ZeroHour

Search: “credential dumping”

3 stories in the last 7d

CISA Urges Organizations to Deploy Cyber Decoys to Detect Hackers Inside Networks

CISA's new guidance urges organizations to deploy cyber decoys like honeytokens and tripwires to detect attackers using valid credentials and living-off-the-land techniques.

CISA published 'Using Cyber Decoys to Strengthen Detection and Response' on September 16, 2026, advising decoy assets that appear legitimate but generate high-confidence alerts when accessed. It describes tripwires, breadcrumbs, and honeytokens such as fake usernames, passwords, API keys, and cloud access tokens, and recommends starting with low-complexity deployments like nonfunctional Active Directory accounts, decoy file shares, and isolated mimic hosts. The agency warns decoys must be segmented and nonfunctional to prevent attackers pivoting to real systems, and aligns decoy planning with MITRE Engage and ATT&CK.

GBHackers · 59m agoAdvisory

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory

CISA and five international agencies publish joint guidance detailing 17 techniques attackers use to compromise Microsoft Active Directory environments.

CISA, NSA, and the Australian Signals Directorate's ACSC, with contributions from Canadian, UK, and New Zealand cyber centers, released technical guidance on 17 Active Directory attack techniques. It covers AD Domain Services, AD Certificate Services, and AD Federation Services, including Kerberoasting, DCSync, Golden Ticket, Golden SAML, Skeleton Key, and Shadow Credentials. The guidance recommends treating domain controllers, CAs, AD FS servers, and Entra Connect systems as Tier 0 assets with phishing-resistant MFA, Kerberos pre-authentication enforcement, and disabling NTLM/SMBv1.

Cyber Security News · 1d agoAdvisory

CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks

CISA and Five Eyes agencies issued joint guidance detailing 17 Active Directory attack techniques like Kerberoasting and DCSync, with hardening and detection advice.

CISA, the NSA, and cyber agencies from Australia, Canada, the UK, and New Zealand released joint guidance on September 15 covering 17 techniques attackers use to compromise Active Directory, including AD CS, Certificate Services, and Federation Services attacks. Named techniques include Kerberoasting, AS-REP roasting, password spraying, DCSync, NTDS.dit dumping, Golden and Silver Tickets, Golden SAML, and Skeleton Key. Recommendations include minimizing SPN accounts, enforcing AES encryption, disabling NTLM, account lockout thresholds of five attempts, phishing-resistant MFA, and Tier 0 prioritization. The guide also lists Windows event IDs 4769, 4768, 4625, 4771, and 2889 for detecting Kerberoasting and password spraying on domain controllers.

GBHackers · 1d agoAdvisory