Guardians of the Directory

Active Directory's Dark Side: Underbelly Threats and Shadowy Permissions


Listen Later

In this episode of Guardians of the Directory, Craig Birch and Derek Melber delve into the complexities of Active Directory security, focusing on the stealthy threats posed by shadow permissions, DC Shadow, and DC Sync. They discuss the historical context of these vulnerabilities, the role of applications in creating shadow permissions, and the importance of cleaning up orphaned SIDs. The conversation also covers best practices for managing service accounts and highlights critical areas within Active Directory that administrators should monitor. The episode concludes with actionable recommendations for improving security posture.
Key Takeaways

  • Active Directory is a critical component of identity infrastructure.
  • Shadow permissions can be exploited by attackers without detection.
  • Many organizations lack visibility into their Active Directory permissions.
  • Cleaning up orphaned SIDs is essential for security.
  • Service accounts should have strong passwords and limited privileges.
  • Regular audits of Active Directory are necessary to identify risks.
  • Applications can inadvertently create shadow permissions.
  • Understanding the baseline permissions is crucial for security.
  • PowerShell can be a powerful tool for managing Active Directory.
  • Start with small changes to improve security posture.
  • ...more
    View all episodesView all episodes
    Download on the App Store

    Guardians of the DirectoryBy Guardian of the Directory