
There and Back Again: An Attacker's Tale of DCs in AWS | SO-CON 2025
Source: YouTube · SpecterOps · published May 14, 2025 · 42:14
BLUF: This presentation details the significant security risks of deploying an on-premises Active Directory Domain Controller into AWS, illustrating how hybrid environments can expose organizations to identity-based attacks 0:09.
Key Takeaways:
• The speakers, Leo and James from WitScur Consulting, introduce the scenario of placing a Domain Controller in AWS to highlight potential failure points 0:13.
• The core issue involves the complexity of maintaining secure trust relationships between on-premises infrastructure and cloud resources 0:10.
• Attack path mapping reveals how misconfigurations can allow adversaries to pivot from the cloud back into the corporate network 0:31.
• The discussion emphasizes the need for rigorous identity governance when extending Active Directory to public clouds 0:15.
The presentation serves as a cautionary tale for security teams managing hybrid identity environments, urging them to audit their cloud-connected domain controllers regularly.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[Music] Right. So, welcome everyone. Uh, we're going to be showing you today what happens when you put a domain controller in AWS and how can that can go wrong. Uh, but before we get started, who are these uh two strange individuals standing in front of you? Um, well, this is Leo. He's a senior security consultant and he's the head of our attack path mapping service. Um he's given a bunch of talks before at places like District Con, Death Con, and he's uh here wearing a funny hat at Adversary Village. Um because he does attack path mapping stuff, he has to come up with a bunch of crazy PowerPoint diagrams, uh which we're going to be showing you a few of. It gets pretty intense. And this is James, our interim purple team lead, also a security consultant. H spoken at many conferences, fuzzer…