CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks
CISA and Five Eyes agencies issued joint guidance detailing 17 Active Directory attack techniques like Kerberoasting and DCSync, with hardening and detection advice.
CISA, the NSA, and cyber agencies from Australia, Canada, the UK, and New Zealand released joint guidance on September 15 covering 17 techniques attackers use to compromise Active Directory, including AD CS, Certificate Services, and Federation Services attacks. Named techniques include Kerberoasting, AS-REP roasting, password spraying, DCSync, NTDS.dit dumping, Golden and Silver Tickets, Golden SAML, and Skeleton Key. Recommendations include minimizing SPN accounts, enforcing AES encryption, disabling NTLM, account lockout thresholds of five attempts, phishing-resistant MFA, and Tier 0 prioritization. The guide also lists Windows event IDs 4769, 4768, 4625, 4771, and 2889 for detecting Kerberoasting and password spraying on domain controllers.
- Joint CISA, NSA, and allied agency guidance covers 17 Active Directory compromise techniques.
- Recommends phishing-resistant MFA, Tier 0 prioritization, and a tiered Enterprise Access Model for hybrid environments.
- Suggests lockout thresholds of five attempts and monthly scans for cleartext secrets.
- Lists event IDs 4769, 4768, 4625, 4771, and 2889 plus AD canaries for detection.
Full article540 words · extracted from gbhackers.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has collaborated with international partners to guide the defense of Active Directory (AD). They warn that attackers exploit 17 common techniques to gain control of identity infrastructure.
The guide, released on September 15, was co-authored by the Australian Signals Directorate’s Australian Cyber Security Center, CISA, the NSA, Canada’s Cyber Center, the UK’s NCSC, and New Zealand’s NCSC.
Gaining control of a domain can provide an intruder with privileged access to various systems, including email, file servers, and critical applications. In hybrid environments, this access can extend to cloud services through Microsoft Entra ID integrations.
Hackers Exploit 17 Active Directory Techniques
AD serves as the authentication and authorization backbone, making it a prime target for attackers. The agencies highlighted that permissive defaults, legacy protocols, complex permissions, and unclear relationships between objects create vulnerabilities.
Adversaries can enumerate domain structures, accounts, configurations, and trust relationships, exploiting weaknesses to escalate privileges, move laterally within the network, and establish persistence.
The guidance covers attacks related to Active Directory Domain Services, Certificate Services, and Federation Services. Techniques identified include Kerberoasting, AS-REP roasting, password spraying, MachineAccountQuota abuse, unconstrained delegation, Group Policy Preferences password exposure, AD CS abuse, DCSync, NTDS.dit dumping, Golden and Silver Tickets, Golden SAML, Entra Connect compromise, trust bypasses, SID History abuse, Skeleton Key, and Shadow Credentials.
Several pathways can transform a single credential or configuration weakness into forest-wide control. For instance, Kerberoasting targets service accounts with service principal names by requesting Kerberos service tickets and subsequently attempting offline password cracking.
CISA and its partners recommend minimizing the number of accounts with SPNs, utilizing group Managed Service Accounts where feasible, enforcing AES encryption, and ensuring service accounts are granted only the privileges they need.
To mitigate password spraying risks, the guidance suggests implementing long, unique, and well-managed credentials; setting an account lockout threshold to no more than five failed attempts; conducting monthly scans for cleartext secrets; and disabling NTLM whenever possible.
When organizations cannot remove NTLM, they should deploy LDAP channel binding, extended protection for authentication, and SMB signing.
Defenders should prioritize Tier 0 security, which includes domain controllers, privileged administrator accounts, certificate authorities, federation infrastructure, backup systems, and identity synchronization servers that can control the domain.
The agencies recommend a tiered Enterprise Access Model for hybrid deployments, employing phishing-resistant multi-factor authentication (MFA), privileged access workstations, Kerberos armoring, and enforcing zero-trust policies.
Detection efforts must accompany hardening measures. Security teams should centrally collect and analyze events from domain controllers.
Key event IDs to monitor include 4769 for RC4-encrypted ticket-granting service requests related to Kerberoasting, 4768 for anomalous ticket-granting ticket requests, and 4625, 4771, and 2889 for password-spraying indicators. The guide also advocates for using AD canaries to detect suspicious access attempts.
The core message is one of prevention: recovering from an AD compromise can necessitate broad password resets or even a directory rebuild. Therefore, reducing identity attack pathways early is far less disruptive than addressing issues after a compromise.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/cisa-warns-hackers-exploit-17-active-directory-techniques/