Главная
Study mode:
on
1
Introduction
2
Agenda
3
Background
4
Request a Certificate
5
Certificate Template
6
Client Authentication
7
Subject Alternative Name
8
Authentication to Active Directory
9
malicious certificate enrollments
10
Certify
11
Defenses
12
Escalation scenarios
13
Certificate templates
14
NTLM relay
15
How to protect
16
How to audit
17
Audit the NT auth certificates object
18
Golden certificates
19
Hunting techniques
20
Highlevel architecture guidance
21
Incident response
Description:
Explore the security implications of Microsoft's Active Directory Certificate Services (AD CS) in this Black Hat conference talk. Delve into the often-overlooked aspects of AD CS, including its potential for credential theft, machine persistence, domain escalation, and subtle domain persistence. Learn about certificate request processes, client authentication methods, and malicious certificate enrollments. Discover escalation scenarios, NTLM relay attacks, and golden certificate techniques. Gain insights into defensive strategies, including how to protect and audit AD CS implementations. Understand high-level architecture guidance and incident response procedures for AD CS-related security issues. Equip yourself with hunting techniques to identify and mitigate potential threats in your AD CS environment.

Recertifying Active Directory Certificate Services

Black Hat
Add to list
0:00 / 0:00