There and Back Again: An Attacker's Tale of DCs in AWS | SO-CON 2025

There and Back Again: An Attacker's Tale of DCs in AWS | SO-CON 2025

Source: YouTube · SpecterOps · published May 14, 2025 · 42:14

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

BLUF: This presentation details the significant security risks of deploying an on-premises Active Directory Domain Controller into AWS, illustrating how hybrid environments can expose organizations to identity-based attacks 0:09.

Key Takeaways:
• The speakers, Leo and James from WitScur Consulting, introduce the scenario of placing a Domain Controller in AWS to highlight potential failure points 0:13.
• The core issue involves the complexity of maintaining secure trust relationships between on-premises infrastructure and cloud resources 0:10.
• Attack path mapping reveals how misconfigurations can allow adversaries to pivot from the cloud back into the corporate network 0:31.
• The discussion emphasizes the need for rigorous identity governance when extending Active Directory to public clouds 0:15.

The presentation serves as a cautionary tale for security teams managing hybrid identity environments, urging them to audit their cloud-connected domain controllers regularly.

Sources:

  • 0:09 Introduction of the topic: Domain Controllers in AWS.
  • 0:13 Overview of potential security failures.
  • 0:31 Importance of attack path mapping in this context.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[Music] Right. So, welcome everyone. Uh, we're going to be showing you today what happens when you put a domain controller in AWS and how can that can go wrong. Uh, but before we get started, who are these uh two strange individuals standing in front of you? Um, well, this is Leo. He's a senior security consultant and he's the head of our attack path mapping service. Um he's given a bunch of talks before at places like District Con, Death Con, and he's uh here wearing a funny hat at Adversary Village. Um because he does attack path mapping stuff, he has to come up with a bunch of crazy PowerPoint diagrams, uh which we're going to be showing you a few of. It gets pretty intense. And this is James, our interim purple team lead, also a security consultant. H spoken at many conferences, fuzzer…