Active Directory Security

Identity Attack Watch: July 2021

Identity Attack Watch: July 2021

  • Semperis Research Team

Cyberattacks targeting Active Directory are on the upswing, putting pressure on AD, identity, and security teams to monitor the constantly shifting AD-focused threat landscape. To help IT pros better understand and guard against attacks involving AD, the Semperis Research Team offers this monthly roundup of recent cyberattacks that used AD…

Applying the MITRE ATT&CK Framework to Your Active Directory

Applying the MITRE ATT&CK Framework to Your Active Directory

  • Nikolay Chernavsky

I recently had the pleasure of teaming up with Ran Harel, principal security product manager at Semperis for a webinar focused on making the MITRE ATT&CK Framework relevant and actionable for organizations seeking to ramp up their security. In the webinar we zeroed in on the most attacked target –…

Time to Leave ADFS Behind for Authenticating in Hybrid Environments?

Time to Leave ADFS Behind for Authenticating in Hybrid Environments?

  • Doug Davis

One of the biggest challenges of adopting cloud services is extending identity policies from the on-premises environment into the cloud. In an Active Directory (AD) environment, it might be tempting to turn to Active Directory Federation Services (ADFS), which has long been the answer for providing single sign-on capabilities to…

What You Need to Know about PrintNightmare, the Critical Windows Print Spooler Vulnerability

What You Need to Know about PrintNightmare, the Critical Windows Print Spooler Vulnerability

  • Ran Harel

Update July 6, 2021: Microsoft has released a patch for CVE 2021-34527, available here. Another week, another critical vulnerability. The latest critical security flaw is dubbed “PrintNightmare,” a reference to two vulnerabilities in the Windows Print Spooler service—CVE 2021-1675 and CVE 2021-34527, published between June and July 2021. CVE 2021-1675…

Identity Attack Watch: June 2021

Identity Attack Watch: June 2021

  • Semperis Research Team

Cyberattacks targeting Active Directory are on the upswing, putting pressure on AD, identity, and security teams to monitor the constantly shifting AD-focused threat landscape. To help IT pros better understand and guard against attacks involving AD, the Semperis Research Team offers this monthly roundup of recent cyberattacks that used AD…

Semperis Directory Services Protector Wins 2021 Fortress Cyber Security Award

Semperis Directory Services Protector Wins 2021 Fortress Cyber Security Award

  • Semperis Team

Semperis was named a winner in the 2021 Fortress Cyber Security Awards (Incident Response category) for Directory Services Protector (DSP). The Fortress Awards identify and reward the world’s leading companies and products that are working to keep data and electronic assets safe among a growing threat from hackers.  Semperis Directory Services…

Three Steps to Harden Your Active Directory in Light of Recent Attacks

Three Steps to Harden Your Active Directory in Light of Recent Attacks

  • Brian Desmond

In a recent webinar I co-hosted with Semperis (the folks behind the Purple Knight security assessment tool), we focused on a key common denominator across recent high-profile attacks—Active Directory. In the session “How Attackers Exploit Active Directory: Lessons Learned from High-Profile Breaches,” Sean Deuby and Ran Harel from Semperis joined…

Identity Attack Watch: May 2021

Identity Attack Watch: May 2021

  • Semperis Research Team

Cyberattacks targeting Active Directory are on the upswing, putting pressure on AD, identity, and security teams to monitor the constantly shifting AD-focused threat landscape. To help IT pros better understand and guard against attacks involving AD, the Semperis Research Team offers this monthly roundup of recent cyberattacks that used AD…