Domain Persistence: Detection, Triage, and Recovery - Josh Prager & Nico Shyne [SO-CON 2024]

  Рет қаралды 671

SpecterOps

SpecterOps

Күн бұрын

We'll dive into Active Directory domain persistence techniques focused on identifying attacks and reclaiming control over organizational domains after a breach. The presentation explores various advanced adversarial techniques such as credential theft on domain controllers, NTDS access, DCSync, and the creation of Golden and Diamond Tickets. It emphasizes the importance of detecting these methods to effectively triage and counteract them. The presentation highlights the need for organizations to be vigilant in monitoring and securing their domains, as adversaries continually seek innovative ways to maintain access, posing significant threats to data security.
Additionally we'll cover post-compromise strategies, detailing the steps necessary for rotating domain secrets and enhancing Windows Security event auditing to better detect domain persistence activities. We'll provide a comprehensive guide on resetting and securing various account types, including machine, user, and service accounts, and emphasizes the criticality of rotating the KRBTGT account to prevent the abuse of Golden Tickets. This presentation will serve as a starting guide for critical technique detection generation and organizational recovery scenarios.

Пікірлер: 1
Офицер, я всё объясню
01:00
История одного вокалиста
Рет қаралды 6 МЛН
Как мы играем в игры 😂
00:20
МЯТНАЯ ФАНТА
Рет қаралды 3,4 МЛН
Крутой фокус + секрет! #shorts
00:10
Роман Magic
Рет қаралды 29 МЛН
Cybersecurity Architecture:  Data Security
14:48
IBM Technology
Рет қаралды 51 М.
PetitPotam NTLM Relay Attack | Threat SnapShot
6:29
SnapAttack
Рет қаралды 5 М.
Identity Providers for Red Teamers - Adam Chester [SO-CON 2024]
59:57
Why Vertical LLM Agents Are The New $1 Billion SaaS Opportunities
37:06
Data Security: Protect your critical data (or else)
7:22
IBM Technology
Рет қаралды 97 М.
Active Directory, DNS, and DHCP Crash Course for Entry Level IT Support Jobs
47:36
LSA Whisperer - Evan McBroom [SO-CON 2024]
48:21
SpecterOps
Рет қаралды 312
Офицер, я всё объясню
01:00
История одного вокалиста
Рет қаралды 6 МЛН