The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with five global cybersecurity organizations, has unveiled a comprehensive guide detailing 17 tactics used by hackers to infiltrate Microsoft Active Directory environments. This technical document provides insights into how cyber attackers exploit identity configurations, outdated protocols, and privileged systems to gain unauthorized access and establish a foothold in enterprise networks.
Global Collaboration for Enhanced Cybersecurity
Developed by the Australian Signals Directorate’s Cyber Security Center, with contributions from the US National Security Agency, Canadian Center for Cyber Security, the UK’s National Cyber Security Center, and New Zealand’s National Cyber Security Center, this guidance is a collective effort to safeguard critical digital infrastructure. The document addresses vulnerabilities in Active Directory Domain Services, Certificate Services, and Federation Services, offering a strategic overview of potential attack vectors.
Why Active Directory is a Prime Target
Active Directory remains a favored target for hackers due to its central role in managing authentication and authorization across numerous enterprise systems. A breach in Active Directory can grant attackers access to user accounts, servers, email systems, and even cloud-based services. The guidance emphasizes the inherent risks posed by permissive defaults and complex user-system relationships, highlighting the challenges defenders face in managing this vast attack surface.
Key Techniques Hackers Use
The document outlines several advanced techniques employed by cybercriminals. For instance, ‘Kerberoasting’ involves requesting Kerberos service tickets to extract service account passwords, while ‘AS-REP Roasting’ targets accounts without Kerberos pre-authentication. Other methods include ‘Password Spraying’, ‘MachineAccountQuota Compromise’, and leveraging ‘Unconstrained Delegation’ vulnerabilities to escalate privileges and move laterally within networks.
Further tactics such as ‘Golden Ticket’ and ‘Silver Ticket’ attacks allow hackers to forge access credentials, while ‘Golden SAML’ involves stealing token-signing certificates to impersonate users and access federated services like Microsoft 365. These sophisticated strategies underscore the importance of robust security measures to protect sensitive systems.
Proactive Measures and Recommendations
The agencies recommend treating domain controllers and related systems as high-value assets, necessitating stringent security protocols. They advise implementing phishing-resistant multifactor authentication, using secure administrative workstations, and minimizing delegated permissions. Additionally, organizations should enforce Kerberos pre-authentication, disable outdated protocols, and protect critical processes such as LSASS.
Regularly reviewing security settings, such as the MS-DS-MachineAccountQuota, SID History, and certificate templates, is crucial. Monitoring specific events like unusual Kerberos activity or unexpected computer-account creation can help detect potential breaches. Establishing baseline authentication behaviors is essential to identify deviations that may signal unauthorized activities.
This comprehensive guidance serves as a critical resource for organizations looking to fortify their defenses against sophisticated cyber threats targeting Active Directory systems.
