in the categories of
“Credential Theft” or “Credential Reuse” have grown into one of the biggest
threats to Microsoft Windows environments. Microsoft has stated more than one
time, that nearly almost all of their customers that run Active Directory have
experienced “Pass-the-Hash” (PtH) attacks recently.[1] Once an
attacker gains an initial foothold on a single system in the environment it
takes often less than 48 hours until the entire Active Directory infrastructure
is compromised. To defend against this kind of attacks, a well-planned approach
is required as part of a comprehensive security architecture and operations
program. As breach has to be assumed[2], this includes a
preventative mitigating control strategy, where technical and organizational
controls are implemented, as well as preparations against insider attacks. This
is mainly achieved by partitioning the credential flow in order to firstly limit
their exposure and secondly limit their usefulness if an attacker was able to
get them. Although we spoke last year at Troopers 15 about “How to Efficiently
Protect Active Directory from Credential Theft & Large Scale
Compromise”[3], we would like to summarize exemplary later in this
post Active Directory pentest findings that we classified in four categories in
order to better understand what goes typically wrong and thus has to be
addressed. For a better understanding of the overall security goals, we
classified the findings as to belonging as a security best practice violation of
the following categories:
This year’s Black Hat US saw a number of quite interesting talks in the context
of Windows or Active Directory Security. For those of you too lazy to search for
themselves 😉 and for our own Windows/AD Sec team (who couldn’t send anyone to
Vegas due to heavy project load) I’ve compiled a little list of those.
Paul Stone &
Alex Chapman: WSUSPect – Compromising the Windows
Enterprise via Windows Update
Slides here.
Whitepaper
here.
(Attention: on the BH website there’s an older this. the above link leads to the
latest one).