18.05.2021 Views

Cyber Defense Magazine Special Annual Edition for RSA Conference 2021

Cyber Defense Magazine Special Annual Edition for RSA Conference 2021 - the INFOSEC community's largest, most popular cybersecurity event in the world. Hosted every year in beautiful and sunny San Francisco, California, USA. This year, post COVID-19, virtually with #RESILIENCE! In addition, we're in our 9th year of the prestigious Global InfoSec Awards. This is a must read source for all things infosec.

Cyber Defense Magazine Special Annual Edition for RSA Conference 2021 - the INFOSEC community's largest, most popular cybersecurity event in the world. Hosted every year in beautiful and sunny San Francisco, California, USA. This year, post COVID-19, virtually with #RESILIENCE! In addition, we're in our 9th year of the prestigious Global InfoSec Awards. This is a must read source for all things infosec.

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

What You Need to Know About Protecting Active<br />

Directory, the Attack Vector of Choice in <strong>2021</strong><br />

Advanced threats are moving fast and have their eyes set on Active Directory<br />

By Carolyn Crandall, Chief Security Advocate, Attivo Networks<br />

Regardless of whether a cyberteacher’s initial compromise originates from phishing or by exploiting<br />

vulnerabilities, they all have one common waypoint in mind, the company’s Active<br />

Directory (AD). It’s a treasure trove of data, and it stores the critical in<strong>for</strong>mation needed to<br />

elevate an adversary’s privileges and advance their attacks. Un<strong>for</strong>tunately, AD is complex and typically<br />

has legacy policies, overprovisioning, and entitlement creep, issues stemming from disjointed growth,<br />

turnover, and M&A. This all makes monitoring <strong>for</strong> bad amongst good activity very hard to detect. Sadly,<br />

the loss or misuse of domain control can be devastating, as seen in the recent SolarWinds, Microsoft,<br />

FireEye, and other high-profile ransomware attacks. These incidents should serve as a megaphone <strong>for</strong><br />

every CISO and CIO that protecting Active Directory must be a top priority.<br />

Protecting Active Directory is multifaceted and isn’t about doing only one thing well. It<br />

requires mitigating risks, hardening AD systems, and efficiently detecting live attacks. Because AD is<br />

also commonly managed across IT and security teams, this can add to its management complexity.<br />

Some of the top things that organizations can do to improve their AD security posture include<br />

implementing least privileges and tiered admin accounts with limited extra privileges. They<br />

can also collect audit logs and sending them to SIEMs or UBA systems to reactively find threats.<br />

90

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!