Главная
Study mode:
on
1
Introduction
2
About Nikhil Mittal
3
Agenda
4
What is MDI
5
MDI Discussion
6
TTP Discussion
7
Triggers
8
Alert
9
Kerberos
10
Lateral Movement
11
Domain Dominance
12
DC Sync
13
Remote Code Execution
14
Domain Controllers
15
Golden Ticket
16
Response Actions
Description:
Explore techniques for bypassing Microsoft Defender for Identity (MDI) in this 55-minute conference talk from BruCON 0x0E. Dive into the workings of MDI, a service protecting on-premises Active Directory identities, and learn about its detection capabilities across various attack phases. Discover Tactics, Techniques, and Procedures (TTPs) that Red Teams can employ to avoid triggering anomaly detections while executing high-impact attacks. Cover topics such as Kerberoasting, lateral movement, domain dominance, DCSync, remote code execution, and Golden Ticket attacks. Gain insights into precision-based attack methods that can potentially circumvent MDI sensors in target environments, ultimately enhancing your understanding of on-premises identity security and potential vulnerabilities.

Bypassing Microsoft Defender for Identity

BruCON Security Conference
Add to list
0:00 / 0:00