Jorge de Almeida Pinto: Safeguarding The Security Posture Of Your AD, Pre-Attack And Post-Attack
About this talk
This talk focuses on safeguarding the security posture of Active Directory (AD) both before and after a cyber attack, with specific emphasis on ransomware threats. The speaker, George Yela Pinto, who is a senior architect at Saris, explains the importance of proactively assessing the security of AD through indicators of exposure to identify potential weaknesses. He introduces various tools and methodologies, such as BloodHound and ForestDruid, that can be employed to uncover attack paths and enhance security configurations. The discussion extends to recovery strategies post-attack, highlighting the necessity of robust disaster recovery plans and routine drills to ensure preparedness. Pinto emphasizes the critical need for continuous monitoring and updating of security protocols, including password management and the elimination of legacy protocols, to fortify defenses against future threats.
Full transcript
[Music] good morning everyone thank you for attending this session in the security and architecture uh track about safeguarding the security posture of your ad pre and post attack so my name is George yela Pinto I'm a senior uh um uh architecture and also senior instument respons Le working for saris uh I've been working with uh identity and security and recovery for many many many years done quite
a lot of experience around that top those topics uh saris is in short a c security compy providing both products and services for uh before the attack during the attack and after the attack so one of the things that you always should remember is on the internet there's always somebody trying to attack your network and um as soon as they succeed to enter your network and get
a foothold in your network this is one of the notes that you might see and when you see something like this which in this case is a ransomware note you'll be having a very very bad day especially if it concerns your domain controllers because if it concerns your domain controllers then probably everything is down or will be down or is going to be down very very quickly
so what can you do about this well in this scenario after a ransomware attack obvious solution is to recover from that we'll talk about it a little bit later but it also important to understand what can do together with partner uh and maybe other companies I don't know in the same work area that that you are are in what can you do to prevent you can even
get into this state well apparently the the the the the things that you should do pre attack obviously is to secure and protect your ad it's not just by doing a few things and reactively no you need to proactively search and fix in other words a continuously assess the security of your ad by having a look at so-called indicators of exposure indicators of exposure are basically metrics
that tell you that your in this case active directory obviously has weaknesses and you need to solve those weaknesses before somebody else uses those weaknesses against you to at some point in time present you that so very not so nice um ransomware note how do you do that you can use all kinds of tooling by either creating it yourself like you see in the upper uh sorry
upper right corner uh by do it in for example in Powershell I've done that um uh in the past to for example have a look at uh account settings but also go very very deep into the passwords to understand how weak or how strong they were together with uh specific tooling and also have using the he Bane Pond database but you should also have a look at
security related configurations third party tooling that's out there and there are many out there that are free are for example the saris purple KN tooling that takes a look uh that takes a snapshot of your ad but also your Azure ad and then present you in a nice report what is good and not so good about it the things that not so good is obvious the things
that you need to pay attention to when you look at certified that tool goes a little bit deeper into your certificate Authority but also certificate templates configuration and gives you a deeper view of how things are grouper is a third party tooling both on G GitHub by the way that gives you a deeper look into the configuration of your group policy objects so by using these by
using these tools you can get a deeper understanding on how good or how bad things are but this is as how I call them the static configurations of your active directory you also need to have a look at the invisible attack paths for those uh attack paths let's call call it invisible because they are not they are not necessarily invisible but they are not clear because the
attack BS are a combination of configurations in your active directory and that's why I'm saying it's not really visible for you as a human by using tooling like Forest Druid from saris or blood hound you can get a deeper understanding on how the things are blood hound uh is a tool that is being used by attackers obviously and it gives you basically all the attack PS into
your tier zero because the tier zero that's what the attackers are interested in Forest Ro in the other so Blood Hound is from the outside in Forest through it however does the exact same thing but takes another approach it takes the approach of inside out Forest through it with Inside Out means it looks at your tier zero and then sees uh U um uh everything that interacts
with the tier zero and then you only need to pay attention uh on that stuff that interacts with your here zero not everything in addition looking at indicators of compromise where indicators of exposure tell you the weaknesses indicators of a compromise basically tells you hey these are signs that you have all that your environment has already been misused in some way or another think about DC Shadow
introducing all kinds of weird changes into your active directory and nobody knows who did it that's the whole reason because it's a DC Shadow attack that uh uh it's basically a virtual domain controller that introduces changes there is no change by cver roasting is very effective very easy to do but you need to have a look for it to see if it's going on or not and
that especially occurs when hyper list accounts are being attacked because they have SPN on their account set obviously there are many more things to do but again this is just a technical perspective it's also important to have a look at the not so technical stuff like backups solution of those backups but also restores the disaster recovery plan you need to have in place because if you don't
have a plan what are you going to do when you are under attack or or have been attacked or or even down the only way to make sure that those those attack those plans work is to periodically test them also management very important periodic password resets of your cerber cgt accounts the default domain administrator account and obviously the directory Services restore accounts what can you do today
well obviously you want to uh have a look at your ad and think well this is a bit fluffy and I want to strengthen it from what you see here on the screen to some really bad security sorry um um from uh better security perspective to make sure that it's better protected what can you do about it well there are a few things in that you can
think about is important thing is tearing model tearing is about segregating privileged accounts in into specific categories where tier zero is the highest privilege managing domain controllers and everything that's similar to a domain controller think about your adfs think about GE your ad connect tier one being the applications tier two being the the the the workstations think about it active directory from its nature is very very
open and because it's so open anyone can see anything and look for anything and then attack as needed by introducing tearing you would also be changing permissions to make sure that uh information is not as visible as it should be for example like hiding your tier zero accounts preventing leral movement make sure to implement uh Labs so that the the the local administrative passwords are change on
a regular basis domain admin account is a very very special account if anything else fails the the default domain admin account is the account that will be able to be used and log on into the environment it's very special therefore you can also use it as a break class account there it also because it's so powerful it needs to be secured properly I have a blog post
around these things so make sure to look at my blog um as I mentioned before you need to have procedures in place to reset the passwords of the the the accounts mentioned uh on screen passwords many many people have already talked about them get rid of them if you have the possibility if you don't have the possibility yet to to to get rid of those passwords strengthen
them for users use password phrases for service accounts use machine like password uh passwords and for admins think what is best but preferably use passwordless um Implement password settings objects to make sure that for every uh uh account type service accounts uh um user accounts and admin accounts have appropriate settings to at herbine and prevent P weak password by using enter ID password protection or a thirdparty
solution which if I'm not mistaken is still free lit net password protection which allows you to integrate whatever been pumped account CH you need to monitor account security continuously day by day and clean up as needed because people make changes they forget about it or something is implemented from an historical perspective and then it's not needed anymore you need to clean up if it's not needed clean
it up certificate template certificate authorities every single time we are involved in an IR case and try to help a customer active directory certificate Authority is always included because for whatever reason it looks like people misunderstood the use of certificate templates and their configurations on and how things should have been configured think about it it is very common for us to see where it's possible to get
a certificate that is provided by certificate templates that allows for example the specification of a subject alternate name because I'm able to specify a subject alternate name I can basically impersonate any account in the environment your default Dom main admin account your CEO your CAO anything and then as soon as I've got that a certificate I can authenticate and because I'm able to authenticate I can impersonate
that so make sure to always and have a deep look at your certificate Authority including the certificate Ty configuration and their permissions because the permissions it's all sometimes also a messy part of it Legacy protocols Legacy software it is basically saying that water is W wet but again get rid of those because protocols software configurations from the past not needed not applicable anymore get rid of those
and in addition the other way around is make sure to enable additional protections like signing prot and extended protection because those protections are there to enhance the security of environment don't negate them but try to implement possible I forgot to mention Legacy protocols like Des ntlm V1 SMB V1 get rid of those because those are the entry points of it to get it into your active directory
and then present that note complexity well with complexity uh uh the problem is that uh because it's so complex maybe not many people um uh uh understand the thing that is so complex and because it's so complex it is also difficult to secure again easy to say probably more difficult to do but keep complex complexity as uh reduced as possible keep it as simple as stupid trusts
also trick one we already knew and know from the past at first that's what Microsoft told us many many many years ago the the main was the security boundary which appeared not to be true because it's the forest that's the security boundary there's a condition as soon as you have a trust the forest is no longer the security boundary because if you have a two-way trust well
you have basically extended the trust to the other Forest but what about if you have a single way trust a unidirectional trust you might think well the other the other Forest is trusting me therefore I can access the data on the other Force but the other Force cannot access my data that is not entirely true because there's a shared password to make sure that the trust Works
a unidirectional trust so with unidirectional trusts you need to have a look at those if you have them and protect them and a way to do that is to use for example authentication policies which is possible in Windows Server 2012 R2 and above you want to know more about it because you don't know what to do make uh feel free to contact me and I'll guide you
on how to do that part because it's a little bit too Technical and too um uh long to explain that whole thing important patch patch patch vulnerabilities are in software software is made by people people makes mistakes and continuously um uh updates are coming from all kinds of software Windows your phones everything make sure patch test your backups many people are probably at least I hope so
to test the backups are you having a correct backup but are people also checking if that backup is okay to be restored especially with your domain controllers you need to check that is that backup usable to restore a domain controller and restoring a domain meaning it's not just restoring a few files you need to restore the backup and make sure that the domain controller after being restored
from that backup comes up and running again if it does then you have a valid restore just restoring a few files is not a valid restore the valid restore is actually restoring it and make sure that the main controller comes up back and running that's just a backup and a restore but the whole Dr Drill is meaning restoring your active directory from a ransom wire tack obviously
nobody's going to do that in a production environment but that's why we have test environments I hope that people are not using the production environment as test environments but a separate test environment where you actually are doing the Dr Drill to make sure that everybody everybody knows what he needs to do at the correct point in time also with the correct actions obviously preferably once a year
that that should be done because your infrastructure changes and by doing it once a year you know is that valid is that plan still valid or not or does it require some adjusts because your infrastructure changes your plan might change already mentioned between the lines but it's very important to continue L Monitor and check for expected maybe even unexpected changes in your environment and act upon it
as soon as possible especially the unexpected ones to think about an attacker adding an account to some group or making some permission changes in your active directory you need to be aware that those things are happening and you need to be notified about them but also have a look at the security State and parture of both your active directory and your entra ID so that you know
know where the weaknesses are and can act upon those because if you don't know where the weaknesses are you obviously cannot act why is this so important well active directory today especially in very large environments it is a let's call it the core directory that basically connects everything in a hybrid environment very it is very likely that companies have exra director the primary identity system where they
basically then synchronize stuff to enter ID and then maybe even synchronize identities to other systems or they Federate with other systems to provide single sign on across the whole thing so the integration from a highed identity perspective it's not a bad thing the bad thing occurs when you um using accounts from one system to manage the other system so for example if you have an active directory
account to manage your enter ID that would mean that if the attacker attacks ad and therefore that account you would be able to attack enter ID because that account has permissions in entri ID in other words you need to be very very careful with those Integrations make sure that when you manage systems identity systems as you see as the ones see on screen that from a management
perspective the management accounts are always represented only in that environment and not in other environments because otherwise you will be count uh uh um having the ability of attacking the one environment from the other today if things are set incorrectly it is possible to attack entri ID from active directory but it's also possible the other way around like for example when using Cloud trust using the default
set of uh uh the default uh configuration you are able to attack active directory from your enter ID you want to know more about it feel free to contact me offline and think about it exit directory was built designed today more than 25 years ago in the 1999 area it was designed to withstand um localized um um threats floods power outages it was not designed like aure
ad is today it was not designed for cyber attacks Network threats it's a different view on how exra directory should be uh should be protected and that's why it also so difficult to protect exra directory because it was not built for the world of today and still many many organizations and people are using it and also keep in mind that many choices that were made in the
past because they were valid back then they might not be valid anymore today why because it's insecure think about old protocols old settings that shouldn't be there anymore make sure to keep that in mind and get rid of those as I mentioned a few times already more business reasing regulations for example in the Netherlands banks are obligated to have Disaster Recovery plan of their ad and probably
other systems uh as part of their business continuity plan why because especially a few banks in the Netherlands uh are called the so the the bankingsales in deep deep trouble so those especially those Banks need to stay up at whatever cost because it's going to uh have a very very um many issues throughout the country and it probably does also plays into account in other countries complexity
from a technology perspective it is very complex but from a management perspective managers might think oh restoring active directory just restore a few backups and you'll be good in theory it may look like that but in practice it's difficult I know because I've done it m many many times before and it's for me it's easy because I know what to do but from the other things it's
easy because you need to be prepared and if you're not prepared it becomes more complicated so being prepared is very very uh much part of it reinstalling and recovering one domain controller is easy but if you have to recover a an environment that's distributed uh across the globe all over the place I don't know let's say 100 domain controllers it's not just restoring the domain contrs but
it's restoring the service making sure it's up and running again if you've outsourced your environment do you have the confidence that your Outsourcing party has the knowledge to recover your environment if you're unsure make sure to ask them because they need to be risk management for many many years um it was very let's say unlikely that ad would go down but these days it's not more than
if but rather when because as I mentioned before for there are many many people trying to attack your adid and to get a foot hold in it think about it if your ad is down are the risks acceptable and obviously the costs that come with it because as soon as you are down you are losing money like crazy and how long can you keep it up all
kinds of scenarios from an impact and and and probability perspective what does it mean what are the things that can happen as I mentioned for many many years I was talking about these uh uh options with customers these are the things that could happen when your ID and that that could happen that your ID goes down How likely are they what's the probability and what's the impact
on the environment and to be very honest um I cannot say I encountered one of these uh um obviously there are small things because of mistakes but throughout the years but as soon as the first ransomware tax occurred this is basically an a byday basis occurring around the globe and we see it many many times where environments are basically attacked breached destroyed and action is required so
this is a different ball game but then again looking at the options before database Corruptions in 20 I think 23 years as I mentioned these things never happened until a company called me um about two years or so ago and basically told me hey our active director we have an issue it's still up and running but every single domain controller has a corrupt database and that's really
caught my attention because in that scenario when database that means that you need to go back in time you need to perform a force recovery because the database is basically broken although it's it's it's um working it's broken promotions didn't go well so the only way was to go back in time guess what they had to go back to months in time why because the backups they
were creating they were not testing backups the backups they were creating and also not the resource uh had the corrupt databases so the corruption started two months earlier and guess what again they had to perform a forest recovery and the moment they had to perform the forest recovery that Disaster Recovery plan did not work because the restore continuously failed the service failed this is not the moment
to find out that your Disaster Recovery plan is not working in the end I was able to help them with let's call it some black magic but it's not the moment to find out that your plan your restor your backups are not working you need to let's say find out before the the the moment that you need them when you go down you have a few options
and one of those options is basically if and this is the scenario a ransom everything is burned to the ground what do you do rebuild from scratch is an option and this basically means reinstall everything reconfigure everything recreate all the objects in your active directory rejoin all the servers if you still have servers rejoin all the clients again if you still have clients reconfigure permissions group memberships
everything needs to be reconfigured as if you were starting a new company today that will take a huge amount of time and in my perspective it's not recommended however I also know that some of let's call it security companies might suggest that part but because it's gives you more trust from that perspective I say well it's true it gives you more trust because everything is new the
attacker doesn't have anything that's new so only you would have it it all the attacker only has the the let's say the power over what was already there however is this really the moment to rebuild everything not in my opinion that's why I'm not recommending it so what is recommended way is to recover from backup restore into an isolated environment preferably use the most recent backup and
I will explain later why assess the security of whatever was restored in that isolated environment and then categorize into shortterm midterm long-term things that need to be fixed and especially the shortterm uh issues which are the critical and most important issues those are the ones that you should focus on um in that isolated environment and fixing them before going back into production and obviously an isolated environment
can mean many things there are a few options like really a separate Network where nobody can do anything besides you and your colleagues obviously it's about doing stuff without interference from any attacker and another way to isolate the environment is that and that's only possible if you already have it is for example if your domain controllers are in a second SE Network where you basically isolate that
existing network from any interaction from the outside that's also a way to create an isolated Network what applies to you I don't know you have to figure it out to see what the possibilities are and looking at the things that you have available this is what I would recommend why because it's faster you have less downtime you have less impact because even though I'm I'm saying less
impact I'm not saying no no impact at all it's less impact but you'll be faster um you'll be quicker in getting things back up and running and most of the things will continue to work you will always have issues trust me that there's no 100% guarantee but it does require that you are prepared to act upon it you need to have a plan you need to know
what to do those are the Dr Drills you need to have the tooling scripts third party tooling whatever and again keep it as simple as stupid complexity is a killer for success keep it as simple and stupid it mitigates the risk and the impact and then you might ask yourself yeah but if I restore the environment trust well it is true that's why I'm saying fix all
the critical and most important stuff because the goal in my opinion is to get your business up and running as fast as possible and as soon as you're fast up and running again as fast as possible in the most secure way possible in that uh time period of able then you can think about additional actions because performing a migration or a new installation during the a ransomware
attack it's a bad decision after the attack then you can think about okay do I still trust this environment would I like to migrate to a new ad uh because I don't trust the old one that's then the decision that you can make if you really want to do it not during the attack because it's it's a wrong moment for that specific decision the whole recovery and
ransomware is already a big uh headache to think about so let's have a look at the options for Recovery when you look at the Microsoft uh documentation this is what you get uh all kinds of steps that you have to execute manually I've done this a few times until you get fed up with it and you think I need to automate and then when you automate those
things you get for example things like these these are scripts that I built for a customer many many years ago uh to automate it in let's say uh do it yourself it's not 100% automation but it's more automation than by just clicking through the all the steps that you just saw in the previous screen but the other option the third option is the fully automated you buy
a third party recovery tooling that basically recovers your environment and you can do something else today I'm not doing it but most of the time when I present a a presentation like this one I start the recovery at the beginning of my presentation and when I'm done presenting my environment has been recovered and it's up and running again when I'm using either the first or the second
option I cannot do that because I need to work on it and with this I'll basically give everything away to the tool and the tool takes care of it until it's tells me I'm done and everything recovered let's compare those options management looking at the left and the middle options well maintenance Knowledge and Skills when you're doing any anything manually you need to know what you're doing
otherwise it's going to be very very difficult the second option the middle one you need to understand on how to maintain it how to deal with all the changes in your environment and then incorporating into your scripts that's where the knowledge goes obviously you also need to still need to know when and what to do but the third option it's fully automated all the knowledge is in
the tool you just start it and at the end it's done it's easier trust me me as I mentioned before yes we sell a third party tooling but I'm just not talking about us because there are other third party vendors out there make sure to buy a tool because it's it's there's it's a game changer orchestration many tools allow you to back up active directory automatically but
do not allow you to recover a domain controller recover that backup and in terms of AD it's not recovering a DC uh uh only you also need to recover the service when looking at the first options it's automatically res uh sorry backing it up but restoring the backup and the domain the the service itself H it depends on how things have been done but you look at
the tool it performs everything automatically and that's again a game changer backup and size with the two on the left window server backup on the right it's propriety and um it's smaller for example looking at our tool we only look at the ad data we don't care about the operating system and because we don't care about the operating system we also don't take malware along important to
understand is make sure whatever tool you take make sure that the backup and recovery tool are not part of their ad it should be ad aware but it should not be ad integrated and if you ask yourself why because if you attack your ad I would be able to attack the backup solution also which you don't want it's not the first time that I've seen where a
custom customer has their ad attacked and their backup solution also attacked because everything is so tightly integrated again you don't want it high level way of working looking at the left two options most of the times you restore a single domain controller per domain and then you clone and redeploy additional domain controllers with a tool you can restore a single multiple or re redeploy after as you
want lots of flexibility many options available automation well it's obviously if you do anything manual it will be slow you will succeed but it will very slow if you automate it's faster if you have a tool it's even faster things not to forget is that when you recover your ad think about it you are performing recovery because you were attacked and because you were attacked you need
to recover and why were you attacked because your configurations were weak there were weaknesses so after the recovery what I'm trying to say is that after the recover in whatever scenario you must perform a security assessment and take any risk mitigating actions to make sure you're not attacked again because if you don't do it and you go back into productionist uh after recovery probably you will doing
this exercise um in a few weeks again preparing for the worst in um terms of hybrid identity Cloud identity it's an easy one hybrid identity different ball game if you have password has synr ization you're good to go there is no real- time dependency with your active directory for authentication pass through authentication different bu it depends on ad being available so if your ad is down so
is your authentication towards aure ad or enter ID the same applies for Federate authentication like for example adfs because it heavily depends on ad has a real-time dependency what are the options to fix the letter to is to implement password has synchronization as disaster recovery for authentication as a backup only then you would be able to survive that attack and allow authentication during or after the attack
uh by switching from pass through or adfs to Native authentication if you don't have password hash sync as a backup you have an issue and you will have an outage until your ad is back up again these are the scenarios that we find that that we uh within our company categorized so we have three scenarios and this is the one that where a ad is attacked but
still running what we always do and it's from an insurance perspective between quotes is take a backup as soon as possible using our tool we Implement tool a tool called ESP in this case to get a view of all the changes that are occurring uh in the environment so we get visibility of the things that are happening we perform a security assessment as I mentioned before for
short mid and long-term everything that's on the short-term list is implemented right away to make sure the environment is as secure as possible and then it's back into production again but you really must be sure this is even possible because if it's not you get basically into the second Environ sorry the second scenario where ad is compromised in this case we do the initial steps uh uh
as I mentioned before we take a backup change monitoring uh tool into the environment to get visibility but we although the the the environment is up and running we still perform the the backup recover environment again change not uh uh change visibility into the environment everything that we have changed we perform the security assessment in that uh isolated environment and we fix whatever needs to be fixed
on the short term and then we turn off the old ad and then we replace the old ad with the one from the isolated Network I also realize this might not always be feasible for every single environment but it's something to work with to make sure it could work for your environment or think about other ways on how you could um Implement s scenario and the third
and last scenario that we categorize is AD has been attacked and it's down it has been burned to the ground think about the ransomware note that you saw in the beginning um it can obviously all happen to our customers um that have our tooling but let's call it honestly it has uh all the calls that we have had are from customers that do not have our tooling
and they call us for help because they've been burned to the ground well we cannot take a backup of anything that is already down so what we try to help is to recover the environment using whatever backup method or option that because trust me I've also seen customers that don't have a backup or the backup have all backups have all Al been compromised in one way or
another so we try to recover the environment the ad in this case uh into the first isolated Network that's where we take the backup using our tool again care about the operating system data so anything that's uh ransomware like in the operating system We Leave Behind we restore into the secondary isolated Network we perform the security assessment very important after recovery Implement all the high critical changes
into that environment and then we move the thing into the production so preferred backup ads burn to the ground backup of yesterday backup of 10 days ago which one do you choose well again very important to any backup that you restore and you would like to go production it's about recovery and security so after recovery whatever backup you need to perform a security system to make sure
that everything is as secure as possible because if you don't well you might be doing this exercise again in a few weeks so what do you prefer fix the changes and the and and and the mismatches in the restored ad between today and just one day ago or 10 days ago so think about it the further you go back in time with your backup the bigger the
changes are compared to today think about passwords that are missing matching accounts not existing or accounts that are still there so you will have more and more issues the older the backup is therefore I always prefer to say keep the gap of differences between today and the backup as small as possible so if you have a backup of an hour ago use that one it is easier
to fix the security of a backup after restoring an isolated environment than closing all the gaps it's a bigger headache to close the the the gaps in terms of recovery of everything is in sync and then it's ransomware you perform a force recovery and then it's down what do you do and as you can see objects are missing if you would just enable synchronization it could mean
and this is an assumption where the synchronization is still up and running and it's not down because it can be Cloud sync or connect sync um because the synchronization doesn't see those objects anymore they have not been deleted but they are not in the app uh in the backup because were created after backup it might cause deletions in your ENT ID which from a user perspective might
be impactful for the user from a group perspective well users are uh in the recycle bin the groups are not so very very very tricky and because the the groups are not in a recycle bin in ENT ID the synchronized ones at least um they are gone forever so think about the licensing group suddenly disappear and then everybody loses their license because the group was deleted what
you need to do is basically recreate the objects perform the Gap analysis using enter ID and see what is missing in ad create the objects making sure they have the immutable ID technical story but then in the end you would be okay and your s it could be a enable synchronization again it's a lot of work uh at this point in time I'm automating this as much
as possible and I will blog about it at some point in time but it's just a lot of work trust me be prepared for this real life scenario just a five five minutes left and I think I can do it in five minutes uh because it's just a few slides this is about a customer calling us uh requiring help and I let's keep it short we started
with scenario one where we tried to fix the environment live and then at some point in time we basically turned into scenario two where we performed the recovery and this is what we did the ad was compromised was attacked and compromised one of the things we did immediately as I mentioned before was to create a a backup and also immediately restart that backup in an isolated environment
at this point in time we did not know if we would need it or not it was just let's just this do these few steps with a few colleagues because if we need to do them we are prepared to continue with that restore at that point in time we continued with the live environment but also one of the things we did is prevent changes freeze the environment
make sure there are no changes anymore and then when you think about no changes think about passwords those continuously change for users when they're forced to change the password but also computers and also gmsa so what we did is prevent the change of passwords or refuse the change of passwords to keep everything as is as possible we created the backups well this is a little bit of
commercial thing not important right now we performed the vulnerability analysis using a few tools this is about one and a half years ago we use purple Knight to to to understand the the the static changes we used certifi to get a deeper understanding of certificate templates and we used Blood Hound for the attack analysis and this what this is what we saw the main computers were allowed
to change certificate templates think about it I have an I'm an admin on a computer because I'm an admin on a computer I can impersonate that computer because I can impersonate that computer I would allow would be allowed to change the certificate template then issue a certificate myself and then impersonate the default domain admin account game easy help desk account which was configured to reset the password
of all kinds of other accounts sounds feasible but the other way around was implemented everyone was basically allowed to to reset the password of the help desk account which was allowed to imp to reset the password of the other accounts in other words everybody was allowed to reset the password of everyone and then we found out it's not one attacker but it's multiple attackers oops after performing
the vulnerability analysis we decided let's continue with the use of the compromised ID and restore and Harden the environment as much as possible that's what we did implemented all kinds of things after implementing those kinds of things we shut down the old ad we moved the restored ad back into the production environment we had to reboot all the servers because of the secure channels and the cber
stickets and then everything afterwards worked very nicely that customer today is very happy and they're still up and running and uh successful because we help them uh get away from that uh attack they survived as I mentioned recommendations takeaways I think throughout the prep the presentation I think you you could see um a call out make sure to be prepared being prepared means it will save you
time lots of work and especially also many any headaches proactively you need to secure your environment with identity threat detection tools make sure to assess and monitor security but also act in near real time if you're too late it's the other guy that's in time not you make sure to be in time you need to win the story not the other guy reactively being able to secure
it's not about ad only you need to include everything that depends on your active directory not from a technology perspective but also from a process perspective the the so-called non-technical stuff think about it people process and tools it's about the whole thing it's not just the technology that you need to take into account also when there's an attack think about possible or immediate pre actions to in
to to um mitigate any impact or risk it's about being prepared if you're not prepared you might not be able to know what to do but also post actions like improving security immediately after the recovery but also the ability to perform a gap analysis as I mentioned before and then recreate the objects to make sure that there's no impact in insur get help before the attack not
after obviously after many will help but before it's it's easier and less impactful make sure to have password synchronization again Gap analysis and fix automate as much as possible it will save you a huge amount of time and only also think about other systems like Azure ad connect and adfs use tools and scripts make sure to have procedures validate your backups and exports perform Disaster Recovery drills
make sure to have a plan to be able to use those not just for reality but also when you are performing that drill and watch out for Integrations prevent cross contamination from one tier zero to the one and this was it thank you so much if you have any questions please let me know I'm looking to the chats I'm not seeing anything well let me wrap it
up Don thank you so much for listening to my presentation if you have any questions uh feel free to contact me with whatever question you might have and um hope to talk to you thank you so much have a great day