Securing Active Directory Administration, by Sean Metcalf
Defending Active Directory with Wire Data, by Vince Stross
Organizations have been forced to adapt to the new reality: Anyone can be targeted and many can be compromised. This has been the catalyst for many to tighten up operations and revamp ancient security practices. They bought boxes that blink and software that floods the SOC with alerts.
Is it enough? The overwhelming answer is: No.
The security controls that matter most are the ones that best protect those with the keys to the enterprise, the Active Directory administrators. With this access, an attacker can do anything they want in the environment: access all sensitive data, change access controls and security settings, embed to persist (for years), and often fully manage and control routers, switches, the virtualization platform (VMWare or Microsoft Hyper-V), and increasingly, the cloud platform.
This presentation explores typical administration methods and how attackers exploit them. Furthermore, this session provides the best methods of secure administration to protect privileged credentials.