Microsoftは、様々なシングルサインオン(SSO)のシステムをユーザーに提供しています。しかし、SSO のために利用されるクレデンシャル情報は、長い間攻撃者に狙われてきました。Pass the HashやPass the Ticket、Pass the Tokenなどの攻撃により、攻撃者はオンプレミス環境のみならずクラウド環境へまでも、ネットワークアクセスができるようになることがあります。これらの攻撃の詳細や、関連するリスクを軽減するための最新のコントロールについて紹介します。
Meet the speaker
Steve Anson
Co-Founder at Informed Defense
Steve Anson is a SANS Principal Instructor, FOR508 co-author and DFIR expert with over 25 years of experience, including complex DCIS and FBI cybercrime investigations, training teams in over 60 countries, and writing widely used IR/forensics books.