ACTIVE DIRECTORY : HOW TO CHANGE A WEAK POINT INTO A LEVERAGE FOR SECURITY MONITORING

No ratings

Presented at First 2017 by

Vincent Le Toux is the "incident prevention, detection, response manager" at the corporate level of Engie, a large energy company, managing SOC / CSIRT activities. On a personal side, he's the author of the DCSync attack included in Mimikatz and writes many papers in the French review MISC. He designed the PingCastle tool (https://www.pingcastle.com). There are a lot of scary presentations made by pentesters on security conferences. Some advices are communicated but they are technical ones and CISO, CERT, ...have difficulties to change the situation. As the author of the DCSync attack (included in Mimikatz & powershell empire) and working at the corporate level of a multinational, I was facing problems nobody could answer. How much domains do we have ? Why auditors were able to list our accounts without any account on our domain ? Are we secure ? (especially with these new attacks) Asked to solve the "AD situation" I decided to create a methodology that I'm sharing here. The idea is not to focus on the technical side, but to get the management support (and budget) by being able to translate the technical situation into risks. And to make the infrastructure guys aware of their problems so they can solve it (with a lot of management pressure ;-)). The presentation is in 4 parts: Context. Why this project had to be managed at the corporate level ? General vulnerabilities of the Active Directory. How bad is the situation ? Methodology presented. How to make the link between attacks and risks to get management support? Trying to secure the AD. Are monitoring / hardening tools available on the market efficient ? Conclusion Key findings: You have more AD than you think (multiply by 2 or 3) You have trust with external companies with no protection! You can act right now by discovering many problems even without an account on the domain to audit You will show to the management contradictions between local management and corporate management. Reminder: ALL domain administrators in a forest can own the forest !