{"id":4031,"date":"2018-10-09T22:21:36","date_gmt":"2018-10-10T02:21:36","guid":{"rendered":"https:\/\/adsecurity.org\/?page_id=4031"},"modified":"2018-10-19T19:43:19","modified_gmt":"2018-10-19T23:43:19","slug":"defense-detection","status":"publish","type":"page","link":"https:\/\/adsecurity.org\/?page_id=4031","title":{"rendered":"Attack Defense &#038; Detection"},"content":{"rendered":"<p>This page is meant to be a resource for Detecting &amp; Defending against attacks.<br \/>\nI provide references for the attacks and a number of defense &amp; detection techniques.<\/p>\n<p><strong><span style=\"text-decoration: underline;\">Active Directory &amp; Windows Security<\/span><\/strong><\/p>\n<p><strong>ATTACK<\/strong><\/p>\n<p><span style=\"text-decoration: underline;\">AD Recon<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/adsecurity.org\/?p=2535\">Active Directory Recon Without Admin Rights<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=1508\">SPN Scanning \u2013 Service Discovery without Network Port Scanning<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=3700\">Beyond Domain Admins \u2013 Domain Controller &amp; AD Administration<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=3658\">Scanning for Active Directory Privileges &amp; Privileged Accounts<\/a><\/li>\n<li><a href=\"https:\/\/blog.netspi.com\/dumping-active-directory-domain-info-with-powerupsql\/\">Active Directory Recon with PowerUpSQL<\/a><\/li>\n<li><a href=\"https:\/\/www.harmj0y.net\/blog\/tag\/powerview\/\">PowerView Usage Reference Posts by Harmj0y<\/a><\/li>\n<li><a href=\"https:\/\/gist.github.com\/HarmJ0y\/184f9822b195c52dd50c379ed3117993#file-powerview-3-0-tricks-ps1-L20-L21\">PowerView one-liners (GitHub)<\/a><\/li>\n<li><a href=\"https:\/\/www.darkoperator.com\/blog\/2014\/1\/29\/enumeration-using-the-meterpreter-adsi-extended-api-commands\">Enumeration using the Meterpreter ADSI Extended API Commands<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">DCSync<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/adsecurity.org\/?p=1729\">DCSync: Attack &amp; Detection<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">DCShadow<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/www.dcshadow.com\/\">DCShadow.com<\/a><\/li>\n<li><a href=\"https:\/\/blog.alsid.eu\/dcshadow-explained-4510f52fc19d\">DCShadow explained: A technical deep dive into the latest AD attack technique<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>DPAPI<\/p>\n<ul>\n<li><a href=\"https:\/\/www.harmj0y.net\/blog\/redteaming\/operational-guidance-for-offensive-user-dpapi-abuse\/\">Operational Guidance for Offensive User DPAPI Abuse\u00a0<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">Attacking Active Directory<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/www.harmj0y.net\/blog\/redteaming\/a-guide-to-attacking-domain-trusts\/\">A Guide to Attacking Domain Trusts<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=2716\">Sneaky Active Directory Persistence #17: Group Policy<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=1405\">MS15-011 &amp; MS15-014: Microsoft Active Directory Group Policy (GPO) Vulnerabilities<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=451\">How Attackers Pull the Active Directory Database (NTDS.dit) from a Domain Controller<\/a><\/li>\n<li><a href=\"https:\/\/byt3bl33d3r.github.io\/practical-guide-to-ntlm-relaying-in-2017-aka-getting-a-foothold-in-under-5-minutes.html\">Practical Guide to NTLM Relaying<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/advanced-threat-analytics\/suspicious-activity-guide\">Microsoft ATA Guide to Suspicious Activity<\/a><\/li>\n<li><a href=\"https:\/\/blog.netspi.com\/exploiting-adidns\/\">Beyond LLMNR\/NBNS Spoofing \u2013 Exploiting Active Directory-Integrated DNS<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">Active Directory Privilege Escalation:<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/adsecurity.org\/?p=2362\">Attack Methods for Gaining Domain Admin Rights in Active Directory<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=2288\">Finding Passwords in SYSVOL &amp; Exploiting Group Policy Preferences<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=2398\">How Attackers Dump Active Directory Database Credentials<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=1684\">The Most Common Active Directory Security Issues and What You Can Do to Fix Them<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=3592\">Attacking Read-Only Domain Controllers (RODCs) to Own Active Directory<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=4064\">From DNSAdmins to Domain Admin, When DNSAdmins is More than Just DNS Administration<\/a><\/li>\n<li><a href=\"https:\/\/youtu.be\/-bcWZQCLk_4?t=2194\">Domain Controller running Print Server + Unconstrained Delegation = AD Domain Compromise<\/a>\u00a0[<a href=\"https:\/\/github.com\/leechristensen\/SpoolSample\">PoC<\/a>]<\/li>\n<li><a href=\"https:\/\/medium.com\/@adam.toscher\/top-five-ways-i-got-domain-admin-on-your-internal-network-before-lunch-2018-edition-82259ab73aaa\">Top Five Ways I Got Domain Admin on Your Internal Network before Lunch (2018 edition)<\/a><\/li>\n<li><a href=\"https:\/\/blog.netspi.com\/windows-privilege-escalation-part-2-domain-admin-privileges\/\">Windows Privilege Escalation Part 2: Domain Admin Privileges<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">Kerberos (AD) Attacks<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/adsecurity.org\/?p=1667\">Kerberos Unconstrained Delegation (or How Compromise of a Single Server Can Compromise the Domain)<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=541\">Kerberos Vulnerability in MS14-068 (KB3011780) Explained<\/a><\/li>\n<li><a style=\"background-color: #ffffff;\" href=\"https:\/\/adsecurity.org\/?p=3458\">Kerberoast\/Kerberoasting: Attack &amp; Detection<\/a><\/li>\n<li><a href=\"https:\/\/www.harmj0y.net\/blog\/activedirectory\/targeted-kerberoasting\/\">Targeted Kerberoasting\u00a0<\/a><\/li>\n<li><a href=\"https:\/\/www.harmj0y.net\/blog\/powershell\/kerberoasting-without-mimikatz\/\">Kerberoasting without Mimikatz\u00a0<\/a><\/li>\n<li><a href=\"https:\/\/www.harmj0y.net\/blog\/activedirectory\/roasting-as-reps\/\">Roasting AS-REPs (Harmj0y)<\/a><\/li>\n<li><a href=\"https:\/\/www.harmj0y.net\/blog\/activedirectory\/s4u2pwnage\/\">S4U2Pwnage\u00a0<\/a><\/li>\n<li><a href=\"https:\/\/www.trustedsec.com\/2018\/10\/w32-coozie-discovering-oracle-cve-2018-3253\/\">Oracle AD attribute contains hashed version of AD account (user\/computer) password<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">Forged Kerberos Tickets<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/adsecurity.org\/?p=2753\">Computer Accounts &amp; Domain Controller Silver Tickets<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=2011\">How Attackers Use Kerberos Silver Tickets to Exploit Systems<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=1640\">Kerberos Golden Tickets are Now More Golden<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>DEFENSE<\/strong><\/p>\n<p><span style=\"text-decoration: underline;\">Windows Security<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/adsecurity.org\/?p=3377\">Securing Domain Controllers to Improve Active Directory Security<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=3299\">Securing Windows Workstations: Developing a Secure Baseline<\/a><\/li>\n<li><a href=\"https:\/\/adsecurity.org\/?p=559\">Microsoft KB2871997: Back-Porting Windows 8.1\/Win2012R2 Enhanced Security &amp; Pass The Hash Mitigation to Windows 7, Windows 8, &amp; Windows 2008R2<\/a><\/li>\n<li><a href=\"https:\/\/channel9.msdn.com\/Events\/Ignite\/New-Zealand-2016\/M377\">Demystifying the Windows Firewall \u2013 Learn how to irritate attackers without crippling your network (Jessica Payne&#8217;s speaks at Ignite)<\/a><\/li>\n<li><a href=\"https:\/\/medium.com\/@cryps1s\/endpoint-isolation-with-the-windows-firewall-462a795f4cfb\">Endpoint Isolation with the Windows Firewall<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">Windows 10 Security<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/blogs.technet.microsoft.com\/secguide\/2018\/10\/01\/security-baseline-draft-for-windows-10-v1809-and-windows-server-2019\/\">Security baseline (DRAFT) for Windows 10 v1809 and Windows Server 2019<\/a><\/li>\n<li><a href=\"https:\/\/blogs.technet.microsoft.com\/secguide\/2018\/04\/30\/security-baseline-for-windows-10-april-2018-update-v1803-final\/\">Security baseline for Windows 10 \u201cApril 2018 Update\u201d (v1803) \u2013 FINAL\u00a0<\/a><\/li>\n<li><a href=\"https:\/\/blogs.technet.microsoft.com\/secguide\/2017\/08\/30\/security-baseline-for-windows-10-creators-update-v1703-final\/\">Security baseline for Windows 10 \u201cCreators Update\u201d (v1703) \u2013 FINAL<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/windows-defender-exploit-guard\/attack-surface-reduction-exploit-guard\">Windows 10 ExploitGuard Attack Surface Reduction Rules<\/a><\/li>\n<li><a href=\"https:\/\/blogs.technet.microsoft.com\/secguide\/2018\/06\/29\/policy-analyzer-minor-update\/\">Microsoft Policy Analyzer (for comparing GPO settings)<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">Windows Event Auditing<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/auditing\/advanced-security-audit-policy-settings\">Microsoft Docs: Advanced security audit policy settings (great event log resource)<\/a><\/li>\n<li><a href=\"https:\/\/github.com\/MicrosoftDocs\/windows-itpro-docs\/tree\/master\/windows\/security\/threat-protection\/auditing\">Microsoft Windows IT Pro Docs on Github: windows-itpro-docs\/windows\/security\/threat-protection\/auditing\/<\/a><\/li>\n<li><a href=\"https:\/\/blogs.technet.microsoft.com\/jepayne\/2015\/11\/23\/monitoring-what-matters-windows-event-forwarding-for-everyone-even-if-you-already-have-a-siem\/\">Monitoring what matters \u2013 Windows Event Forwarding for everyone (even if you already have a SIEM.)<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">Effective Defenses &amp; Hunting<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/adsecurity.org\/?p=1790\">Manage Local Administrator Account Passwords: Microsoft Local Administrator Password Solution (LAPS)<\/a><\/li>\n<li><a href=\"https:\/\/trimarcsecurity.com\/transcript-detecting-the-elusive-active-directory-threat-hunting-seanmetcalf\">Active Directory Threat Hunting &#8211; Effective AD Event Auditing<\/a>: <a href=\"https:\/\/www.youtube.com\/watch?v=9Uo7V9OUaUw\">Video<\/a> &amp; <a href=\"https:\/\/adsecurity.org\/wp-content\/uploads\/2017\/04\/2017-BSidesCharm-DetectingtheElusive-ActiveDirectoryThreatHunting-Final.pdf\">Slides<\/a><\/li>\n<li><a href=\"https:\/\/blogs.technet.microsoft.com\/jepayne\/2017\/12\/08\/weffles\/\">Build a fast, free, and effective Threat Hunting\/Incident Response Console with Windows Event Forwarding and PowerBI (aka &#8220;Weffles&#8221;)<\/a><\/li>\n<li><a href=\"https:\/\/www.harmj0y.net\/blog\/defense\/hunting-with-active-directory-replication-metadata\/\">Hunting With Active Directory Replication Metadata\u00a0<\/a><\/li>\n<li><a href=\"https:\/\/www.darkoperator.com\/blog\/2017\/10\/14\/basics-of-tracking-wmi-activity\">Basics of Tracking WMI Activity<\/a><\/li>\n<li><a href=\"https:\/\/aka.ms\/toppopslam\">Presentation of SLAM and Lateral Movement (Channel9 video with Jessica Payne)<\/a><\/li>\n<li><a href=\"https:\/\/blogs.technet.microsoft.com\/jepayne\/2015\/11\/26\/tracking-lateral-movement-part-one-special-groups-and-specific-service-accounts\/\">Tracking Lateral Movement Part One \u2013 Special Groups and Specific Service Accounts<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">Application Whitelisting Resources<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/blogs.msdn.microsoft.com\/aaron_margosis\/2018\/10\/11\/aaronlocker-update-v0-91-and-see-aaronlocker-in-action-on-channel-9\/\">\u201cAaronLocker\u201d update (v0.91) \u2014 and see \u201cAaronLocker\u201d in action on Channel 9!<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">Building Robust Detection<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/medium.com\/starting-up-security\/lessons-learned-in-detection-engineering-304aec709856\">Lessons Learned in Detection Engineering<\/a><\/li>\n<li><a href=\"https:\/\/medium.com\/palantir\/alerting-and-detection-strategy-framework-52dc33722df2\">Alerting and Detection Strategy Framework<\/a><\/li>\n<li><a href=\"https:\/\/www.linkedin.com\/pulse\/socless-detection-team-netflix-alex-maestretti\/\">A SOCless Detection Team at Netflix<\/a><\/li>\n<li><a href=\"https:\/\/medium.com\/@cryps1s\/detecting-windows-endpoint-compromise-with-sacls-cd748e10950\">Detecting Windows Endpoint Compromise with SACLs<\/a><\/li>\n<li><a href=\"https:\/\/github.com\/Invoke-IR\/ACE\/\">Automated Collection and Enrichment<\/a><\/li>\n<li><a href=\"https:\/\/github.com\/Cyb3rWard0g\/HELK\/wiki\">The HELK\u00a0<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>ADFS<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/adsecurity.org\/?p=3782\">Securing Microsoft Active Directory Federation Server (ADFS)<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>POWERSHELL<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/adsecurity.org\/?p=2921\">PowerShell Attack &amp; Detection<\/a><\/li>\n<li><a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2018\/07\/malicious-powershell-detection-via-machine-learning.html\">Malicious PowerShell Detection with Machine Learning (FireEye)<\/a><\/li>\n<li><a href=\"https:\/\/blogs.msdn.microsoft.com\/powershell\/2017\/10\/23\/defending-against-powershell-attacks\/\">Defending Against PowerShell Attacks (Microsoft)<\/a><\/li>\n<li><a href=\"https:\/\/www.blackhat.com\/docs\/us-17\/thursday\/us-17-Bohannon-Revoke-Obfuscation-PowerShell-Obfuscation-Detection-And%20Evasion-Using-Science-wp.pdf\">Revoke-Obfuscation: PowerShell\u00a0Obfuscation Detection Using Science (Black Hat whitepaper by Daniel Bohannon &amp; Lee Holmes)<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>TOOLS<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/github.com\/gentilkiwi\/mimikatz\">Mimikatz<\/a>: <a href=\"https:\/\/adsecurity.org\/?page_id=1821\">Info<\/a><\/li>\n<li><a href=\"https:\/\/github.com\/gentilkiwi\/kekeo\">Kekeo<\/a><\/li>\n<li><a href=\"https:\/\/github.com\/sense-of-security\/ADRecon\">ADRecon<\/a>: PowerShell recon tool for AD<\/li>\n<li><a href=\"https:\/\/github.com\/BloodHoundAD\/Bloodhound\/wiki\">Bloodhound<\/a>: Map out AD permissions &amp; rights via graphs<\/li>\n<li><a href=\"https:\/\/github.com\/byt3bl33d3r\/CrackMapExec\">CrackMapExec<\/a>: Pentesting toolkit<\/li>\n<li><a href=\"https:\/\/github.com\/byt3bl33d3r\/DeathStar\">DeathStar<\/a>: A Python script to auto-pwn Active Directory<\/li>\n<li>Impacket: Collection of pentesting python tools<\/li>\n<li><a href=\"https:\/\/github.com\/Kevin-Robertson\/Inveigh\">Inveigh<\/a>: PowerShell tool to get network creds<\/li>\n<li><a href=\"https:\/\/github.com\/NetSPI\/MicroBurst\">MicroBurst<\/a>: Tool for assessing Azure security<\/li>\n<li><a href=\"https:\/\/www.pingcastle.com\/download\/\">PingCastle<\/a>: Tool for evaluating Active Directory security<\/li>\n<li><a href=\"https:\/\/github.com\/PowerShellMafia\/PowerSploit\/tree\/master\/Recon\">PowerView<\/a>: PowerShell AD recon<\/li>\n<li><a href=\"https:\/\/github.com\/jaredhaight\/PSAttack\">PSAttack<\/a>: PowerShell attack tools in an EXE<\/li>\n<li><a href=\"https:\/\/github.com\/SpiderLabs\/Responder\">Responder<\/a>: The easy button for getting network creds<\/li>\n<li><a href=\"https:\/\/github.com\/GhostPack\/Rubeus\">Rubeus<\/a>: the C# port of Kekeo\u00a0<a href=\"https:\/\/www.harmj0y.net\/blog\/redteaming\/from-kekeo-to-rubeus\/\">Info<\/a> &amp; <a href=\"https:\/\/www.harmj0y.net\/blog\/redteaming\/rubeus-now-with-more-kekeo\/\">Updates<\/a><\/li>\n<li><a href=\"https:\/\/github.com\/GhostPack\/Seatbelt\">Seatbelt<\/a>: Host survey tool<\/li>\n<li><a href=\"https:\/\/github.com\/cobbr\/SharpSploit\">SharpSploit<\/a>: a partial C# port of PowerSploit<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>TWITTER ACCOUNTS TO FOLLOW<\/strong><\/p>\n<ul>\n<li>Aaron Margosis <a href=\"https:\/\/twitter.com\/AaronMargosis\">@AaronMargosis<\/a> &#8211; co-author with Mark Russinovich on SysInternal books (and topics), publishes the Microsoft Windows security baselines (Windows 10, Windows Server 2016, etc), and AaronLocker (simpler method of deploying AppLocker).<\/li>\n<li>Andy Robbins <a href=\"https:\/\/twitter.com\/_wald0\">@_wald0<\/a> &amp; Rohan Vazarkar <a href=\"https:\/\/twitter.com\/CptJesus\">@cptjesus<\/a> &#8211; wrote Bloodhound<\/li>\n<li>Benjamin Delpy <a href=\"https:\/\/twitter.com\/gentilkiwi\">@gentilkiwi<\/a> &#8211; wrote Mimikatz &amp; Kekeo<\/li>\n<li>Carlos Perez <a href=\"https:\/\/twitter.com\/Carlos_Perez\">@Carlos_Perez<\/a> &#8211; Red\/Blue\/Purple teamer focused on Windows &amp; AD security and more\u00a0(&amp; Microsoft MVP)<\/li>\n<li>Dane <a href=\"https:\/\/twitter.com\/cryps1s\">@cryps1s<\/a>\u00a0&#8211; has published real-world Windows firewall, Windows Event Forwarding (WEF) references, and other Windows security topics.<\/li>\n<li>DirectoryRanger <a href=\"https:\/\/twitter.com\/DirectoryRanger\">@DirectoryRanger<\/a> &#8211; tweets out useful info relating to AD security<\/li>\n<li>Jason Fossen <a href=\"https:\/\/twitter.com\/JasonFossen\">@JasonFossen<\/a> &#8211; SANS Instructor on Windows security topics<\/li>\n<li>Jess Dodson <a href=\"https:\/\/twitter.com\/girlgerms\">@girlgerms<\/a> &#8211; blogger &amp; speaker on Active Directory security topics (&amp; Microsoft MVP)<\/li>\n<li>Jessica Payne <a href=\"https:\/\/twitter.com\/jepayneMSFT\">@jepayneMSFT<\/a> &#8211; has promoted the use of the Windows Firewall and created WEFFLES.<\/li>\n<li>Lee Christensen <a href=\"https:\/\/twitter.com\/tifkin_\">@tifkin_<\/a> &#8211; wrote many cool tools like unmanaged PowerShell used in most attack tools &amp; discovered the <a href=\"https:\/\/adsecurity.org\/?p=4056\">DC Print Service\/Unconstrained delegation privilege escalation<\/a>.<\/li>\n<li>Marcello <a href=\"https:\/\/twitter.com\/byt3bl33d3r\">@byt3bl33d3r<\/a> &#8211; publishes offensive Windows &amp; AD tools like <a href=\"https:\/\/github.com\/byt3bl33d3r\/CrackMapExec\">CrackMapExec<\/a>, <a href=\"https:\/\/github.com\/byt3bl33d3r\/DeathStar\">DeathStar<\/a>, <a href=\"https:\/\/github.com\/byt3bl33d3r\/SprayingToolkit\">Password Spraying Toolkit<\/a>, etc.<\/li>\n<li>Matt Graeber <a href=\"https:\/\/twitter.com\/mattifestation\">@mattifestation<\/a> &#8211; founded PowerSploit, documented Device Guard, and numerous PowerShell and Device Guard bypasses\u00a0(&amp; Microsoft MVP)<\/li>\n<li>Matt Nelson <a href=\"https:\/\/twitter.com\/enigma0x3\">@enigma0x3<\/a>\u00a0&#8211; discovered numerous Windows vulnerabilities and privilege escalations (top 100 Microsoft security researchers)<\/li>\n<li>Oddvar Moe <a href=\"https:\/\/twitter.com\/Oddvarmoe\">@Oddvarmoe<\/a>\u00a0&#8211; Windows security researcher (&amp; Microsoft MVP)<\/li>\n<li>Sean Metcalf <a href=\"https:\/\/twitter.com\/PyroTek3\">@PyroTek3<\/a> &#8211; maintainer of ADSecurity.org and AD enthusiast.<\/li>\n<li>SwiftOnSecurity <a href=\"https:\/\/twitter.com\/SwiftOnSecurity\">@SwiftonSecurity<\/a> &#8211; the parody account that&#8217;s worth following. Tons of Windows advice and recommendations not found elsewhere based on real world experience\u00a0(&amp; Microsoft MVP)<\/li>\n<li>Vincent LeToux <a href=\"https:\/\/twitter.com\/mysmartlogon\">@mysmartlogon<\/a> &#8211; wrote the DCSync &amp; DCShadow components in Mimikatz<\/li>\n<li>Will <a href=\"https:\/\/twitter.com\/harmj0y\">@Harmj0y<\/a> &#8211; wrote PowerView, the original Bloodhound ingest PowerShell script, Rubeus and more!\u00a0 (&amp; Microsoft MVP)<\/li>\n<li>Microsoft Azure AD <a href=\"https:\/\/twitter.com\/azuread\">@AzureAD<\/a> &#8211; Microsoft&#8217;s Azure Active Directory account tweets info about&#8230; Azure AD topics.<\/li>\n<\/ul>\n<p>Don&#8217;t follow <a href=\"https:\/\/twitter.com\/NerdPyle\">@NerdPyle<\/a> since he doesn&#8217;t talk AD anymore. \ud83d\ude09<\/p>\n<p><em>(I&#8217;m sure there are a bunch I forgot)<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><strong><a href=\"https:\/\/attack.mitre.org\/wiki\/Main_Page\">MITRE ATT&amp;CK<\/a> ACTIVE DIRECTORY RELATED ELEMENTS<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1087\">Account Discovery<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1098\">Account Manipulation<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1003\">Credential Dumping<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1207\">DCShadow<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1212\">Exploitation for Credential Access<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1210\">Exploitation of Remote Services<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1208\">Kerberoasting<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1171\">LLMNR\/NBT-NS Poisoning<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1037\">Logon Scripts<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1177\">LSASS Driver<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1046\">Network Service Scanning<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1040\">Network Sniffing<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1135\">Network Share Discovery<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1075\">Pass the Hash (PTH)<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1097\">Pass the Ticket (PTT)<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1174\">Password Filter DLL<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1201\">Password Policy Discovery<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1069\">Permission Group Discovery<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Privilege_Escalation\">Privilege Escalation<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1018\">Remote System Discovery<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1101\">Security Support Provider<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1178\">SID History Injection<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1016\">System Network Configuration Discovery<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1111\">Two-Factor Authentication Interception<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1077\">Windows Admin Shares<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1047\">Windows Management Instrumentation (WMI)<\/a><\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/wiki\/Technique\/T1028\">Windows Remote Management (WinRM)<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This page is meant to be a resource for Detecting &amp; Defending against attacks. I provide references for the attacks and a number of defense &amp; detection techniques. Active Directory &amp; Windows Security ATTACK AD Recon Active Directory Recon Without Admin Rights SPN Scanning \u2013 Service Discovery without Network Port Scanning Beyond Domain Admins \u2013 &hellip; <\/p>\n<p><a class=\"more-link btn\" href=\"https:\/\/adsecurity.org\/?page_id=4031\">Continue reading<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-4031","page","type-page","status-publish","hentry","nodate","item-wrap"],"_links":{"self":[{"href":"https:\/\/adsecurity.org\/index.php?rest_route=\/wp\/v2\/pages\/4031","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/adsecurity.org\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/adsecurity.org\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/adsecurity.org\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/adsecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4031"}],"version-history":[{"count":47,"href":"https:\/\/adsecurity.org\/index.php?rest_route=\/wp\/v2\/pages\/4031\/revisions"}],"predecessor-version":[{"id":4097,"href":"https:\/\/adsecurity.org\/index.php?rest_route=\/wp\/v2\/pages\/4031\/revisions\/4097"}],"wp:attachment":[{"href":"https:\/\/adsecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4031"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}