DEF CON 32 - Winning the Game of Active Directory - Brandon Colley

DEF CON 32 - Winning the Game of Active Directory - Brandon Colley

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 43:04

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Winning the game of Active Directory is not about gaining domain admin privileges, but about maintaining a secure, continuously improved environment through proactive hardening and vulnerability mitigation 2:15.

Key Takeaways:
• Anonymous access misconfiguration allows unauthorized users to enumerate users and passwords; removing group memberships like "Anonymous logon" and avoiding password exposure in descriptions mitigates this risk 3:00.
• Kerberos pre-authentication misconfigurations expose password hashes; disabling "Do not require pre-authentication" on user accounts prevents this attack 11:38.
• Poor password policies (e.g., weak complexity, reuse) enable credential stuffing and password spraying; enforcing strong policies and account lockout thresholds improves security 12:20.
• Kerberoasting attacks target service accounts with SPNs; identifying and removing unused or vulnerable SPNs (e.g., Jon Snow) reduces attack surface 17:55.
• On-path attacks usingResponder can extract NTLMv1 hashes; disabling LLMSR and enforcing Kerberos NTLMv2 prevents these attacks 20:54.
• ACL misconfigurations in GPOs allow privilege escalation; auditing and restricting delegation rights (e.g., via "Protected Users" group) strengthens domain controls 26:00.

Active Directory security is an ongoing process—patching known vulnerabilities and using tools like Locksmith to automate detection and remediation ensures long-term resilience 39:44.

Sources:

  • 2:15 Discussion on the

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

okay I am with the packet hacking Village and uh this particular speak speaker is being uh sponsored by us and we are delighted to present uh Brandon collie who is going to obviously talk to you about active directory he has been uh he'll tell a little bit about himself but he works for trar security and I'm also proud to call him friend take it away [Applause] thank you Kathy friend Kathy investigator check everybody um all right can you guys hear me okay in the back awesome let's do this so uh title as you all know is winning the game of active directory so a little bit about myself is I served in an operations role managed active directory for about 15 years for multiple different organizations before I joined trar about two and a half years ago of a senior security consultant for them …