Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

CISA’s Warning on 17 Active Directory Attack Methods Exposes Persistent Enterprise Identity Risks

Дата публикации: 08-10-2026 10:22:13

A new CISA-led advisory details 17 techniques adversaries use to compromise Active Directory, from Kerberoasting to shadow credentials. Sophos data shows attackers reach AD servers in 3.4 hours median. Enterprises must address identity weaknesses now.

Основное содержимое страницы с новостью.

Attackers keep finding their way into corporate networks. They don’t always smash through firewalls or exploit the latest software flaw. Often they simply log in. And once inside, their eyes turn quickly to Active Directory.

That pattern shows no sign of fading. A fresh joint advisory from CISA, the NSA and four international partners lays out exactly how adversaries exploit Microsoft’s directory service. Released in mid-September 2026, the document details 17 techniques observed across real intrusions. It builds on earlier versions with expanded detection advice for DCSync attacks and shadow credentials. The agencies behind it read like a who’s who of Western cyber defense: Australia’s ASD ACSC led development, joined by CISA, NSA, Canada’s CCCS, the UK’s NCSC and New Zealand’s NCSC-NZ. (CISA).

But this isn’t abstract theory. Sophos investigators saw the consequences firsthand. In their 2026 Active Adversary Report, which examined incidents from 2025, identity-related issues drove 67.32 percent of root causes. Compromised credentials alone accounted for over 42 percent. Attackers reached Active Directory servers in a median of just 3.4 hours after initial access. That’s 70 percent faster than the year before. “The dominance of identity-related root causes for successful initial access… Organizations must take a proactive approach to identity security,” said John Shier, Sophos field CISO and lead author of the report. (Sophos).

The techniques cataloged range from credential theft methods that have plagued administrators for years to more advanced persistence tricks that survive reboots and basic cleanup. Start with Kerberoasting. Any domain user can request a service ticket for an account that has a service principal name. Those tickets contain encrypted data derived from the service account’s password. Crack it offline and the attacker walks away with valid credentials. Detection looks for spikes in event ID 4769 tickets issued to accounts that rarely request them. Mitigation demands fewer SPNs, longer complex passwords on service accounts, and a shift to group Managed Service Accounts where feasible.

AS-REP Roasting follows a similar path but targets accounts without Kerberos pre-authentication enabled. The attacker sends an authentication request and receives an encrypted response that can be cracked without ever talking to the target account. Simple configuration change stops most of it: require pre-authentication. Yet thousands of environments still leave this door open.

Password spraying feels almost quaint in 2026. One or two common passwords tried across hundreds of accounts. Low and slow enough to dodge lockouts. Still effective because users pick predictable phrases and MFA coverage remains spotty. Sophos found MFA absent in 59 percent of the cases they reviewed.

Some methods exploit default settings that administrators rarely touch. MachineAccountQuota, set to 10 by default, lets any authenticated user create computer objects in the domain. Those new objects inherit permissions that can be abused for privilege escalation. CISA’s own red team exercises demonstrated this exact path earlier in 2026. In two separate simulated attacks on critical infrastructure organizations, operators used the quota weakness after an initial phishing foothold to escalate privileges and move laterally. One team reached sensitive business systems and cloud resources without triggering meaningful alerts. (CyberPress).

Unconstrained delegation creates another quiet hazard. Compromise a server configured to delegate without restrictions and pull cached Kerberos tickets from its memory. Those tickets might belong to highly privileged users who happened to authenticate to the box. The cached data sits in LSASS, waiting to be harvested.

Older flaws persist too. Group Policy Preferences once stored passwords in SYSVOL using an AES key that Microsoft published years ago. Anyone with domain read access can decrypt them. The practice should have died long ago. Yet remnants still appear in mature environments.

Active Directory Certificate Services offers rich attack surface when templates allow overly permissive enrollment. Attackers request certificates on behalf of other users, sometimes domain admins. The resulting certs authenticate cleanly. Shadow credentials take certificate abuse further by writing to the msDS-KeyCredentialLink attribute on a target object. No template changes required. Detection hinges on auditing writes to that specific attribute.

Then come the crown jewels of persistence. DCSync. An attacker with replication rights mimics a domain controller and pulls password hashes for every account. Event logs show replication requests from non-DC machines. Golden Tickets and Silver Tickets let adversaries forge Kerberos tickets that never touch a key distribution center in the expected way. Silver Tickets prove especially sneaky because they authenticate directly to services without generating the usual domain controller traffic that defenders monitor.

Golden SAML abuses federation trust by stealing the AD FS signing key. One compromise grants access to cloud resources across the enterprise. Microsoft Entra Connect servers, which sync identities between on-premises and Azure AD, become high-value targets. Compromise the sync account and manipulate cloud identities.

SIDHistory abuse, one-way trust bypasses, Skeleton Key malware that patches LSASS in memory. The list goes on. Each technique builds on the last. A single weak service account can lead to domain dominance in hours.

The advisory doesn’t stop at listing problems. It pushes hard for structural change. Microsoft’s Enterprise Access Model receives repeated emphasis. Tier 0 assets, those with the highest privileges, must be isolated. Privileged access workstations, phishing-resistant authentication, strict segmentation between tiers. Canary objects scattered through the directory act as tripwires. Any reconnaissance tool that touches them generates high-fidelity alerts without complex log correlation. SharpHound, popular among red teams and real attackers, lights them up immediately.

Yet many organizations still treat Active Directory as a set-it-and-forget-it system. Default permissions accumulate over years. Service accounts multiply with weak passwords. Logging gets turned down to manage volume. The result is exactly what Sophos measured: faster and faster progression to the keys of the kingdom.

Recent incidents reinforce the message. In one case examined by Kaspersky, PAYLOAD ransomware operators gained domain admin rights then pushed malicious Group Policy Objects at the domain root. No files encrypted on Windows endpoints. Instead the GPOs changed wallpapers, displayed ransom notes, disabled local admin accounts and turned off firewalls across thousands of machines. All through trusted Active Directory mechanisms. (Cybersecurity News).

Another intrusion chain exploited PaperCut print server vulnerabilities to reach a domain controller, harvest credentials and enable Restricted Admin mode for further movement. Zero-days met classic identity abuse. (CyberPress).

Defenders face a tough reality. Patching alone won’t solve this. Nor will another layer of endpoint detection if the directory itself remains porous. The CISA-led guidance stresses monitoring for behavioral anomalies over static signatures. Look for unusual ticket requests, unexpected replication traffic, writes to sensitive attributes.

But monitoring generates noise. And skilled attackers blend with legitimate activity. That explains why red teams in CISA exercises could read SOC email and plant keyloggers on defenders’ machines without raising alarms.

The path forward demands discipline. Reduce the attack surface by eliminating unnecessary SPNs and legacy delegation. Enforce strong password policies on the accounts that matter most. Implement tiered administration and privileged access workstations. Deploy canary objects and tune detection for the specific techniques outlined. Above all, treat Active Directory not as plumbing but as the crown jewels it has become.

Because attackers already do. They reach it in hours. They own it in days. And organizations that treat these 17 techniques as yesterday’s news risk becoming tomorrow’s headline.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally07.6328-09-2026
2CISA warnt vor Angriffen auf Zammad und Citrix NetScaler06.0505-10-2026
3Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected011.829-09-2026
4Angriffe auf Microsoft-SharePoint-Schwachstelle024.0628-09-2026
5Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT07.930-09-2026
6Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager09.9530-09-2026
7Chinese espionage groups swarm to exploit triple-link chain of zero-days014.3209-09-2026
8Citrix discloses third actively exploited NetScaler zero-day in less than a week09.5705-10-2026
9WaterISAC reckons with range of threats after summer of cyberattacks09.1830-09-2026
10不正アクセス被害激増、今、何をすべきか? IPAから緊急の点検要請01009-10-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 16.98. Источник: www.webpronews.com.