Active Directory Security

Active Directory Security: Abusing Display Specifiers

Active Directory Security: Abusing Display Specifiers

  • Darren Mar-Elia | VP of Products

I was reminded recently about a feature in AD that I haven’t used in nearly 20 years, one that can be abused by attackers. This feature is based on an area in the Configuration partition within a given Active Directory forest called Display Specifiers. I’m sure these have many roles…

How to Defend Against Ransomware-as-a-Service Groups That Attack Active Directory

How to Defend Against Ransomware-as-a-Service Groups That Attack Active Directory

  • Semperis Team

Concern about the Colonial Pipeline ransomware attack by DarkSide has expanded beyond the cybersecurity industry and into the consciousness of the everyday consumer—an indicator of the extensive implications the attack has on the global economy. In response, the Biden administration issued an executive order and held a press conference, and…

Hafnium Attack Timeline

Hafnium Attack Timeline

  • Sean Deuby | Principal Technologist

The attacks on Microsoft Exchange servers around the world by Chinese state-sponsored threat group Hafnium are believed to have affected over 21,000 organizations. The impact of these attacks is growing as the four zero-day vulnerabilities are getting picked up by new threat actors. While the world was introduced to these…

Identity Attack Watch: April 2021

Identity Attack Watch: April 2021

  • Semperis Research Team

Cyberattacks targeting Active Directory (AD) are on the upswing, putting pressure on AD, identity, and security teams to monitor the constantly shifting AD-focused threat landscape. To help IT pros better understand and guard against attacks involving AD, the Semperis Research Team offers this monthly roundup of recent cyberattacks that used AD to introduce or propagate malware. In this April roundup, the Semperis Research Team highlights identity-related cyberattacks,…

Active Directory Experts Have a Future in Security

Active Directory Experts Have a Future in Security

  • Gil Kirkpatrick

Between the growth of cloud applications and a changing threat landscape, the world of a Microsoft Active Directory (AD) professional has changed significantly over the last 20-plus years. As in any other area of IT, the drive and curiosity to level up one’s skills to keep pace with evolving technologies…

How to Defend Against Active Directory Attacks That Leave No Trace

How to Defend Against Active Directory Attacks That Leave No Trace

  • Guido Grillenmeier

Cybercriminals are using new tactics and techniques to gain access to Active Directory in novel ways, making their attacks even more dangerous—and more necessary to detect.  One of the most important parts of any cybersecurity strategy is detection. Having an ability to spot the bad guy entering, moving about, or worse—administering—your network is…

Identity Attack Watch: March 2021

Identity Attack Watch: March 2021

  • Semperis Research Team

Cyberattacks targeting Active Directory are on the upswing, putting pressure on AD, identity, and security teams to monitor the constantly shifting AD-focused threat landscape. To help IT pros better understand and guard against attacks involving AD, the Semperis Research Team offers this monthly roundup of recent cyberattacks that used identity…

Do You Know Your Active Directory Security Vulnerabilities?

Do You Know Your Active Directory Security Vulnerabilities?

  • Sean Deuby | Principal Technologist

Microsoft Active Directory security involves dealing with a mixed bag of risks, ranging from management mistakes to unpatched vulnerabilities. We often write about the fact that cyber-attackers are targeting AD to elevate privileges and gain persistence in the organization. Investigate a typical data breach, and you’ll find that stolen credentials…