homepage
Open menu
Go one level top
  • Train and Certify
    Train and Certify

    Immediately apply the skills and techniques learned in SANS courses, ranges, and summits

    • Overview
    • Courses
      • Overview
      • Full Course List
      • By Focus Areas
        • Cloud Security
        • Cyber Defense
        • Cybersecurity and IT Essentials
        • DFIR
        • Industrial Control Systems
        • Offensive Operations
        • Management, Legal, and Audit
      • By Skill Levels
        • New to Cyber
        • Essentials
        • Advanced
        • Expert
      • Training Formats
        • OnDemand
        • In-Person
        • Live Online
      • Course Demos
    • Training Roadmaps
      • Skills Roadmap
      • Focus Area Job Roles
        • Cyber Defense Job Roles
        • Offensive Operations Job Roles
        • DFIR Job Roles
        • Cloud Job Roles
        • ICS Job Roles
        • Leadership Job Roles
      • NICE Framework
        • Security Provisionals
        • Operate and Maintain
        • Oversee and Govern
        • Protect and Defend
        • Analyze
        • Collect and Operate
        • Investigate
        • Industrial Control Systems
      • European Skills Framework
    • GIAC Certifications
    • Training Events & Summits
      • Events Overview
      • Event Locations
        • Asia
        • Australia & New Zealand
        • Latin America
        • Mainland Europe
        • Middle East & Africa
        • Scandinavia
        • United Kingdom & Ireland
        • United States & Canada
      • Summits
    • OnDemand
    • Get Started in Cyber
      • Overview
      • Degree and Certificate Programs
      • Scholarships
      • Cyber Aces
    • Cyber Ranges
  • Manage Your Team
    Manage Your Team

    Build a world-class cyber team with our workforce development programs

    • Overview
    • Why Work with SANS
    • Group Purchasing
    • Build Your Team
      • Team Development
      • Assessments
      • Private Training
      • Hire Cyber Professionals
      • By Industry
        • Health Care
        • Industrial Control Systems Security
        • Military
    • Leadership Training
  • Security Awareness
    Security Awareness

    Increase your staff’s cyber awareness, help them change their behaviors, and reduce your organizational risk

    • Overview
    • Products & Services
      • Security Awareness Training
        • EndUser Training
        • Phishing Platform
      • Specialized
        • Developer Training
        • ICS Engineer Training
        • NERC CIP Training
        • IT Administrator
      • Risk Assessments
        • Knowledge Assessment
        • Culture Assessment
        • Behavioral Risk Assessment
    • OUCH! Newsletter
    • Career Development
      • Overview
      • Training & Courses
      • Professional Credential
    • Blog
    • Partners
    • Reports & Case Studies
  • Resources
    Resources

    Enhance your skills with access to thousands of free resources, 150+ instructor-developed tools, and the latest cybersecurity news and analysis

    • Overview
    • Webcasts
    • Free Cybersecurity Events
      • Free Events Overview
      • Summits
      • Solutions Forums
      • Community Nights
    • Content
      • Newsletters
        • NewsBites
        • @RISK
        • OUCH! Newsletter
      • Blog
      • Podcasts
      • Summit Presentations
      • Posters & Cheat Sheets
    • Research
      • White Papers
      • Security Policies
    • Tools
    • Focus Areas
      • Cyber Defense
      • Cloud Security
      • Digital Forensics & Incident Response
      • Industrial Control Systems
      • Cyber Security Leadership
      • Offensive Operations
  • Get Involved
    Get Involved

    Help keep the cyber community one step ahead of threats. Join the SANS community or begin your journey of becoming a SANS Certified Instructor today.

    • Overview
    • Join the Community
    • Work Study
    • Teach for SANS
    • CISO Network
    • Partnerships
    • Sponsorship Opportunities
  • About
    About

    Learn more about how SANS empowers and educates current and future cybersecurity practitioners with knowledge and skills

    • SANS
      • Overview
      • Our Founder
      • Awards
    • Instructors
      • Our Instructors
      • Full Instructor List
    • Mission
      • Our Mission
      • Diversity
      • Scholarships
    • Contact
      • Contact Customer Service
      • Contact Sales
      • Press & Media Enquiries
    • Frequent Asked Questions
    • Customer Reviews
    • Press
    • Careers
  • Contact Sales
  • SANS Sites
    • GIAC Security Certifications
    • Internet Storm Center
    • SANS Technology Institute
    • Security Awareness Training
  • Search
  • Log In
  • Join
    • Account Dashboard
    • Log Out
  1. Home >
  2. Blog >
  3. Protect Privileged AD Accounts With Five Free Controls
370x370_Erik-Van-Buggenhout.jpg
Erik Van Buggenhout

Protect Privileged AD Accounts With Five Free Controls

September 10, 2018

five_free_controls

Once an adversary has obtained an initial entry point into your environment, they typically pivot around in the AD, looking to escalate their privileges further and eventually gain access to your crown jewels.

One of the most common attack flows looks something like this:

An adversary compromises a low-privileged user (through a phishing mail with a malicious attachment, for example), to get an initial foot in the door of your network.

If the user isn't already assigned administrative rights, the adversary exploits a local privilege escalation issue to get them. To pivot further in the network, the adversary attempts to steal the credentials of administrative domain accounts, knowing they'll provide access to additional domain resources.

Once they have administrative domain account credentials, the adversary can dump them from memory and further compromise the environment (example: a typical Mimikatz attack). Tools like Bloodhound will map out where administrators are connected, often giving adversaries exactly the information they need.

If BloodHound doesn't provide the "path to domain admin," another common trick involves disabling or breaking something small on a compromised machine to lure help-desk or IT staff to a machine controlled by the adversary.

With Domain Administrator access, the adversary can attempt to persist his administrative access to the domain (by generating a Golden Ticket, for example).

What kind of controls can we implement to prevent these attacks from succeeding?

  1. Use separate accounts for all administrative purposes.
  2. Design your environment using Privileged Access Workstations.
  3. Use domain protected users.
  4. Deploy CredentialGuard on Windows 10 and protected processes on Windows 8.
  5. Deploy Local Administrator Password Solution (LAPS).

1. Use separate accounts for all administrative purposes

  • Use accounts with the minimum privileges necessary to do specific jobs.
  • Create fine-grained administrative accounts, such as database server, web server, and workstation administrators.
  • Educate your staff on how administrative privileges should be used.
  • Don't give helpdesk users Domain Administrator accounts so they can fix small issues on an employee's workstation?never give access that isn't absolutely needed.
  • Finally, have administrators create a separate account for administrative use and a normal account for day-to-day use. (This is highly recommended.)

Controls such as UAC (User Account Control) aim to limit when the administrative token (for example, administrative privileges) can be used, but how could those controls be bypassed?

An excellent overview of current UAC bypass methods is listed on Github.

2. Design your environment using Privileged Access Workstations

This practice, recommended by Microsoft, mainly applies to highly privileged accounts that administer the AD management of the active directory (and use of highly privileged accounts). The process should only be performed from a dedicated system that can be seen as an administrative "jump box." (Never allow direct administrative access to the Domain Controllers from normal "internal network zones.")

Microsoft labels these "jump boxes" as "Privileged Access Workstations." Make sure to subject these systems to additional security hardening, such as the full implementation of Credential Guard, and dedicate them exclusively to administrative functionality?don't use them to run software such as email applications, web browsers, or productivity software like Microsoft Office.

In Best Practices for Securing Active Directory, Microsoft describes three core principles for these administrative hosts:

  • Never administer a trusted system (that is, a secure server such as a domain controller) from a less-trusted host (a workstation that isn't secured to the same degree as the systems it manages, for example).
  • Don't rely on a single authentication factor when performing privileged activities. User name and password combinations aren't acceptable authentication, because only a single factor (something you know) is represented. Consider where credentials are generated and cached or stored in administrative scenarios.
  • Although most attacks in the current threat landscape leverage malware and malicious hacking, don't omit physical security when designing and implementing secure administrative hosts.

For more on this, see:

Implementing Secure Administrative Hosts

Privileged Access Workstations

3. Use domain protected users

Domain protected users are defined at the AD level, and enforce a number of security controls to protect sensitive credentials for a user or group. They can be configured as of Windows 8.1/Windows Server 2012 R2. They enforce:

Credential delegation (CredSSP) and Windows Digest (Wdigest — as of Windows 8.1 and Windows Server 2012 R2) will not cache the user's plain text credentials.

Kerberos will no longer create DES or RC4 keys. It will also not cache the user's plain text credentials or long-term keys after the initial TGT (Ticket Granting Ticket) is acquired. This control is mainly aimed at Kerberoasting attacks.

Credentials are never locally cached to allow offline authentication.

When the domain is a Windows Server 2012 R2 domain, the user cannot authenticate with NTLM authentication?only Kerberos.

4. Deploy CredentialGuard on Windows 10 and protected processes on Windows 8

With Windows Server 2012 (and Windows 8), the LSA can be configured to have its lsass.exe process hosted as a protected process. With the correct privileges, accounts can access the memory of any Windows process?but not with protected processes.

Protected processes and their memory cannot be accessed by other processes, regardless of the account. Protected processes were introduced with Windows Vista for DRM purposes (to make media players), but repurposed for security boundaries when Windows 8 was introduced.

If you run the lsass.exe process as a protected process, tools like Mimikatz cannot access the process to extract credentials. However, protected processes are implemented in the Kernel software and can be defeated. Mimikatz includes a function to remove protection by requiring its kernel driver to be installed.

You can, however, detect and respond to installation of this kernel driver.

registry_Editor

Credential Guard was introduced with the enterprise editions of Windows Server 2016 and Windows 10. It requires modern CPUs that provide virtualization functionality.

When Credential Guard is enabled, Windows still runs on top of the hypervisor and the hardware, and the LSA process still runs in userland. The difference is that the credentials are now stored in the Isolated LSA process (LsaIsol.exe), which does not run under Windows, but in the Virtual Secure Mode. This is a separate, virtualized environment separated from the other environments (like Windows) via hardware.

It's impossible for processes in the Windows environment to access processes in the Virtual Secure Mode environment, even by manipulating kernel data structures. All operations requiring credentials, like checking NTML hashes, do so by the Isolated LSA?upon request of the LSA. The credentials never leave the Isolated LSA.

LSA

5. Deploy Local Administrator Password Solution (LAPS)

In some cases, environments have the same local administrator password configured for all systems (for "recovery" reasons). From a security perspective, this is a horrible idea?if an adversary gets access one local admin credential, he can reuse it across the entire enterprise.

Local Administrator Password Solution (LAPS) is a free Microsoft utility that helps manage local administrator accounts securely. It generates a secure random password for the default local administrator account (500) and stores it in the AD.

LAPS can configure a maximum of two local administrator accounts per system; the randomized local administrator passwords are protected using ACLs in the AD. (The passwords are stored in clear text in the Active Directory, though, so be sure the ACLs are thoroughly reviewed to ensure they're properly configured.)

LAPS is supported on the majority of Windows systems, as of Windows 7 (both x86 and x64 systems). To read more about LAPS, check out this article on Technet.

SANS instructor Jason Fossen, whose work is highly focused on Windows security, also provides an interesting alternative to LAPS here.

How can I learn more about how to defend my environment against adversaries?

Take SEC599: Defeating Advanced Adversaries - Purple Team Tactics & Kill Chain Defenses. In this course, Purple Team Tactics & Kill Chain Defenses will arm you with the knowledge and expertise you need to detect and respond to today's threats. Recognizing that a prevent-only strategy is not sufficient, course authors Erik Van Buggenhout & Stephen Sims, both certified GIAC Security Experts, will introduce security controls designed to stop advanced adversaries. With more than 20 labs, plus a full-day "Defend-the-Flag" exercise, SEC599 presents students with real world examples to face modern attacks head-on.

Share:
TwitterLinkedInFacebook
Copy url Url was copied to clipboard
Subscribe to SANS Newsletters
Receive curated news, vulnerabilities, & security awareness tips
United States
Canada
United Kingdom
Spain
Belgium
Denmark
Norway
Netherlands
Australia
India
Japan
Singapore
Afghanistan
Aland Islands
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antarctica
Antigua and Barbuda
Argentina
Armenia
Aruba
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belize
Benin
Bermuda
Bhutan
Bolivia
Bonaire, Sint Eustatius, and Saba
Bosnia And Herzegovina
Botswana
Bouvet Island
Brazil
British Indian Ocean Territory
Brunei Darussalam
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Cook Islands
Costa Rica
Croatia (Local Name: Hrvatska)
Curacao
Cyprus
Czech Republic
Democratic Republic of the Congo
Djibouti
Dominica
Dominican Republic
East Timor
East Timor
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Ethiopia
Falkland Islands (Malvinas)
Faroe Islands
Fiji
Finland
France
French Guiana
French Polynesia
French Southern Territories
Gabon
Gambia
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard And McDonald Islands
Honduras
Hong Kong
Hungary
Iceland
Indonesia
Iraq
Ireland
Isle of Man
Israel
Italy
Jamaica
Jersey
Jordan
Kazakhstan
Kenya
Kiribati
Korea, Republic Of
Kosovo
Kuwait
Kyrgyzstan
Lao People's Democratic Republic
Latvia
Lebanon
Lesotho
Liberia
Liechtenstein
Lithuania
Luxembourg
Macau
Macedonia
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia, Federated States Of
Moldova, Republic Of
Monaco
Mongolia
Montenegro
Montserrat
Morocco
Mozambique
Myanmar
Namibia
Nauru
Nepal
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
Northern Mariana Islands
Oman
Pakistan
Palau
Palestine
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn
Poland
Portugal
Puerto Rico
Qatar
Reunion
Romania
Russian Federation
Rwanda
Saint Bartholemy
Saint Kitts And Nevis
Saint Lucia
Saint Martin
Saint Vincent And The Grenadines
Samoa
San Marino
Sao Tome And Principe
Saudi Arabia
Senegal
Serbia
Seychelles
Sierra Leone
Sint Maarten
Slovakia
Slovenia
Solomon Islands
South Africa
South Georgia and the South Sandwich Islands
South Sudan
Sri Lanka
St. Helena
St. Pierre And Miquelon
Suriname
Svalbard And Jan Mayen Islands
Swaziland
Sweden
Switzerland
Taiwan
Tajikistan
Tanzania
Thailand
Togo
Tokelau
Tonga
Trinidad And Tobago
Tunisia
Turkey
Turkmenistan
Turks And Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United States Minor Outlying Islands
Uruguay
Uzbekistan
Vanuatu
Vatican City
Venezuela
Vietnam
Virgin Islands (British)
Virgin Islands (U.S.)
Wallis And Futuna Islands
Western Sahara
Yemen
Yugoslavia
Zambia
Zimbabwe

By providing this information, you agree to the processing of your personal data by SANS as described in our Privacy Policy.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Tags:
  • Cybersecurity and IT Essentials
  • Purple Team

Related Content

Blog
Purple Team
May 24, 2022
Purple Teaming and Threat-Informed Detection Engineering
In the first two webcasts of this Purple Team series, we covered how to run your first Purple Team Exercise and how to Operationalize your Purple Team. You may have noticed that a common process in Purple Teaming is detection engineering. In this blog, we go into the items discussed in our third...
370x370_Jorge-Orchilles.jpg
Jorge Orchilles
read more
Blog
Purple Team
April 11, 2022
Building an Internal Red Team? Go Purple First
If you are asked to build an internal red team program today, start with a Purple Team Exercise to foster collaboration across stakeholders early on.
370x370_Jorge-Orchilles.jpg
Jorge Orchilles
read more
Blog
Purple Team, Red Team Operations, Digital Forensics and Incident Response
March 24, 2022
Cyber Kill Chain, MITRE ATT&CK, and Purple Team
Understanding how attacks work is critical for defense. It's a common theme in SANS Purple Team courses: offense informs defense and defense informs.
370x370_Jorge-Orchilles.jpg
Jorge Orchilles
read more
  • Register to Learn
  • Courses
  • Certifications
  • Degree Programs
  • Cyber Ranges
  • Job Tools
  • Security Policy Project
  • Posters & Cheat Sheets
  • White Papers
  • Focus Areas
  • Cyber Defense
  • Cloud Security
  • Cybersecurity Leadership
  • Digital Forensics
  • Industrial Control Systems
  • Offensive Operations
Subscribe to SANS Newsletters
Receive curated news, vulnerabilities, & security awareness tips
United States
Canada
United Kingdom
Spain
Belgium
Denmark
Norway
Netherlands
Australia
India
Japan
Singapore
Afghanistan
Aland Islands
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antarctica
Antigua and Barbuda
Argentina
Armenia
Aruba
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belize
Benin
Bermuda
Bhutan
Bolivia
Bonaire, Sint Eustatius, and Saba
Bosnia And Herzegovina
Botswana
Bouvet Island
Brazil
British Indian Ocean Territory
Brunei Darussalam
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Cook Islands
Costa Rica
Croatia (Local Name: Hrvatska)
Curacao
Cyprus
Czech Republic
Democratic Republic of the Congo
Djibouti
Dominica
Dominican Republic
East Timor
East Timor
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Ethiopia
Falkland Islands (Malvinas)
Faroe Islands
Fiji
Finland
France
French Guiana
French Polynesia
French Southern Territories
Gabon
Gambia
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard And McDonald Islands
Honduras
Hong Kong
Hungary
Iceland
Indonesia
Iraq
Ireland
Isle of Man
Israel
Italy
Jamaica
Jersey
Jordan
Kazakhstan
Kenya
Kiribati
Korea, Republic Of
Kosovo
Kuwait
Kyrgyzstan
Lao People's Democratic Republic
Latvia
Lebanon
Lesotho
Liberia
Liechtenstein
Lithuania
Luxembourg
Macau
Macedonia
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia, Federated States Of
Moldova, Republic Of
Monaco
Mongolia
Montenegro
Montserrat
Morocco
Mozambique
Myanmar
Namibia
Nauru
Nepal
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
Northern Mariana Islands
Oman
Pakistan
Palau
Palestine
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn
Poland
Portugal
Puerto Rico
Qatar
Reunion
Romania
Russian Federation
Rwanda
Saint Bartholemy
Saint Kitts And Nevis
Saint Lucia
Saint Martin
Saint Vincent And The Grenadines
Samoa
San Marino
Sao Tome And Principe
Saudi Arabia
Senegal
Serbia
Seychelles
Sierra Leone
Sint Maarten
Slovakia
Slovenia
Solomon Islands
South Africa
South Georgia and the South Sandwich Islands
South Sudan
Sri Lanka
St. Helena
St. Pierre And Miquelon
Suriname
Svalbard And Jan Mayen Islands
Swaziland
Sweden
Switzerland
Taiwan
Tajikistan
Tanzania
Thailand
Togo
Tokelau
Tonga
Trinidad And Tobago
Tunisia
Turkey
Turkmenistan
Turks And Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United States Minor Outlying Islands
Uruguay
Uzbekistan
Vanuatu
Vatican City
Venezuela
Vietnam
Virgin Islands (British)
Virgin Islands (U.S.)
Wallis And Futuna Islands
Western Sahara
Yemen
Yugoslavia
Zambia
Zimbabwe

By providing this information, you agree to the processing of your personal data by SANS as described in our Privacy Policy.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
  • © 2023 SANS™ Institute
  • Privacy Policy
  • Contact
  • Careers
  • Twitter
  • Facebook
  • Youtube
  • LinkedIn