For your Global Admin and Privileged Role Admins, if you want to implement an approval process for PIM, below is a screenshot of the setting.
I understand there is some controversy around this setting. As a previous offsec practitioner in Microsoft Cloud, I recommend this coupled with the following mitigations:
1. Managed Device Requirement
2. Approved Named Location
3. Authentication Context
Your Global Admins should be having a conversation with another Global Admin when they need to elevate the role for approved work.
Access reviews quarterly is not enough in my opinion. Checking on your PAWS health (i.e. validating EDR telemetry and device health) during Access Reviews won't hurt either.
Great content from @D1iv3, introducing 𝗿𝗲𝗺𝗼𝘁𝗲 privilege escalation via #NTLM & #Kerberos over DCOM.
I would recommend also using the #RPCFirewall as mitigation on your ADCS servers :)
#BHASIA
Active Directory hardening blog post series, like a boss, by Jerry Devore. Posting this so I can reference it later!
Disabling NTLMv1 https://t.co/b6FZuUrnJ5
Removing SMBv1 https://t.co/Ngp6rGEIcE
Enforcing LDAP Signing -https://t.co/lq7wTHvOXA
Enforcing AES for Kerberos https://t.co/1ws86c9L1s
The xz backdoor was initially caught by a software engineer at Microsoft. He noticed 500ms lag and thought something was suspicious.
This is the Silver Back Gorilla of nerds. The internet final boss.
I'm pumped to announce the release of Misconfiguration Manager, a knowledge base and how-to for both offensive and defensive SCCM attack path management, that @subat0mik, @garrfoster, and I have been working on! Check it out and let us know what you think! https://t.co/OuGS5uLAYA
There seems to be this idea that red teaming is about improving detection, whilst true in part people seem to ignore incident response.
You cant assess IR effectiveness without spreading through a network undetected.
Imo assessing IR provides far more value. Some examples...
Microsoft has a huge list of portals and it is not always easy to keep track of all the naming changes, Therefore, this resource comes in very handy!
[LandingPage] MSPortals
https://t.co/CHptT44ph7
#Microsoft#LandingPage
This is a really cool (and free) service to help you learn just about anything. I love the way it hierarchically breaks concepts down.
https://t.co/iTeyx1Dbsv
The new Incident Response PowerShell V2.0.0 release brings exciting updates such as SIEM exports, new artefact collections, and more. Nice tool!
[Repo] #Powershell Digital Forensics & Incident Response (DFIR)
https://t.co/G1vtrKALRn
Credit: Bert-JanP
#CyberSecurity
From our initial recreation of CVE-2023-23397 based on @MDSecLabs, this is what it looks like from a defender's perspective.
Lucky for us, it's super easy to spot.
1. svchost spawns rundll32 w/attacker UNC path
2. svchost makes distinct HTTP requests
#ThreatHunting#DFIR
A thread of visuals that will change how you think about relationships, careers, success, and life:
1. Who we spend our time with over the course of our lives. Time is precious—cherish it.