ACSC updates guidance on detecting and mitigating AD compromises
The Australian Cyber Security Centre (ACSC) has released updated guidance on detecting and mitigating Microsoft Active Directory compromises.
Because Microsoft Active Directory is a core identity and access management system that controls access to critical systems and data, it is a prime target for malicious cyber threats. It acts as an organisation's digital gatekeeper, verifying users, managing permissions, and enabling single sign-on.
Because Active Directory controls access to so many systems, it is a highly attractive target for malicious actors. If malicious actors take control of Active Directory, they can effectively gain complete control over an organisation’s enterprise IT network. In many cases, they can use the permissions already granted to standard users to investigate the environment, discover weaknesses, and gradually increase their access.
Alongside international partners, the ACSC has released updated guidance titled Detecting and mitigating Active Directory compromises, to help organisations improve their network defences against these threats. The updated guidance provides mitigation and detection advice for 18 common Active Directory compromise techniques including a new novel DCSync detection technique, and a new section covering shadow credentials.
The guidance provides an overview of each technique and how it can be leveraged by malicious actors, as well as recommended actions to mitigate against these techniques. By implementing the recommendations in the guidance, ACSC says organisations can significantly improve their Active Directory security, and strengthen their overall network security against cyber threats.
Read more about detecting and mitigating Active Directory compromises here.
Splunk advancements help deliver trusted AI on premises
Splunk AI features are now available on-premises with the release of Cisco AI POD...
Citadel Edge and Cyber Automation announce strategic partnership
Two Australian cybersecurity companies have announced a partnership that they say is to help...
US DoJ and FBI seize Chinese hacking platforms
Seizures of domains used by China state-sponsored hackers are reported to have disrupted attacks...
