tips and tricks to know if your active directory auditing tools are even working

20
Fortress that stands still: Tips and Tricks to Know if Your Active Directory Auditing Tools Are Even Working @paulacqure @CQUREAcademy CONSULTING Krzysztof Pietrzak CQURE: Infrastructure & Security Expert CQURE Academy: Trainer Mike Jankowski - Lorek CQURE: Cloud Solutions & Machine Learning Expert CQURE Academy: Trainer

Upload: beyondtrust

Post on 22-Jan-2018

29 views

Category:

Software


0 download

TRANSCRIPT

Page 1: Tips and tricks to know if your active directory auditing tools are even working

Fortress that stands still: Tips and Tricks to Know if Your Active Directory Auditing Tools Are Even Working

@paulacqure

@CQUREAcademyCONSULTING

Krzysztof PietrzakCQURE: Infrastructure & Security ExpertCQURE Academy: Trainer

Mike Jankowski - LorekCQURE: Cloud Solutions & Machine Learning ExpertCQURE Academy: Trainer

Page 2: Tips and tricks to know if your active directory auditing tools are even working

What does CQURE Team do?

Consulting services

High quality penetration tests with useful reports

Applications

Websites

External services (edge)

Internal services

+ configuration reviews

Incident response emergency services

– immediate reaction!

Security architecture and design advisory

Forensics investigation

Security awareness

For management and employees

[email protected]

Trainings

Security Awareness trainings for executives

CQURE Academy: over 40 advanced security

trainings for IT Teams

Certificates and exams

Delivered all around the world only by a CQURE

Team: training authors

Page 3: Tips and tricks to know if your active directory auditing tools are even working
Page 4: Tips and tricks to know if your active directory auditing tools are even working

Agenda

Page 5: Tips and tricks to know if your active directory auditing tools are even working

Auditing Active Directory

You must enable auditing in a domain-level GPO, with no

override, to ensure every system in your domain is

tracking important events.

For Domain members you should audit failed logons,

successful and failed account management and policy

change.

For Directory servers you should monitor critical

directory object change

Use the same GPO to boost the security log size, because

with the increased auditing you’ll need it (but not overdo

this).

Page 6: Tips and tricks to know if your active directory auditing tools are even working

Active Directory Dynamic Objects

Page 7: Tips and tricks to know if your active directory auditing tools are even working

What is the most successful path for the attack right now?

Page 8: Tips and tricks to know if your active directory auditing tools are even working

:)

THE ANATOMY OF AN ATTACK

Healthy Computer

User Receives Email

User Lured to Malicious Site

Device Infected with

Malware

Page 9: Tips and tricks to know if your active directory auditing tools are even working

HelpDesk Logs into Device

Identity Stolen, Attacker Has

Increased Privs

:)

Healthy Computer

User Receives Email

User Lured to Malicious Site

Device Infected with

Malware

Page 10: Tips and tricks to know if your active directory auditing tools are even working

User Lured to Malicious Site

Device Infected with

Malware

HelpDesk Logs into Device

Identity Stolen, Attacker Has

Increased Privs

User Receives Email

Page 11: Tips and tricks to know if your active directory auditing tools are even working
Page 12: Tips and tricks to know if your active directory auditing tools are even working

Chasing the obvious: NTDS.DIT, SAM

The above means:

To read the clear text password you need to struggle!

To perform an analysis on NTDS.DIT the following information

sources are needed from the domain controller:

NTDS.DIT

Registry hives (at least the SYSTEM hive)

SAM, ntds.dit are stored locally on the server’s drive

They do not contain passwords

Page 13: Tips and tricks to know if your active directory auditing tools are even working

Auditing Active Directory is not enough!

Page 14: Tips and tricks to know if your active directory auditing tools are even working

Summary

Start monitoring professionally your AD

Know who has changed what and when

If you detect a successful attack

Report the issue

Investigate or do a penetration test /AD Audit

Perform regular AD Health Checks

Database changes, permission on top-level objects - we

commit obvious mistakes

Page 15: Tips and tricks to know if your active directory auditing tools are even working
Page 16: Tips and tricks to know if your active directory auditing tools are even working

PowerBroker Auditing &

Security Suite

Real-time Change Auditing and Recovery

for AD and Windows environments

Page 17: Tips and tricks to know if your active directory auditing tools are even working

PowerBroker Auditing & Security Suite

Centralized real-time change auditing of Active

Directory, File Systems, Exchange, SQL and

NetApp

Entitlement reporting for AD and File Systems

Continuous backup and recovery for AD

Page 18: Tips and tricks to know if your active directory auditing tools are even working

How does it work?

Page 19: Tips and tricks to know if your active directory auditing tools are even working

Demonstration

Page 20: Tips and tricks to know if your active directory auditing tools are even working

Quick Poll + Q&A

Thank you for attending

today’s webinar.