Today Active Directory Security is mission-critical to organizational security worldwide and thus mission-critical to Cyber Security worldwide. On this blog, former Microsoft Program Manager for Active Directory Security, and today, CEO of Paramount Defenses, shares valuable technical insights on Active Directory Security.


Friday, September 4, 2026

FYI

Folks,

Hi. I hope you're well. Albeit I don't blog here anymore (given my immense time constraints,) this blog is still one of my most visited blogs, so I thought I'd share something I've been working on, concerning the subject, these past few weeks. 

It's ready, and will be unveiled on Sep 08, 2026, 1300 GMT at www.activedirectorysecurity.com.

Thx,
Sanjay.

PS: I suppose I can say that for the "realization" that led me to commissioning this project, I'm thankful to the following intelligence agencies - the National Security Agency (NSA), the National Cyber Security Center (a part of GCHQ, United Kingdom), the Australian Signals Directorate (ASD), Communications Security Establishment (Canada) and Cyber Security and Infrastructure Security Agency (CISA), USA. [For context on what I mean by this, you may want to read this (post 09/08)]

Tuesday, May 25, 2021

New Coordinates

 Folks,

I hope this finds you all doing well. As some of you may now, over the years, I have shared numerous perspectives on foundational cyber security and on Active Directory security, both here (i.e. on this blog) and at my first blog.

Unfortunately, given my immense responsibilities today, and the sheer paucity of time, I will no longer be able to share my perspectives on multiple blogs, so from now on, I will mostly be sharing my perspectives at the Paramount Defenses Blog.

I recently penned two relevant posts, including What's common between the Colonial Pipeline Hack and the SolarWinds Breach and one on what actually was At the Heart of the SolarWinds Breach i.e. none other than Privileged Access in Active Directory.

The URL for my new coordinates is - https://blog.paramountdefenses.com

Thanks,
Sanjay

Tuesday, April 28, 2020

Coming Soon - "Active Directory Security Beyond the MCT"

Folks,

From the U.S. Dept. of Defense to Microsoft, over 85% of organizations worldwide operate on Microsoft Active Directory.


The security of foundational Active Directory deployments worldwide is thus paramount to cyber security worldwide, and yet, unfortunately, the Active Directory deployments of most organizations remain alarmingly vulnerable to compromise.

To help thousands of organizations adequately bolster their existing Active Directory security defenses, and to help millions of cyber security and IT personnel worldwide enhance their proficiency in this paramount subject, starting May 05, 2020, I will personally share vital Active Directory security insights for everyone's benefit at the Paramount Defenses Blog.

Save the date - May 05, 2020.

Best wishes,
Sanjay



PS: Until then, if you're into Active Directory Security, here's some recommended reading.

Monday, February 24, 2020

Bloodhound for Active Directory : Bloody Inaccurate

Folks,

As former Microsoft Program Manager for Active Directory Security, and today as CEO of Paramount Defenses, my time is EXTREMELY valuable, so I don't have too much time for blogging etc. but I wanted to make a very important point today.



Bloodhound for AD

There's a tool out there called Bloodhound for AD (Active Directory) and its designed to be able to analyze an organization's Active Directory security permissions and find privilege escalation paths leading to all-powerful privileged AD accounts.


Over the years, its gained a lot of attention, and from what I'm told, today hundreds of thousands, if not millions, of Red and Blue Teamers worldwide use Bloodhound to find privilege escalation paths in Active Directory deployments.

In fact, these days even $ 10 B cyber security companies like CrowdStrike write about Bloodhound, as can be seen here; sadly, when they do so, all they do is show the whole wide world just how little they too know about Active Directory Security.



Bloodhound for AD - Bloody Inaccurate 

Folks, please pardon my French but when someone can design a tool to exploit weaknesses in Active Directory deployments, which could then be used to harm organizations, and call it Bloodhound, then I hope its designers and the world won't mind it if I could accordingly use the word BLOODY in pointing out just how INACCURATE this tool actually is.


I've personally tested Bloodhound, and in less than two minutes, I was able to determine that it is not accurate. I spent fifteen more minutes testing several advanced factors involved in Active Directory security, and it seemed to fail virtually all of them.

In less than 15 minutes, I was able to factually (technically) determine that Bloodhound's results were far from being accurate.




Details and Proof

I've invested almost twenty years of life in being the best in the world at Active Directory Security, so I'm NOT about to provide FREE feedback to whoever built this tool to help them make it accurate, because conceptually this tool empowers bad guys to exploit weaknesses and take out good guys. I'd encourage them to work harder to learn more, and figure it out on their own.

I'll share the ESSENCE of what makes it bloody inaccurate - it does not take THIS one essential technicality into account.

That said, to anyone who may want proof that Bloodhound is inaccurate, all one has to do is compare its output on even just a few core test cases, with the output of the world's only accurate Active Directory privileged access audit tool, Gold Finger.




Gold Finger for AD - The GOLD Standard

Even after a decade, there's still just only one tool on planet Earth that can ACCURATELY determine privileged access in Active Directory, based on the accurate determination of effective permissions, and it is the world's ONLY accurate privileged access audit tool for Microsoft Active Directory - the Microsoft-endorsed Gold Finger.


Over the last decade, from the United States Department of Defense to the United States Treasury, the world's most powerful and important government and business organizations across six continents worldwide have used and trusted Gold Finger to make these paramount determinations in their foundational Active Directory deployments.

Gold Finger includes the world's best Active Directory ACL Analyzer, ACL Exporter, Permissions Analyzer, the world's only accurate Active Directory Effective Permissions Calculator, the world's only accurate Active Directory Effective Access Auditor, AND most importantly, the world's only accurate, fully-automated, domain-wide Privileged Access Auditor for Active Directory.


Now, unlike those who built Bloodhound and made it available for free, we do NOT license Gold Finger to individuals ; we only license it to legitimate organizations, and only for use in their own Active Directory deployments, for a very simple reason.

The reason very simply is that the information that Gold Finger can uniquely determine and reveal can ACTUALLY be used to either protect and lock down or compromise and take down entire $ Billion/Trillion companies, all within a matter of minutes.





A Much Bigger Problem

From a technical standpoint, its hard to have an issue with its concept, as it seems to be a penetration testing tool that seeks to identify exploitable privilege escalation paths leading to Domain-Admin equivalent privileged accounts in Active Directory.

What amazes me and should amaze everyone is that even with its limited accuracy, based on its ability to take basic factors into account, those using it can still easily find so very many privilege escalation paths in almost any Active Directory deployment.


There's a MUCH bigger problem here, which is that even today, 99% of organizations operating on Active Directory, either do not know enough about Active Directory Security to care to lock it down, or that they do not know how to correctly audit and lockdown privileged access in their Active Directory, as a result of which they all remain massively vulnerable.

That is a far more concerning problem than a tool like this, because this is merely one tool. Proficient hackers could easily write their own tools to identify and exploit such privilege escalation paths in Active Directory, AND until organizations accurately identify and lockdown privileged access in their Active Directory, they will remain substantially exposed to compromise.




Time's Up

That's it. That's all the time I had for this. I'll end on this - just because millions of people use something doesn't mean it is either accurate ; it just means that these millions of people TOO may not yet know enough (or at all) about Active Directory Security.

Best wishes,
Sanjay.


PS: If you want to learn Active Directory Security, reading the contents of the list in this 1 post alone is a good place to start.

Friday, January 17, 2020

Active Directory Security - A Guide for CISOs

Folks,

Over the last decade, we've had thousands of organizations reach out to us to request our assistance on numerous aspects of Active Directory Security, so we have a very good idea of exactly how well organizations worldwide, as well as their CISOs, understand the paramount importance of Active Directory Security today.

In our vast experience, we have found that the thousands of organizations worldwide still do not yet understand the paramount importance of securing and defending their foundational Active Directory, and unfortunately that is deeply concerning.


Today cyber security begins at the top, so to help the CISOs of all organizations worldwide unequivocally understand the paramount importance of Active Directory Security, we released an Executive Summary on Active Directory Security -

Active Directory Security

This simple Executive Summary (PDF) can be downloaded from here - Active Directory Security.


In the interest of their organization's foundational security, I highly recommend that all CISOs worldwide read it.

Best wishes,
Sanjay.

Tuesday, January 7, 2020

A Simple Question for all Self-Proclaimed Active Directory Security Experts

Folks,

As former Microsoft Program Manager for Active Directory Security, I find it amusing every time I come across some Active Directory vendor's or self-proclaimed AD security expert's website that claims that they know Active Directory Security well.

(You see, not one of these Active Directory Security vendors or self-proclaimed Active Directory security experts seem to have a CLUE as to the most important Active Directory Security Capability in the world, let alone possessing that paramount capability.)

So, I thought I'd  pose a very simple Active Directory Security question to all Active Directory Security vendors and experts -


Question: Do you know the answer to this ONE simple question?


Specifically, in that question, I have shared a simple non-default string, and I have indicated that is a cause for great concern.

What I would like to know is what it represents and why is it a great cause of concern for 85% of organizations worldwide?


On a scale of 1 to 10, 1 being easy and 10 being difficult, I'd rate this question as a 3, so if you're truly an Active Directory expert, this should be easy for you, and shouldn't take you a minute. You can leave your answer in a comment below.


Here's your chance to impress me (and the whole world.) Oh, and Microsoft employees too may feel free to take a shot ;-)

Best wishes,
Sanjay.

Monday, January 6, 2020

What is Active Directory, and Why Is it Important?

Folks,

Today is January 06, 2020, and as promised, here I am getting back to sharing thoughts on Active Directory Security.


Back to the Basics (Cyber Security 101)

I'd like to kick off this blog this year/decade by asking and answering a very simple yet vital question - What is Active Directory?

You see, while this question may seem simple to some (and it is,) its one of the most important questions to answer adequately, because in an adequate answer to this most simple question lies the key to organizational cyber security worldwide.

The reason is very simple -  if you were to ask most CISOs or IT professionals, they'll likely tell you that Active Directory is the "phone book" of an organization's IT infrastructure, and of course, since "who really cares about a phone book" it is this shallow view that leads so many organizations to greatly diminish the value of Active Directory to the point of sheer negligence!

In fact, for years now, this has been the predominant view held by most CISOs and organizations worldwide, and sadly it is the negligence resulting from such a simplistic view of Active Directory that the Active Directory deployments of most organizations remain substantially insecure and vastly vulnerable to compromise today.



Active Directory - The Very Foundation of Organizational Cyber Security Worldwide

If as they say, a "A Picture is Worth a Thousand Words", perhaps I should paint you a very simple Trillion $ picture -


An organization's Active Directory deployment is quite simply its single most valuable IT and corporate asset, worthy of the highest protection at all times, because it is the very foundation of an organization's cyber security.

You see, the entirety of an organization's building blocks of cyber security i.e. all organizational user accounts and passwords used to authenticate their people, all security groups used to authorize access to all their IT resources, all their privileged user accounts, all the accounts of all their computing devices (laptops, desktops, servers etc.) are all stored, managed and secured in (i.e. inside) the organization's foundational Active Directory, and all sensitive/privileged actions on them are audited in it.

In other words, should an organization's foundational Active Directory, or even a single Active Directory privileged user account, be compromised, the very foundation of the organization's cyber security, and thus the entire organization could be exposed to the risk of complete, swift and colossal compromise.



Active Directory Security Must Be Organizational Cyber Security Priority #1

Ensuring the highest protection of an organization's foundational Active Directory deployment must, without a doubt, be the #1 priority of every organization that cares about cyber security, protecting shareholder value and business continuity.


Here's why - A deeper, detailed look into What is Active Directory ?


For anyone to whom this may still not be clear, I'll spell it out - just about everything in organizational Cyber Security, whether it be Identity and Access Management, Privileged Access Management, Network Security, Endpoint Security, Data Security, Intrusion Detection, Cloud Security, Zero Trust etc. ultimately relies and depends on Active Directory (and its security.)


In essence, today every organization in the world is only as secure as is its foundational Active Directory deployment, and from the CEO to the CISO, from IT Managers to Auditors and from Domain Admins to employees, everyone should know this fact.

Best wishes,
Sanjay.

Friday, December 6, 2019

Its Time to Help Secure Active Directory Worldwide

Folks,

I trust this finds you all doing well. It has been a few months since I last blogged - pardon the absence. I had to focus my energies on helping the world get some perspective, getting 007G ready for launch, and dealing with a certain nuisance.

Having successfully accomplished all three objectives, it is now finally TIME to help thousands of organizations worldwide adequately secure and defend their foundational Active Directory deployments from the proverbial SKYFALL(ing on them).


I'm BLOWN away by just how little organizations (as well as AD/cyber security companies) worldwide seem to know and understand not just the paramount importance of, but also what it takes to adequately ensure Active Directory Security.


When you know as much as I do, care as much as I do, and possess as much capability as I do, you not only shoulder a great responsibility, you almost have an obligation to educate the whole world about cyber security risks that threaten their security.

So, even though I barely have any time to do this anymore, in the interest of foundational cyber security worldwide, I'm going to start sharing some valuable perspectives again, and do so, on three blogs - this one, that one, and the one below.


Speaking of which, earlier this week, I had the PRIVILEGE to launch the official PD blog -  https://blog.paramountdefenses.com


Stay tuned for high-value AD security insights right here from January 06, 2020 onwards,
and let me take your leave with a befitting (and one of my favorite) songs(s)  -



Best wishes,
Sanjay.


PS: Just a month ago, the $ Billion Czech cyber security company Avast was substantially compromised, and guess what the perpetrators used to compromise them? They used the EXACT  means I had clearly warned about TWO years ago, right here.

Friday, February 1, 2019

Pardon the Delay

Folks,

I trust this finds you doing well. The last time I blogged was on Nov 05, 2018, and I had said that it was time to help Microsoft and the world better understand Active Directory Security and that I would be sharing additional insights starting Nov 18, 2018.

Please pardon the delay - something important came up, and
today I'd like to share with you the reason for this delay...


One of the World's Most Powerful Defense Organizations Requested Our Assistance

Back in Nov 2018, just as I was about to start blogging that series, one of the most powerful defense organizations in the world reached out to us requesting our assistance in correctly identifying privileged users within their foundational Active Directory.


(You see, organizations that actually understand Active Directory Security know that there is ONLY one way to correctly identify privileged access in Active Directory. Organizations that don't yet know this simple fact still resort to acquiring and using what basically are petty but pretty looking Active Directory permissions analyzers (and there still are 1000s of such organizations.))

Whilst we were happy to assist them, due to certain operational constraints, it turned out that in order for us to help them, we would have to make some non-trivial changes to Gold Finger. This was very important for them so we went straight to work.

We put our entire development team to work, and we worked 60 days straight without taking a break; there were no Christmas holidays, no New Years holidays, no weekends. There was only work, and within 60 days we had made and thoroughly tested all the enhancements required for us to be able to assist this one particular organization, and as a result, 1000s of others.

As Gold Finger's architect, I too was substantially involved in the process, and as a leader, I too worked 60 days straight, and it is my privilege to share that earlier today we officially released Gold Finger version 6.5, complete with all the required changes.



Introducing Gold Finger 6.5

Earlier today, we announced the release of Gold Finger v6.5, featuring amongst other enhancements, support for Windows 10.

Here's the Press Release from this morning - Paramount Defenses Releases Gold Finger Version 6.5

Gold Finger v6.5

If you can touch a button, you can now instantly, automatically and accurately determine exactly who has what privileged access, where and how, in any Active Directory, and on any Microsoft Windows operating system, including Windows 10!


The free version of Gold Finger v6.5 is also available at - https://www.paramountdefenses.com/goldfinger.html


With this little but important detour out of the way, you can expect me to get back to some blogging one of these days because Microsoft and thousands of its customers worldwide still seem to need of help understanding the very basics of Active Directory security i.e. without the ability to accurately determine effective permissions in Active Directory, you cannot secure a single object in Active Directory, and by corollary you can't accomplish a single Active Directory security related objective, and that includes all the latest buzzwords - Privileged Access Management, Privileged Account Discovery, Zero-Trust, Blah Blah, etc. etc.

So, thank you for pardoning the delay, and stay tuned!  

Any day now!

Best wishes,
Sanjay.

Monday, November 5, 2018

It is TIME to Help Microsoft AND Thousands of Organizations Worldwide Better Understand Active Directory Security

Folks,

As former Microsoft Program Manager for Active Directory Security, and today as the CEO of Paramount Defenses, I feel that it is time to help the $800 Billion Microsoft, and 1000s of organizations worldwide better understand Active Directory Security.


Here's why - Over the last few years, 1000s of organizations from across over 150 countries worldwide have requested our assistance (completely unsolicited), so we know about the various challenges that most organizations have to deal with, and based on what we're seeing across the globe, the state of foundational cyber security worldwide seems to be worrisome.

Incidentally, a large majority of these organizations do have several piece-meal cyber security controls such as Active Directory Auditing, Advanced Threat Analytics, Two-Factor Authentication, Privileged Session Managers, Password Vaults, Zero-Trust Security, Privileged Access Management (PAM) etc., yet their Active Directory deployments are still likely vastly vulnerable.

I'll say only this much - TODAY Microsoft Active Directory is at the foundation of cyber security and privileged access at over 85% of all business and government organizations worldwide, AND the current state of awareness and (the substantially inadequate level of) protection afforded to these foundational Active Directory deployments is concerning enough that it warrants the attention of all stakeholders, including executive and IT leadership, customers and investors, worldwide.

Thus, in weeks to come, we may reach out to the Executive Management of organizations worldwide to make them aware.






In addition, to help educate Microsoft AND the world, starting next Monday, Nov 12, 2018, I'll be penning the following -

  1. Active Directory Security For Everyone - Why is Active Directory Security Paramount to Organizational Cyber Security?

  2. Active Directory Security For Novices and Enthusiasts - A Closer Look at Active Directory's Security Model etc.

  3. Active Directory Security for IT Admins and Security Auditors - An Overview of Active Directory Security Permissions

  4. The World's Most Important Active Directory Need and Security Capability - Active Directory ___ ___

  5. For Self-Proclaimed Active Directory Security Experts - Why Analyzing Active Directory Security Permissions is Useless


  6. For IT Managers and CISOs - The Billion $ Difference Between Active Directory Auditing and Active Directory Audit

  7. For all Organizations - What Happens When an Organization Deploys a Cheap Auditing Solution Built Overseas?

  8. For Microsoft, Domain Admins and CISOs Worldwide - What Constitutes a Privileged User in Active Directory?

  9. For the CyberArks of the World - How to Correctly Identify/Audit Privileged Access/Users in Active Directory?

  10. For All Audit Organizations Worldwide - Are You Sure Your Auditors Know How to Correctly Audit Active Directory?


  11. To All Cloud & Cyber Security Companies Worldwide - Isn't Active Directory at the Very Foundation of Your Security Too?



Finally, for C*Os worldwide, I penned this today - Cyber Security 101 for the C-Suite - Active Directory Security is Paramount.


Ideally, Microsoft should be doing this (i.e. helping adequately educate their customers worldwide), but it appears that these days all they seem to care about is that new fad called "The Cloud", so we're left with no choice but to do this for the world.

Very well then, onward to Nov 12, 2018, right here.


Sincerely,
Sanjay

Wednesday, October 31, 2018

Looking for a Few Good Active Directory Security Experts

Folks,

In days to come, I'll be helping thousands of organizations worldwide better understand Active Directory Security essentials / fundamentals, so that they can adequately secure and defend their foundational Active Directory deployments.


Albeit, we have no dearth of resources, I'm looking for a few good external Active Directory Security Experts (e.g. DS MVPs), who may be willing to assist in this noble objective, so if you're interested, please feel free to connect, and I'll tell you more.

We're all in it together, and together we can make a difference.

Thanks,
Sanjay

PS: If you understand this stuff, you're ready to help.

Sunday, October 28, 2018

How Massive Could the Impact of an Active Directory Security Breach Be?

Folks,

Today I'd like to ask a simple but paramount question, the answer to which impacts not just trillions of dollars of organizational and investor wealth worldwide, but also likely the national security of over one hundred and fifty countries worldwide.

Here it is -
Q: How Massive Could the Impact of an Active Directory Security Breach Be?
      Specifically, exactly what could happen if the foundational Active Directory of an organization were breached
Active Directory is the Foundation of Cyber Security Worldwide 

If you need me to paint you a picture, consider the potential impact of an Active Directory security breach at virtually any organization that impacts your life - from the world's biggest IT (Cloud, Operating Systems, Phones, Computers, Networking, Internet, Social Media etc.) companies to the world's biggest cyber security companies, or for that matter from virtually every financial institution on Wall Street, to just about every company traded on any stock exchange in any country in the world, or any one of thousands of government agencies/departments in over 150 countries worldwide.

The reason I am publicly asking this question, is because its 2018 today, not 2004, and this is possibly the most important cyber security question that Executive Management, Cyber Security and IT leadership at thousands of organizations worldwide should be asking themselves today, but most likely are not.

In fact, at most organizations, this isn't even on their radar, let alone rightly being their top (#1) cyber security priority.

Thus, I felt the need to ask this paramount question.

Also, for once, I am NOT going to answer a question that I have asked, but instead let organizations worldwide ponder over it. Over the years, I've already asked and answered many of the world's most vital Active Directory / cyber security questions.

I'll only say this much - Any organization whose CEO and CISO do not know the answer to this question is not secure today.

Sicnerely,
Sanjay

Monday, October 22, 2018

What are the Minimum Security Permissions Needed in Active Directory to Run Mimikatz DCSync?

Folks,

In days to come, I'll be helping organizations worldwide understand what constitutes a privileged user in Active Directory, how to correctly audit privileged access in Active Directory, and what the world's most important Active Directory security capability is.

Today though, I just wanted to ask a very simple and elemental cyber security multiple-choice question, so here it is -


Q. What are the minimum Active Directory Security Permissions that a perpetrator needs to be able to successfully run Mimikatz DCSync against an organization's foundational Active Directory deployment?

Is it -
A. The "Get Replication Changes" Extended Right 
B. The "Get Replication Changes All" Extended Right 
C. Both A and B above 
D. Something else

I already know the answer to this simple question. I'm only asking because I believe that today every Domain Admin and every CISO at every organization that operates on Active Directory MUST know the answer to this question, and here's why.

You may be surprised if I were to share with you just how many Domain Admins and CISOs (at so many of the world's most prominent organizations) don't know even seem to know what Mimikatz DCSync is, let alone knowing the answer!


If you know the answer to this question, please feel free to share it by leaving a comment below.

Best wishes,
Sanjay.

Tuesday, October 16, 2018

Mimikatz DCSync Detection

Folks,

I trust this finds you doing well. I know so many of you are waiting for me to answer the question - What's the World's Most Important Active Directory Security Capability? but before I did so, I just wanted to address something very simple and vital.


Mimikatz DCSync Detection ?! ;-)

If you're into Cyber Security, unless you live on another planet, by now you know that at the very foundation of cyber security worldwide lies Microsoft Active Directory, you know that little thing within which lie not just everyone's accounts and passwords, or for that matter the computer accounts of every single domain-joined machine, or for that matter every single domain security group that is used to protect the entirety of an organization's IT assets, but also the proverbial "Keys to the Kingdom!" etc. etc.

By the way, this isn't some secret - this is CYBER SECURITY 101 that millions of IT personnel, IT managers, CISOs and just about everyone in IT ought to know by know, considering that Active Directory has been around for almost two decades now!

Alright, fast forward...

A few years ago, a remarkably intelligent and talented Benjamin Delpy introduced a new feature in his hacking tool Mimikatz, and that feature was called Mimikatz DCSync. In essence, if you can run Mimikatz DCSync against an Active Directory, you can instantly obtain access to the credentials of literally everyone who has a domain account in that domain - we're talking the accounts of literally everyone, from Domain Admins to the CISO and from the Enterprise Admin to the CEO, etc. etc.

Now, technically, DCSync leverages the ability of a security principal to be able to request and replicate Active Directory content (including secrets i.e. password hashes) out of Active Directory. It turns out anyone who has sufficient effective permissions to be able to replicate secrets out of Active Directory can run Mimikatz DCSync, and within minutes be proverbial God!

So, what happens? In time, Mimikatz DCSync finds global fame and glory, it becomes a must have tool in the arsenal of these so called kiddish Red Teams and Blue Teams, and in addition today there's no dearth of cyber security experts who will want to blog about Mimikatz DCSync sharing with the world, its usage, how to exploit it etc. etc. and in particular how to detect it!

Here are a few random blogs a Google search seemed to suggest -
  1. Mimikatz DCSync Usage, Exploitation, and Detection
  2. Mimikatz and DCSync and ExtraSids, Oh My
  3. Modern Active Directory Attack Scenarios and How to Detect Them
  4. DCSYNC

Now, please pardon me for expressing serious concern here because if the best an organization can do is DETECT the use of Mimikatz DCSync, that's sort of like, well let me paint you a picture:



A Billion $ Organization or for that matter a Government Agency having to rely on detection of Mimikatz DCSync is akin to ....


... lets assume a SNIPER takes a shot at a target from point blank range, and the best those protecting the target can do is try and detect the bullet in flight milliseconds before it hits its target. Well, I shouldn't have to complete the sentence for you.


Here's the Trillion $ point - if an organization is having to rely on the DETECTION of the use of Mimikatz DCSync, its too late.

From the Domain Admin to the CISO, its time to go home and find another job, because it would already have been too late. You're done. Once a malicious perpetrator has gained administrative access in even a single Active Directory domain, those who know anything about Active Directory Security will tell you that you've lost the entire Active Directory forest. Oh, and if you think you could easily recover that forest from a trusted forest, you've likely been getting some amateur advice ;-)


Mimikatz DCSync Mitigation

I cannot stress this enough - this is not a risk that can be addressed by detection. It needs to be mitigated and today, every single organization that operates on Microsoft Active Directory can easily mitigate the risk posed by Mimikatz DCSync. I've already spent enough time educating the world about this, so I'm not going to waste one more precious minute on this.

For every org that wants to learn how to do so - How to Lockdown Active Directory to Thwart the Use of Mimikatz DCSync


Incidentally, the astute mind will observe, that whether it be mitigating the risk posed by Mimikatz DCSync or securing access to just about anything and everything in Active Directory, all organizations worldwide (including likely the $800 Billion Microsoft) require is 1 single, fundamental cyber security capability - The Most Important Active Directory Security Capability in the World.





A Request to All Experts Out There

To all cyber security experts and cyber security companies (including Microsoft) out there, I have a request - if you truly know Active Directory Security, lets see you go beyond helping the world learning how to use, exploit and detect Mimikatz DC Sync...


...lets see you teach the world how to actually mitigate this risk, perhaps with an example, for when you get there, you'll likely realize that not a single object in any Active Directory domain worldwide can be adequately secured without possessing this.


Alright that's it, I'm not wasting one more minute of my precious time
on this little distraction of a thing called Mimikatz DCSync.


After all this dry stuff, perhaps I should end on a humorous note - Time to Ignite an Intellectual Spark at Microsoft Ignite 2018 ;-)

Best wishes,
Sanjay.

Monday, October 1, 2018

Did Anyone at Microsoft Ignite 2018 Know the Answer To This Question?


Folks,

Last week, thousands of IT professionals, managers, CISOs and CIOs were in Orlando, attending, well, Microsoft Ignite 2018 !

Image Courtesy Microsoft. Source: https://www.microsoft.com/en-us/ignite

Not surprisingly, the Microsoft Ignite Conference had SOLD OUT!  There were 900+ sessions, 100+ instructor-led technology workshops, 60+ Microsoft Immersion workshops, and 50+ hands-on labs with access to expert proctors! That's great!

Did I mention that likely hundreds of Microsoft's own experts were also there, and collectively, they covered numerous vital areas such as Securing the Enterprise, Simplified IT Management, Identity‚ Access & Compliance, Enterprise Security etc.


So, with over 1000 sessions, 1000s of attendees, access to "expert proctors", and 100s of Microsoft's very own IT experts, one would hope THERE MUST'VE BEEN AT LEAST ONE PERSON AT MICROSOFT IGNITE 2018 who could have answered A VERY SIMPLE QUESTION -




       Question: What's The World's Most Important Active Directory Security Capability?






This is paramount, and here's why. In case you're wondering why anyone, and everyone who attended Microsoft Ignite 2018 should care about this question AND know the answer, its because in any Microsoft Windows Server based IT Infrastructure, NOT A SINGLE ONE of the many vital areas listed above i.e. Securing the Enterprise, Simplified IT Management, Identity‚ Access & Compliance, Enterprise Security etc. etc. can be adequately addressed without involving Active Directory Security.


In fact, here's proof - 

Not a single one of the following fundamental cyber security / Windows security questions can be answered without knowing the answer to the question above and possessing that capability -


  1. Who can reset the passwords of any/every Domain Admin in an organization?

  2. Who can disable two-factor authentication on privileged and other domain user accounts?

  3. Who can change the membership of the Domain Admins group, or of any domain security group?

  4. Who can use Mimikatz DCSync to completely compromise the credentials of all domain user accounts?

  5. Who can delete an(y) Organizational Unit (OU) in a(ny) of the organization's Active Directory domains?

  6. Who can link a malicious group policy to an OU to instantly compromise all domain computer accounts in that OU?

  7. Who can modify the attributes of a mission-critical service's service connection points to instantly render it useless?

  8. Who can set the "Trusted for Unconstrained Delegation" bit on a server's domain account to compromise security*?

  9. Who can create, delete and manage domain user accounts, domain security groups, OUs etc. in Active Directory?

  10. Who can control/change privileged access as well as delegated access within and across the entire Active Directory?


Each and every single organization whose IT personnel / CISOs attended Microsoft Ignite 2018 (including Microsoft itself) must have precise answers to each and every one of the above listed fundamental cyber security questions at all times.




So, if anyone who attended Microsoft Ignite 2018 (including Microsoft's own experts) knows the answer to this 1 question, please be my guest and answer the question by leaving a comment at the end of that blog post, and you'll earn my respect.


If you don't know the answer, I highly recommend reading, one, two and three, because without knowing the answer to this question (and without possessing this capability,) you cannot secure anything in an Active Directory based Windows network.

The last time I checked, virtually the whole world runs on Active Directory.

Best wishes,
Sanjay

Friday, September 28, 2018

A Few Notable Names in the Active Directory (AD) / AD Security Space

Folks,

Today I wanted to take a moment to share a few notable names in the Active Directory space, of those individuals who I feel have done a lot to help IT admins and IT personnel worldwide better understand Active Directory and Active Directory Security.

Oh, and for those wondering who I am to come up with such a list, I'm a nobody whose work however likely impacts everybody, and here's a very small sample of my work -
  1. AdminSDHolder
  2. Kerberos Token Bloat
  3. Mimikatz DCSync Mitigation
  4. Active Directory Privilege Escalation
  5. Active Directory Effective Permissions 
  6. Active Directory ACLs - Attack and Defense
  7. How to Discover Stealthy Admins in Active Directory
  8. How to Thwart Sneaky Persistence in Active Directory 
  9. How to Easily Solve the Difficult Problem of Active Directory Botnets
  10. and of course, the 30-day series on Active Directory Security School for Microsoft

BTW, in the next few days, you can expect much more, including What Constitutes a Privileged User in Active Directory, The Most Important Active Directory Security Capability, How to Make an Organization's Domain Admins Powerless in 2 Minutes, How to Actually Secure and Defend an Active Directory, Breach to 0wned in 5 Minutes, Defending Active Directory and more.

But this isn't about me, so lets keep reading.



A Few Notable Names in the Active Directory / Active Directory Security Space

Without further adieu, I'd like to take a moment to share a few notable names in the Active Directory / Active Directory Security space, as I feel that in the last 10 to 20 years, these individuals have done a lot to helps hundreds of thousands (if not millions) of IT admins and personnel worldwide, better understand various aspects of Active Directory and Active Directory Security.



So here's a list of a few notable folks in the Active Directory space, listed in no particular (i.e. random) order -

  1. Joe Richards - Joe is one of the most knowledgeable and experienced folks in the Active Directory space.

  2. Daniel Ulrichs - Daniel is one of the most knowledgeable and experienced folks in Active Directory Security.

  3. Christoffer Andersson - Christoffer, a longtime Directory MVP is very knowledgeable in Active Directory.

  4. Robbie Allen - Robbie needs no introduction in the space and is the author of multiple books on Active Directory. 

  5. Santhosh Sivarjan - Santhosh has been working on Active Directory for years and is very knowledgeable.

  6. Guido Grillemeier - Guido is amongst the most knowledgeable and finest Active Directory Security experts out there.

  7. Brian Desmond - Brian is a recognized Microsoft infrastructure expert with years of experience.

  8. Derek Seaman - Derek is a highly experienced Active Directory practioner, now focused on virtualization.

  9. Sander Berkouwer - Sander is a multiple-time Directory Services MVP and has been working on AD for years.

  10. John Craddock - John is an accomplished Microsoft MVP who has been working on AD since pre-Windows 2000.

  11. Alistair G. Lowe-Norris - Alistair too needs no introduction and is the author of several books on Active Directory. 

  12. Jorge de Almeida Pinto -  Jorge, a multiple time MVP, is a highly experienced Active Directory consultant/engineer.

  13. Brian Puhl - Brian is a highly experienced Active Directory Domain Admin, and is one of Microsoft IT's finest.

  14. Gil Kirkpatrick - Gil is one of the most recognized and experienced Active Directory experts out there.

  15. John Savill - John is a 11-time Microsoft MVP currently focused on Microsoft Azure.

  16. Ulf Simon-Weidner - Ulf is an 8-time MVP, an MCT, and has been working on Active Directory since Windows 2000.

  17. Sean Deuby - Sean is a highly experienced IT Architect and has been working on Active Directory since Windows 2000.

  18. Jimmy Andersson - Jimmy is a highly experienced AD expert, and has been awarded Microsoft MVP for 20 years now

  19. Mark Parris - Mark is an experienced AD consultant with almost two decades of experience on Active Directory 

  20. Jackson Shaw - Jackson is a longtime Active Directory veteran, who is very knowledgeable and well-known. 

In my opinion, the work, efforts and contributions of these individuals, whether it be in the form of sharing knowledge on blogs, answering questions on forums, providing feedback, presenting at conferences, or helping organizations directly, have likely helped millions of IT folks worldwide better understand various aspects of Active Directory and Active Directory security.

There are many more folks out there who have been working on Active Directory and Active Directory Security for years now, such as the hundreds of incredible folks who work for Microsoft Consulting Services, as well as other organizations in the Active Directory space such as Quest Software, HP Services and others, so if I may have unintentionally missed a few names I'm sorry. If you know of someone whose name you feel should be on this list, please leave me a comment below to let me know.

In addition, there are also a few notable new comers to the Active Directory / Active Directory Security space who have been working very hard and are making an impact, and this post wouldn't be complete without recognizing the new comers as well, so here they are (shared in random order) - Sean Metcalf, Andy Robbins, Will Schroeder and Lucas Bouillot to name a few.

Of course, I should also mention that in the list above, I haven't included my former Microsoft colleagues on the Active Directory Dev Team, because if I did so, the list would be long. Oddly enough, I think most of them may be working on Azure now ;-)


That's all for today. In the next two weeks, I'm going to answer this question to help Microsoft and organizations worldwide.

Best wishes,
Sanjay.

Monday, September 24, 2018

Pardon the Absence, and Get Ready!

Folks,

Hello again. I trust this finds you all doing well. It has been a few weeks since I last blogged. I hope you'll pardon my absence.

Yes I was supposed to answer a rather important question, in fact, possibly the world's most important cyber security question, for the whole world, back in July, but I had to postpone doing so, for a few good reasons, which I may reveal in days to come.

Let's just say that amongst other things (e.g. a rather interesting trip across the Atlantic), I was working on finalising a project that directly impacts cyber security worldwide today, you know, the kind of stuff that even James Bond doesn't have yet!



By the way, speaking of Mr. Bond, as you probably know, I'm a huge fan, so thought I'd share a catchy tune with you -



Oh, that project I was working is almost over (i.e. RC1), so its time for me to get back to blogging, and...     … well, get ready!

Best wishes,
Sanjay

Monday, July 9, 2018

What's The World's Most Important Active Directory Security Capability?


Folks,

A few days ago, I had asked likely the most important Cyber Security question in the world today, one that today DIRECTLY impacts the foundational cyber security of 1000s of business and government organizations across 190 countries worldwide.

Here It Is -

What Is the 1 Essential Cyber Security Capability Without Which NOT a Single Active Directory object, domain, forest or deployment can be adequately secured?



I had even provided a hint - it controls exactly who is denied and who is granted access to literally everything within Active Directory, and it comes into play every time anyone accesses anything in any Active Directory domain in any organization.

Thusfar, thousands of IT professionals from across the world, including some of the world's most famous/renowned Windows and Active Directory Security experts and CISOs, as well as Microsoft employees, have all seen the question on my blog.

Unfortunately, not ONE individual in the world (okay, except one) has answered this ONE most simple and basic question yet!



Why Not?

Do organizations worldwide NOT know the answer, OR are they afraid to answer it because they don't possess this capability?

Let's find out. To help organizations worldwide, including Microsoft, figure out the answer, I'm going to give a few more hints.



A Few More BIG Hints

Ladies and Gentlemen, NOT a single organization in the world whose IT infrastructure operates on Microsoft Active Directory, can fulfill even ONE of the following mission-critical IT and cyber security needs without possessing this ONE capability -


  1. Adequately secure their foundational Active Directory

  2. Adequately mitigate the risk posed by the use of Mimikatz DCSync

  3. Adequately mitigate the risk posed by Active Directory Privilege Escalation

  4. Accurately identify privileged users in their foundational Active Directory domains

  5. Accurately discover stealthy admins in their foundational Active Directory domains

  6. Adequately protect all organizational computers and user accounts (including C*O accounts)

  7. Adequately secure mission-critical Active Directory integrated applications (e.g. Exchange, Centrify)

  8. Securely integrate their on-premises Active Directory deployments with Microsoft Azure in the "Cloud"

  9. Correctly demonstrate regulatory compliance of access privileged provisioned within their Active Directory

  10. Reliably control the distribution and delegation of administrative authority in their foundational Active Directory

Let me repeat it again so there is NO ambiguity - not a single one of the above mission-critical IT and cyber security needs can be fulfilled without possessing this ONE capability, only because it is technically impossible to do so without this ONE capability.





I'll Make it Easy

Ladies and Gentlemen, Active Directory has been around for almost two decades now, and yet most organizations worldwide do not currently possess this ONE essential, fundamental and paramount cyber security capability yet. The reason they don't currently possess it is likely that they may not even know about it, and that sounds as unbelievable to me as it does to you!

If they haven't figured it out in almost TWO decades, they're not likely to figure it on their own, so let me make it easy for them.

It is ONE of the following five Active Directory Security Capabilities -
  1. Active Directory Auditing
  2. Active Directory Permissions/ACL Analysis
  3. Active Directory Effective Permissions/Access
  4. Microsoft Advanced Threat Analytics (aka ATA)
  5. <You can throw in all the latest buzzwords here e.g. Privileged Identity/Account Management, Zero Trust, blah blah etc >

Here's one FINAL hint. If you possess this ONE capability (on the right object in Active Directory,) then you can also easily turn off i.e. deactivate, disable, and/or render useless, all of the other listed security capabilities in an Active Directory deployment!


So, which ONE is it ?





Make No Mistake + Only Two Kinds of Organizations

Make no mistake about it - one simply CANNOT adequately protect anything in any Active Directory WITHOUT possessing this ONE capability, and thus one simply cannot protect the very foundation of an organization's cyber security without possessing this ONE paramount cyber security capability. It unequivocally is as remarkably simple, elemental and fundamental as this.


Thus, today there are only two kinds of organizations worldwide - those that possess this paramount cyber security capability, and those that don't. Those that don't possess this essential capability do not have the means to, and thus cannot adequately protect, their foundational Active Directory deployments, and thus by logic are provably and demonstrably vastly insecure.




My Concern - This Impacts Organizational Security Worldwide

I hope that with the hints I've provided above, organizations worldwide will finally realize what this ONE essential capability is.


More importantly, I hope that at organizations worldwide, IT personnel, Domain Admins, CISOs and CIOs realize and recognize that without possessing this ONE essential and paramount Active Directory Security capability, their $ Billion organizations may currently be operating on a highly vulnerable foundation, which is a matter so serious that it should concern all stakeholders.



The Answer

February 24, 2020 Update: Here's the answer - THIS  is the world's most important Active Directory Security Capability.


Best,
Sanjay.