The Canadian Centre for Cyber Security (Cyber Centre) has joined the Australian Signals Directorate’s (ASD) Australian Cyber Security Centre (ACSC) and the following international partners in releasing cyber security guidance on mitigating Microsoft Active Directory compromises:
- Cybersecurity and Infrastructure Security Agency (CISA)
- National Security Agency (NSA)
- New Zealand's National Cyber Security Centre (NCSC-NZ)
- United Kingdom’s National Cyber Security Centre (NCSC-UK)
Microsoft’s Active Directory is an authentication and authorization solution widely used in enterprise information technology networks globally. It’s a valuable target for threat actors, and if compromised, threat actors can gain privileged access to all of the systems and users that Active Directory manages. Responding to Active Directory attacks can be time consuming, costly and disruptive.
This guidance provides strategies to prevent, detect and mitigate prevalent Active Directory compromises including:
- Kerberoasting
- AS-REP roasting
- Password spray
- MachineAccountQuota
- Unconstrained delegation
- Password in group policy reference
- Active Directory certificate services
- Golden certificate
- DCSync
- Dumping ntds.dit
- Golden ticket
- Silver ticket
- Golden SAML
- Microsoft Entra Connect
- One-way domain trust bypass
- SID history
- Skeleton key
- Shadow Credentials
Organizations can implement this guidance to help secure their enterprise directory services.
Consult the full joint guidance on Detecting and mitigating Active Directory attacks.