Stephan Berger Profile picture
Head of Investigations @InfoGuardAG

Mar 7, 2023, 7 tweets

1/ Number #2 of the #ActiveDirectory hardening measures:

Service Accounts

🧵 #CyberSecurity

2/ In our AD assessments or IR cases, we repeatedly see that service accounts are highly privileged, often also part of the domain administrators group.

This can be disastrous, especially with a weak password for the service account:

3/ @Synacktiv took a closer look at the detection capabilities of Defender for Identity, including whether and how Kerberoasting could be detected. [1]

4/ Interestingly, the researchers found that a time-delay between the LDAP query to find accounts with an SPN and the request for the service ticket is enough to bypass the detection.

Whether this detection has been adjusted or revised in the meantime, I can't say.

"DFI includes logic to detect Kerberoasting activity in your environment. By taking signals from your domain controllers, Defender for Identity can help detect users enumerating your domain looking for Kerberoast-able accounts or attempts to actively exploit those accounts." [2]

6/ A recommendation for already relatively well-secured networks is to implement Honey-SPNs.

These service accounts are never used, and an alert should be generated if a service ticket is requested for his honey-account.

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling