Today Active Directory Security is mission-critical to organizational security worldwide and thus mission-critical to Cyber Security worldwide. On this blog, former Microsoft Program Manager for Active Directory Security, and today, CEO of Paramount Defenses, shares valuable technical insights on Active Directory Security.


Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Tuesday, May 25, 2021

New Coordinates

 Folks,

I hope this finds you all doing well. As some of you may now, over the years, I have shared numerous perspectives on foundational cyber security and on Active Directory security, both here (i.e. on this blog) and at my first blog.

Unfortunately, given my immense responsibilities today, and the sheer paucity of time, I will no longer be able to share my perspectives on multiple blogs, so from now on, I will mostly be sharing my perspectives at the Paramount Defenses Blog.

I recently penned two relevant posts, including What's common between the Colonial Pipeline Hack and the SolarWinds Breach and one on what actually was At the Heart of the SolarWinds Breach i.e. none other than Privileged Access in Active Directory.

The URL for my new coordinates is - https://blog.paramountdefenses.com

Thanks,
Sanjay

Monday, January 6, 2020

What is Active Directory, and Why Is it Important?

Folks,

Today is January 06, 2020, and as promised, here I am getting back to sharing thoughts on Active Directory Security.


Back to the Basics (Cyber Security 101)

I'd like to kick off this blog this year/decade by asking and answering a very simple yet vital question - What is Active Directory?

You see, while this question may seem simple to some (and it is,) its one of the most important questions to answer adequately, because in an adequate answer to this most simple question lies the key to organizational cyber security worldwide.

The reason is very simple -  if you were to ask most CISOs or IT professionals, they'll likely tell you that Active Directory is the "phone book" of an organization's IT infrastructure, and of course, since "who really cares about a phone book" it is this shallow view that leads so many organizations to greatly diminish the value of Active Directory to the point of sheer negligence!

In fact, for years now, this has been the predominant view held by most CISOs and organizations worldwide, and sadly it is the negligence resulting from such a simplistic view of Active Directory that the Active Directory deployments of most organizations remain substantially insecure and vastly vulnerable to compromise today.



Active Directory - The Very Foundation of Organizational Cyber Security Worldwide

If as they say, a "A Picture is Worth a Thousand Words", perhaps I should paint you a very simple Trillion $ picture -


An organization's Active Directory deployment is quite simply its single most valuable IT and corporate asset, worthy of the highest protection at all times, because it is the very foundation of an organization's cyber security.

You see, the entirety of an organization's building blocks of cyber security i.e. all organizational user accounts and passwords used to authenticate their people, all security groups used to authorize access to all their IT resources, all their privileged user accounts, all the accounts of all their computing devices (laptops, desktops, servers etc.) are all stored, managed and secured in (i.e. inside) the organization's foundational Active Directory, and all sensitive/privileged actions on them are audited in it.

In other words, should an organization's foundational Active Directory, or even a single Active Directory privileged user account, be compromised, the very foundation of the organization's cyber security, and thus the entire organization could be exposed to the risk of complete, swift and colossal compromise.



Active Directory Security Must Be Organizational Cyber Security Priority #1

Ensuring the highest protection of an organization's foundational Active Directory deployment must, without a doubt, be the #1 priority of every organization that cares about cyber security, protecting shareholder value and business continuity.


Here's why - A deeper, detailed look into What is Active Directory ?


For anyone to whom this may still not be clear, I'll spell it out - just about everything in organizational Cyber Security, whether it be Identity and Access Management, Privileged Access Management, Network Security, Endpoint Security, Data Security, Intrusion Detection, Cloud Security, Zero Trust etc. ultimately relies and depends on Active Directory (and its security.)


In essence, today every organization in the world is only as secure as is its foundational Active Directory deployment, and from the CEO to the CISO, from IT Managers to Auditors and from Domain Admins to employees, everyone should know this fact.

Best wishes,
Sanjay.

Sunday, October 28, 2018

How Massive Could the Impact of an Active Directory Security Breach Be?

Folks,

Today I'd like to ask a simple but paramount question, the answer to which impacts not just trillions of dollars of organizational and investor wealth worldwide, but also likely the national security of over one hundred and fifty countries worldwide.

Here it is -
Q: How Massive Could the Impact of an Active Directory Security Breach Be?
      Specifically, exactly what could happen if the foundational Active Directory of an organization were breached
Active Directory is the Foundation of Cyber Security Worldwide 

If you need me to paint you a picture, consider the potential impact of an Active Directory security breach at virtually any organization that impacts your life - from the world's biggest IT (Cloud, Operating Systems, Phones, Computers, Networking, Internet, Social Media etc.) companies to the world's biggest cyber security companies, or for that matter from virtually every financial institution on Wall Street, to just about every company traded on any stock exchange in any country in the world, or any one of thousands of government agencies/departments in over 150 countries worldwide.

The reason I am publicly asking this question, is because its 2018 today, not 2004, and this is possibly the most important cyber security question that Executive Management, Cyber Security and IT leadership at thousands of organizations worldwide should be asking themselves today, but most likely are not.

In fact, at most organizations, this isn't even on their radar, let alone rightly being their top (#1) cyber security priority.

Thus, I felt the need to ask this paramount question.

Also, for once, I am NOT going to answer a question that I have asked, but instead let organizations worldwide ponder over it. Over the years, I've already asked and answered many of the world's most vital Active Directory / cyber security questions.

I'll only say this much - Any organization whose CEO and CISO do not know the answer to this question is not secure today.

Sicnerely,
Sanjay

Monday, July 9, 2018

What's The World's Most Important Active Directory Security Capability?


Folks,

A few days ago, I had asked likely the most important Cyber Security question in the world today, one that today DIRECTLY impacts the foundational cyber security of 1000s of business and government organizations across 190 countries worldwide.

Here It Is -

What Is the 1 Essential Cyber Security Capability Without Which NOT a Single Active Directory object, domain, forest or deployment can be adequately secured?



I had even provided a hint - it controls exactly who is denied and who is granted access to literally everything within Active Directory, and it comes into play every time anyone accesses anything in any Active Directory domain in any organization.

Thusfar, thousands of IT professionals from across the world, including some of the world's most famous/renowned Windows and Active Directory Security experts and CISOs, as well as Microsoft employees, have all seen the question on my blog.

Unfortunately, not ONE individual in the world (okay, except one) has answered this ONE most simple and basic question yet!



Why Not?

Do organizations worldwide NOT know the answer, OR are they afraid to answer it because they don't possess this capability?

Let's find out. To help organizations worldwide, including Microsoft, figure out the answer, I'm going to give a few more hints.



A Few More BIG Hints

Ladies and Gentlemen, NOT a single organization in the world whose IT infrastructure operates on Microsoft Active Directory, can fulfill even ONE of the following mission-critical IT and cyber security needs without possessing this ONE capability -


  1. Adequately secure their foundational Active Directory

  2. Adequately mitigate the risk posed by the use of Mimikatz DCSync

  3. Adequately mitigate the risk posed by Active Directory Privilege Escalation

  4. Accurately identify privileged users in their foundational Active Directory domains

  5. Accurately discover stealthy admins in their foundational Active Directory domains

  6. Adequately protect all organizational computers and user accounts (including C*O accounts)

  7. Adequately secure mission-critical Active Directory integrated applications (e.g. Exchange, Centrify)

  8. Securely integrate their on-premises Active Directory deployments with Microsoft Azure in the "Cloud"

  9. Correctly demonstrate regulatory compliance of access privileged provisioned within their Active Directory

  10. Reliably control the distribution and delegation of administrative authority in their foundational Active Directory

Let me repeat it again so there is NO ambiguity - not a single one of the above mission-critical IT and cyber security needs can be fulfilled without possessing this ONE capability, only because it is technically impossible to do so without this ONE capability.





I'll Make it Easy

Ladies and Gentlemen, Active Directory has been around for almost two decades now, and yet most organizations worldwide do not currently possess this ONE essential, fundamental and paramount cyber security capability yet. The reason they don't currently possess it is likely that they may not even know about it, and that sounds as unbelievable to me as it does to you!

If they haven't figured it out in almost TWO decades, they're not likely to figure it on their own, so let me make it easy for them.

It is ONE of the following five Active Directory Security Capabilities -
  1. Active Directory Auditing
  2. Active Directory Permissions/ACL Analysis
  3. Active Directory Effective Permissions/Access
  4. Microsoft Advanced Threat Analytics (aka ATA)
  5. <You can throw in all the latest buzzwords here e.g. Privileged Identity/Account Management, Zero Trust, blah blah etc >

Here's one FINAL hint. If you possess this ONE capability (on the right object in Active Directory,) then you can also easily turn off i.e. deactivate, disable, and/or render useless, all of the other listed security capabilities in an Active Directory deployment!


So, which ONE is it ?





Make No Mistake + Only Two Kinds of Organizations

Make no mistake about it - one simply CANNOT adequately protect anything in any Active Directory WITHOUT possessing this ONE capability, and thus one simply cannot protect the very foundation of an organization's cyber security without possessing this ONE paramount cyber security capability. It unequivocally is as remarkably simple, elemental and fundamental as this.


Thus, today there are only two kinds of organizations worldwide - those that possess this paramount cyber security capability, and those that don't. Those that don't possess this essential capability do not have the means to, and thus cannot adequately protect, their foundational Active Directory deployments, and thus by logic are provably and demonstrably vastly insecure.




My Concern - This Impacts Organizational Security Worldwide

I hope that with the hints I've provided above, organizations worldwide will finally realize what this ONE essential capability is.


More importantly, I hope that at organizations worldwide, IT personnel, Domain Admins, CISOs and CIOs realize and recognize that without possessing this ONE essential and paramount Active Directory Security capability, their $ Billion organizations may currently be operating on a highly vulnerable foundation, which is a matter so serious that it should concern all stakeholders.



The Answer

February 24, 2020 Update: Here's the answer - THIS  is the world's most important Active Directory Security Capability.


Best,
Sanjay.

Sunday, December 31, 2017

Looking Back at 2017 - An Eventful Year for Active Directory Security

Folks,

As we get ready to bid farewell to 2017, it may be fitting to recap notable happenings in Active Directory Security this year.

This appears to have been the year in which the mainstream Cyber Security community finally seems to have realized just how important and in fact paramount Active Directory Security is to cyber security worldwide, in that it appears that they may have finally realized that Active Directory is the very heart and foundation of privileged access at 85% of organizations worldwide!


I say so only because it appears to have been in this year that the following terms seem to have become mainstream cyber security buzzwords worldwide - Privileged User, Privileged Access, Domain Admins, Enterprise Admins, Mimikatz DCSync, AdminSDHolder, Active Directory ACLs, Active Directory Privilege Escalation, Sneaky Persistence in Active Directory, Stealthy Admins in Active Directory, Shadow Admins in Active Directory, Domain Controllers, Active Directory Botnets, etc. etc.



Top-10 Notable Active Directory Security Events of 2017

Here are the Top-10 most notable events in Active Directory Security this year -


  1. Since the beginning on the year, i.e. January 01, 2017, Mimikatz DCSync, an incredibly and dangerously powerful tool built by Benjamin Delpy, that can be used to instantly compromise the credentials of all Active Directory domain user accounts in an organization, including those of all privileged user accounts, has been gaining immense popularity, and appears to have become a must-have tool in every hacker, perpetrator and cyber security penetration-tester's arsenal.

  2. On May 15, 2017, the developers of BloodHound introduced version 1.3, with the objective of enhancing its ability to find privilege escalation paths in Active Directory that could help find out "Who can become Domain Admin?"  From that point on, Bloodhound, which is massively inaccurate, seems to have started becoming very popular in the hacking community.

  3. On June 08, 2017, CyberArk a Billion+ $ cyber-security company, and the self-proclaimed leader in Privileged Account Security, introduced the concept of Shadow Admins in Active Directory, as well as released a (massively inaccurate) tool called ACLight to help organizations identify all such Shadow Admins in Active Directory deployments worldwide.

  4. On June 14, 2017, Sean Metcalf, an Active Directory security enthusiast penned an entry-level post "Scanning for Active Directory Privileges and Privileged Accounts" citing that Active Directory Recon is the new hotness since attackers, Red Teamers and penetration testers have realized that control of Active Directory provides power over the organization!

  5. On July 11, 2017, Preempt, a Cyber Security announced that they had found a vulnerability in Microsoft's implementation of LDAP-S that permits the enactment of an NTLM relay attack, and in effect could allow an individual to effectively impersonate a(n already) privileged user and enact certain LDAP operations to gain privileged access. 

  6. On July 26, 2017, the developers of (massively inaccurate) BloodHound gave a presentation titled An ACE Up the Sleeve - Designing Active Directory DACL Backdoors at the famed Black Hat Conference USA 2017. This presentation at Black Hat likely played a big role in bringing Active Directory Security to the forefront of mainstream Cyber Security.

  7. Also on July 26, 2017, a second presentation on Active Directory Security at the Black Hat Conference titled The Active Directory Botnet introduced the world to a new attack technique that exploits the default access granted to all Active Directory users, to setup command and control servers within organizations worldwide. This too made waves.

  8. On September 18, 2017, Microsoft's Advanced Threat Analytics (ATA) Team penned a detailed and insightful blog post titled Active Directory Access Control List - Attacks and Defense, citing that recently there has been a lot of attention regarding the use of Active Directory ACLs for privilege escalation in Active Directory environments. Unfortunately, in doing so Microsoft inadvertently ended up revealing just how little its ATA team seems to know about the subject.

  9. On December 12, 2017, Preempt, a Cyber Security announced that they had found a flaw in Microsoft's Azure Active Directory Connect software that could allow Stealthy Admins to gain full domain control. They also suggested that organizations worldwide use their (massively inaccurate) tooling to find these Stealthy Admins in Active Directory.

  10. From January 26, 2017 through December 27, 2017, Paramount Defenses' CEO conducted Active Directory Security School for Microsoft, so that in turn Microsoft could help not just every entity mentioned in points 1- 9 above, but the whole world realize that in fact the key and the only correct way to mitigate each one of the security risks and challenges identified in points 1 - 9  above, lies in Active Directory Effective Permissions and Active Directory Effective Access.





Helping Defend Microsoft's Global Customer Base
( i.e. 85% of Business and Govt. Organizations Worldwide )

Folks, since January 01, 2017, both, as former Microsoft Program Manager for Active Directory Security and as the CEO of Paramount Defenses, I've penned 50+ insightful blog posts to help educate thousands of organizations worldwide about...


...not just the paramount importance of Active Directory Security to their foundational security, but also about how to correctly secure and defend their foundational Active Directory from every cyber security risk/challenge covered in points 1- 9 above.

This year, I ( / we) ...

  1. conducted 30-days of advanced Active Directory Security School for the $ 650+ Billion Microsoft Corporation

    Introduction, How Well Does Microsoft Understand Cyber Security, The Importance of Active Directory Security, The Impact of an Active Directory Security Breach, The Active Directory Attack Surface, The Top-5 Security Risks to Active Directory, Active Directory Privilege Escalation, An Ocean of Access Privileges, AdminSDHolder, Active Directory ACLs - Attack and Defense (Actual),  Active Directory Effective Permissions, and so many more ...


  2. showed thousands of organizations worldwide How to Render Mimikatz DCSync Useless in their Active Directory

  3. helped millions of pros (like Mr. Metcalf) worldwide learn How to Correctly Identify Privileged Users in Active Directory

  4. helped the developers of BloodHound understand How to Easily Identify Sneaky Persistence in Active Directory

  5. helped Microsoft's ATA Team learn advanced stuff About Active Directory ACLs - Actual Attack and Defense

  6. showed CyberArk, trusted by 50% of Fortune 100 CISOs, How to Correctly Identify Shadow Admins in Active Directory

  7. helped cyber security startup Preempt's experts learn How to Correctly Identify Stealthy Admins in Active Directory

  8. helped the presenters of The Active Directory Botnet learn How to Easily Solve the Problem of Active Directory Botnets

  9. helped millions of cyber security folks worldwide understand and illustrate Active Directory Privilege Escalation

  10. Most importantly, I helped thousands of organizations worldwide, including Microsoft, understand the paramount importance of Active Directory Effective Permissions and Active Directory Effective Access to Active Directory Security


In fact, we're not just providing guidance, we're uniquely empowering organizations worldwide to easily solve these challenges.





Summary

All in all, its been quite an eventful year for Active Directory Security (, and one that I saw coming over ten years ago.)

In 2017, attackers, pen-testers and defenders finally seem to have realized the importance of Active Directory Security.


Perhaps, in 2018, they'll realize that the key to Active Directory Security lies in being able to accurately determine this.

Best wishes,
Sanjay.

PS: Why I do, What I do.

Thursday, December 21, 2017

A Very Simple and Fundamental Cyber Security Question

Folks,

Today, I'd like to ask a very simple question to you all, and I do so because this too impacts cyber security worldwide.

Question - When a Cyber Security company develops, releases and promotes the use of a security product (i.e. one that potentially thousands of organizations worldwide may use and rely on to make mission-critical cyber security decisions,) irrespective of whether it may be free software or not, does the company put its credibility on the line vis-à-vis the reliability of that product?

Context: If subsequent to the release of such a security product by a company, it is found / discovered that this product is actually unreliable in that it may be delivering (substantially) inaccurate information, reliance upon which could result in thousands of organizations worldwide making inaccurate access-control decisions, which could then leave them with a false sense of security, and thus potentially vulnerable to the risk of compromise, then could such a finding impact the credibility of this company?

Potential Answers:    A) YES   or   B) NO


I'd encourage everyone to give this question a few minutes of thought.

Best wishes,
Sanjay

Wednesday, August 30, 2017

How Someone Could Launch a Massive Denial-of-Service Attack and Bring Businesses that Operate on Microsoft Active Directory to a Halt in Seconds


Folks,

This is a short post I'm penning upon the recommendation of several folks who read my last blog post. They felt that the sheer importance and impact of what was shared in that post may not have been be conveyed well enough by its title, thus this post.




How Someone Could Halt Business at Billion $ Organizations in Literally 1 Second -

Consider this. Its 9:00 am on a Monday morning at a multi-billion dollar organization. Thousands of employees show up to work, and proceed to log-on to their domain-joined Windows machines so that they can then go about their everyday work, email, etc.

There's only one little problem - no one is able to log on, and by 9:30 am its very clear that all fifty thousand (50,000) employees of this multi-billion $ organization cannot logon, and thus cannot go about their work!  In short, the business has come to a halt.


By the way, its not just employees who won't be able to logon; any and all IT services that may be running as Network Service / System on domain-joined machines and that rely on authorized access to other servers/services to work, will also stop working.

This was an especially important day for the company. It was the day they were going to announce and launch a new multi-billion $ product line, continue assisting millions of customers on a recent major issue, and announce their quarterly earnings.


Unfortunately, since no one can log on, not a leaf is
moving in the organization this Monday morning.

(Its a dark morning.)



By 12:00 noon, rumors of a "cyber breach" at the organization surface on Wall Street, and in minutes, its stock plunges 7%...


... the organization just lost a few Billion $ in market cap, and from the CEO to Shareholders everyone's shocked and worried.


By the time someone figures out what's wrong, its almost 12:30 pm. By the time the appropriate Active Directory admins are called in, and figure out what's going on and do what's needed to fix the problem, its almost 5:30 pm i.e. an entire day, lost.

Oh, and by the way, this assumes that the organization had an up-to-date backup of their foundational Active Directory. If the back-up happens to be days old or older, it could easily take many more days, if not weeks, before everything from accounts and group memberships to provisioned access etc. is effectively restored back to where it should be in their Active Directory.





So, What Happened?

By 2:30 pm, their Active Directory administrators had figured out that literally all that happened here was that ONE individual who was not even supposed to have sufficient effective permissions / effective access in their Active Directory to do so, had been able to DELETE the organization's top-level organizational unit (OU) in their Active Directory!

That's it?!


That's it!

In weeks to come, they would learn that a Junior IT Analyst who had recently become disgruntled over a petty issue with his manager, decided to prove a point, and he had been able to figure out that he had sufficient effective permissions in Active Directory so as to be able to perform a simple Delete-Tree operation on a top-level OU in the Active Directory.

So, that Monday morning, he arrived a bit early, and at 8:55 am he launched Active Directory Users and Computers, located the top-level OU in Active Directory, right-clicked and selected Delete, and within seconds over 50,000 domain user accounts, 75,000 domain computer accounts, 100,000 domain security groups etc., i.e. the entire contents of that OU, all got deleted!





So What Made This Possible?

Are you kidding me?! How could someone have caused SO much damage in literally one second, by clicking just one button?!


The answer (or rather the question's right here) - Who can Delete an Organizational Unit in Active Directory and its Impact?


Now, in light of the above, here's how thousands of organizations in the world, including Microsoft, can prevent this scenario from occurring in their IT infrastructures today - all they need to do is accurately identify (i.e. audit) who can enact this task in their Active Directory, and then proceed to revoke the access of anyone who is on that list but who should not be on that list.

The hardest part here is the former part i.e. accurately identify (i.e. audit) who can enact this task in their Active Directory, so here's trillion $ advice on how to correctly do so - How to Audit Who Can Delete an Organizational Unit in Active Directory



Alright, that'll do it for today. I just wanted to help folks worldwide, especially C-Suite folks, understand the real and profound consequences and impact to their business, of someone possessing excessive Active Directory effective permissions in their foundational Active Directory deployments. The above scenario is likely enactable at most organizations worldwide today.

Incidentally, I wouldn't even call this a "cyber breach", yet as illustrated above, its impact on business can be substantial.

Best wishes,
Sanjay


PS: If I'm shedding light on these (easily addressable) weaknesses in Active Directory (which is otherwise a highly robust and securable technology), it is only because even after 17 years of AD having shipped, organizations worldwide still remain vastly exposed to such risks, even though the probability of occurrence of such risks materializing has since increased dramatically.



PS2: If this scenario seems far-fetched, consider 3 alternatives (and I could share many more such alternatives with you):


  1. An entity hired hackers to breach the organization, who post-breach determined who had sufficient effective permissions to enact a top-OU-level deletion, then compromised the account of any one such individual to make this happen. They had also shorted the organization's stock over the past few days, and ended up making a $100 Million that morning.

  2. A lone-wolf intruder who controls at least one domain-joined machine figures out who has sufficient effective-permissions to delete a top-level OU, then uses various avenues such as using the archaic Pass-the-Hash technique to compromise one of these accounts, which then gives him/her the ability to delete this top-level OU, and then proceeds to do so. 

  3. An APT (e.g. a foreign government aided entity) writes malware designed to try and delete top-level OUs in Active Directory (whenever a user logs on to an infected machine) in the security context of whoever the currently logged-on (to an infected machine) domain-user account happens to be, and then proceeds to try and have as many computers in the target organization be infected with that specific malware. Should a sufficiently authorized individual end up logging on to their designated (but now infected) machine, the attempt will succeed.
In short, neither motive nor avenue matter as much as the need to identify and minimize who can do what in Active Directory ! (If you know that only 4 individuals in the organization can enact this privileged task, and the user accounts of these individuals are adequately protected, then irrespective of their motive or avenue, malicious entities won't be able to succeed in their efforts.)




PS3: If you have the time, you may enjoy the following which is a continuation of the above...


Who's to Blame?

In weeks to come, the organization set up a high-level committee to look into how this happened, to figure out who was to blame here, and to determine how to ensure that something like this could not ever happen again!


The #1 question that was raised was - "How did the organization's IT and Cyber Security leadership not know that this individual had sufficient access so as to be able to perform such a high-impact and privileged access operation i.e. delete a top-level OU in their Active Directory!"


Here's how the Q&A in that committee hearing went, led by the Committee's Chairman -

Chairman to CISO - "Were you aware that this individual possessed such elevated access in Active Directory?"

CISO to Chairman - "Sir, we care deeply about cyber security and this year alone, we've spent millions on cyber security. As to the security of our foundational Active Directory, I rely on our Active Directory Operations (Ops) Team to ensure its security, so perhaps I should defer the question to the Active Directory Ops Team."

Chairman to CISO - "Well, ultimately this falls under your umbrella, so and ultimately you're responsible, but okay, I will ask the Active Directory Operations Team."

Chairman to Active Directory Ops Team Director - "Were you aware of this individual having such access?"

Active Directory Ops Team Director to Chairman - "My role is managerial; I rely on our Enterprise Admins for this."

Chairman to Enterprise Admins - "Were you aware of this individual having such access?"

Enterprise Admins to Chairman - "Trying to find out who has what effective privileged access in Active Directory is very difficult. We've unsuccessfully tried do this for years. Recently, we had requested funds for the procurement of tooling that could greatly help in this vital regard, but our request was turned down due to 'lack of funds'."

A Domain Admin interjects - "Sir, actually for quite some time now, we actually didn't know that we were supposed to be determining "who has what effective permissions in Active Directory." All these years, we have been determining "who has what permissions in Active Directory" and apparently, that isn't how we're supposed to do this. We then attempted to accurately determine effective permissions in Active Directory, and realized that it is very very difficult, so we proceeded to identify tooling that could help us do so easily and accurately, thus the request to procure such tooling."

A 2nd Domain Admin interjects - "Sir, to be honest, we sort of knew we were operating in the dark, but we thought that at least we had a feature called 'Prevent object from accidental deletion' turned on, and we assumed that that would have been sufficient, but apparently not."


The Chairman, whose time is easily worth thousands of dollars per day, paused briefly, then continued...


Chairman to Enterprise Admins - "Gentlemen, how much did you need to procure such tooling that you believed could help you easily and accurately identify who has what privileged access in our foundational Active Directory for our multi-billion dollar publicly-held organization?"

Enterprise Admins to Chairman - "Sir, not much actually; I believe it was a few thousand dollars."

Chairman to Enterprise Admins - "Gentlemen, just so I understand this clearly, are you saying that if you had the appropriate tooling, you would have been able to identify that this individual had excessive privileged access, and thus could have taken steps to revoke such access, and thereby prevent this security incident from occurring?"

Enterprise Admins to Chairman - "That is correct Sir."

Chairman to Enterprise Admins (Shocked!)- "Gentlemen, do you realize that the lack of such vital cyber insight, which required only a few thousand dollars, has now cost us a few billion dollars of loss in our market cap?!"

Enterprise Admins to Chairman - <Silence>


Chairman to Enterprise Admins - "Who turned down this funding request?"

Enterprise Admins to Chairman - <Silence> (The Enterprise Admins turn to look at the AD Ops Team Director.)


Chairman to Active Directory Operations Team Director - "Who turned down this funding request?"

Active Directory Operations Team Director to Chairman- <Silence> (The Director turns to look at the CISO.)


Chairman to CISO - "Mr. CISO, Who turned down this funding request?"

CISO to Chairman - <Silence> ...


...and so it continued, and I'll let your imagination help you figure out how this all ended.


(Folks, this isn't Rocket Science. This is Cyber Security 101 and common sense, but I suppose, as they say, "Common sense isn't so common!" Even Microsoft does not seem to have fathomed the implications of possessing excessive privileged access in Active Directory, so how can we expect 1000s of organizations worldwide to know about what is likely their Achilles' Heel ?!)

Monday, July 31, 2017

A Trillion $ Question to Microsoft regarding "Identities" and Cyber Security


Dear Microsoft,

Today is Day-11 of our advanced Active Directory Security School for you, and today I'd like to ask you a very simple question that concerns the most elemental and fundamental aspect of cyber security in Windows-based networks worldwide - Identities.

Identity is fundamental to Cyber Security

Identity is an elemental and fundamental aspect of cyber security, as each one of the 3-As of cyber security i.e. Authentication, Authorization and Auditing, require the ability to be able to uniquely identify entities i.e. people, computers, service accts etc.

The importance of identities is evidenced by that fact that an entire field of IT security is devoted to it, i.e. Identity Management, and that numerous multi-million $ companies such as Ping Identity, Centrify etc. exist only to help make identities more secure.

So, ...



Identities in Windows Environments

Now, as you know, at the foundation of over 90% of all business and government organizations worldwide lies Active Directory, and in these organizations, the Identities of their employees, contractors, executives, privileged users and other stakeholders are all represented by ...

A Domain User Account in Active Directory
... none other than their  unique  Active Directory domain user accounts !

(For completeness, it must be mentioned that computers have identities too represented by their domain computer accounts, and that strictly/technically speaking, it is a domain account's Security Identifier (i.e. SID) that uniquely represents its identity.)


That's right. In Active Directory based IT infrastructures, it is domain (i.e. Active Directory) accounts that represent identities.

In fact, at thousands of organizations worldwide, it is Active Directory domain user accounts that represent corporate identities, and in Active Directory deployments worldwide, today hundreds of millions of identities are represented by these accounts.





Uniqueness Is Imperative

Now, of vital note here is that, as you know, the keyword above is unique, because the entire premise of cyber security in Active Directory based networks rests on each user having a single, irrefutably uniquely identifiable domain user account!




After all, you likely don't have two domain user accounts at Microsoft for say, Satya Nadella, right? Yes I know that to address certain needs, some users like privileged users have multiple (e.g. alt) accounts, but they are always explicitly labeled as such.

In fact, here's why it is so important that users have only (one identity, i.e.) one domain user account -
  1. Security - Uniqueness is required to eliminate ambiguity. Ensuring secure access to securable resources in a network requires that resource owners be able to uniquely identify the entities/individuals for whom access is to be specified.

  2. Accountability - Accountability necessitates uniqueness. Should a user be able to authenticate him/herself using an account other than one assigned to him/her, he/she could engage in malicious activity, such as obtaining unauthorized access to, divulging and/or destroying various IT resources, that could not be irrefutably tied/traced back to him/her.

In fact, ensuring security requires that, ideally speaking, no user (except for a known few explicitly authorized administrative personnel) must ever be in a position that provides him/her access to more than one uniquely authenticatable domain account.

Now there are generally only two ways in which one could obtain access to an additional account - 1) a user could create a new domain user account in Active Directory, or 2) a user could reset the password of an existing domain user account in Active Directory. For now, let's assume that the second way is not that important (although it is), and lets just focus on the first one.

It turns out that the seemingly simple and mundane task of being able to create domain user accounts in Active Directory is actually very important to cyber security, because, as explained above, if someone could create a domain user account in Active Directory, he/she could instantly obtain and be in possession of an additional, separate uniquely authenticable identity.

Incidentally, the very least one could do with an additional domain user account is use it to scour the entire IT network for vulnerabilities, perform network logons on to most computers, and access anything and everything (e.g. files on servers, databases, SharePoint portals, ) to which Domain Users and Authenticated Users have read access (and you would be surprised to know as to just how much these two well-knowns (-RID and -SID) have access to in most organizations today.)

Of course, a proficient individual (intruder/perpetrator) could use an alternate domain account to engage in all sorts of nefarious activities, and the smartest ones could possibly find and exploit privilege escalation paths to take over the entire network.

In fact, if you consider even just the recent critical vulnerability that you just patched i.e. CVE-2017-8563 (Windows Elevation of Privilege), note that its exploit vector too involved/required that the perpetrator create a domain user account in Active Directory!





A Simple Trillion Dollar Question -

So, in light of the above, as you'll hopefully agree, it is absolutely imperative that organizations know at all times as to exactly who can create new identities in their environment, i.e. who can create new domain user accounts in their Active Directory?!


So, and speaking of which, here's yet another a very simple Trillion dollar question for you, Microsoft -

Exactly how do/should organizations find out exactly who can create domain user accounts in their Active Directory? (and ideally also, where they can do so & how)

[ My apologies for harping on "exactly" ; it is just that when it comes to cyber security, accuracy is paramount. ] 


Make no mistake about it - organizations that do not know the answer to this most fundamental of cyber security questions concerning identity management in Windows based networks cannot be considered secure from a cyber perspective.


Now, in case this seems like a simple question, consider what it might take to accurately answer this question at an organization that may have numerous (say even 20+, if not 100s of) organizational units and containers in their Active Directory domain(s).

Here's a hint - In all likelihood, even you*, the $ 550+ Billion Microsoft, that may be spending billions to so convince the world to get on its recent Cloud offering, don't possess the ability to help organizations answer this simplest of cyber security questions.


(In light of which, this might now 
make sense, esp. paragraph 7.)


I, and the whole world, look forward to your answer.  (Also, since you're likely not going to answer it, I'll answer it on Day-12.)

Best wishes,
Sanjay


* Not just you, not a single one of dozens of multi-million/billion $ IT, cyber security, tech and defense companies focused on identity management and cyber security can help organizations answer this simple cyber security question. Well, except one.

PS: August 05, 2017 Update - I've answered the question here.

Sunday, July 30, 2017

Regarding Cyber Security, Kaspersky Labs, Russia & the U.S. Government

Folks,

In light of the recent controversy surrounding whether or not Kaspersky Labs, a Russian cyber security company's, anti-virus software should be running on computers in the U.S. Government, thought I'd re-post a recent post concerning this subject.

As you may have heard, according to Reuters, earlier this week the U.S. Congress, and specifically a U.S. Congressional Panel has asked 22 government agencies to share documents on Kaspersky Labs, saying that its products could be used to carry out "nefarious activities against the United States."

While I am not going to comment on this specific topic/issue, I just wanted to say one thing:


The only thing I will say is that the U.S. Congress and all U.S. Government Agencies, including all U.S. intelligence agencies should know that today, computer software other than Kaspersky Labs' anti-virus software, that was highly likely written in Russia and that may very likely still being supported from within Russia, is very likely still running in possibly the highest privileged security contexts across potentially many parts of the U.S. Government.


If this is true, then if someone could compromise a specific location in Russia, they could... <you can complete the sentence.>


By the way, this is neither something that we uniquely know nor is it classified information. This information is freely available in the public domain and can be easily deduced by some basic online sleuthing, by anyone with merely an Internet connection.

Interestingly, I should also mention that this very piece of computer software may also be running (for years now) in the highest privileged security context in not just the networks of the U.S. Government, but at thousands of organizations worldwide today.


Just one more thing; as a cyber security professional, I find the means by which whoever hacked the DNC and John Podesta's emails absolutely laughable - I mean what an amateur job it was, and yet its impact on global security may have been colossal.

I mean, here we worry about how someone could write a few lines of code targeting Active Directory and potentially be in a position to proverbially shut the motor of the world, (considering that the whole world runs on Active Directory,) and there some kid just phishes John Podesta into obtaining access to his Gmail account and thereby to vast amounts of private email, which he/she then purportedly passes on to WikiLeaks, who ends up releasing it in the public domain. and that according to the CIA, that ends up influencing the U.S. Election.

Finally, and I have said this before, the idea of setting up a joint cyber security unit with Russia may not be a good idea.


Before I put my pen down, let me just say, and I cannot stress one point enough - if potentially untrustworthy code is running in the highest security contexts in your IT network, it likely is not your network anymore (i.e. you're likely not the only one who has access to (and/or can access, control access to, as well as divulge, tamper and destroy) almost everything in your network.)

Best wishes,
Sanjay


PS: To the respected folks in our govt., please know that we already informed the highest cyber security officials concerning the likely presence of Russian code earlier last year. However, if there is still a need to identify it, pls let us know; we're here to help.

PS2: That's all for now. We will continue with Day-11 of our advanced Active Directory Security School for Microsoft tomorrow.


Friday, June 2, 2017

Active Directory Security is Paramount to Global Security Today (Day 2)

Folks,

Today is Day 2 of advanced Active Directory Security school for Microsoft. Today's post, albeit short and non-technical, is also very important, because the world needs to understand just how important Active Directory Security is to global security today.

From the White House to the British Houses of Parliament, and from Microsoft to the Fortune 1000, at the very foundation of IT, identity and access management, and cyber security at over 85% of all organizations worldwide today lies Active Directory.


In other words, the foundational security of thousands of government and business organizations depends on Active Directory.

To paint a picture - Governments, Militaries, Law Enforcement Agencies, Banks, Stock Exchanges, Energy Suppliers, Defense Contractors, Hospitals, Airlines, Airports, Hotels, Oil and Gas Companies, Internet, Tech and Cyber Security Companies, Manufacturing Companies, Pharmaceutical Companies, Retail Giants ... <the list is long> all run on Microsoft Active Directory.

Now imagine a scenario wherein someone is able to write and unleash malware designed to target and exploit weaknesses in and compromise foundational Active Directory deployments worldwide. Just how much damage do you think that could do?

If that's a stretch for your imagination, consider this and a much simpler scenario, wherein a perpetrator (e.g. a hacker, an APT, an insider) specifically targets and is able to compromise the Active Directory of even just a few of the world's top organizations.

Hopefully you can now see why Active Directory Security is paramount to global security today. What could be more important?


Now consider this - in almost every Active Directory deployment in the world, there exist thousands of exploitable unauthorized effective access grants, yet neither do most organizations seem to know this, nor do they possess the means to identify them.

Considering the above, one would think Microsoft would be aware of this problem, and if so, have a solution for it, for the world. Sadly, neither Microsoft nor any cyber security company on the planet has a(ny) solution to help these organizations adequately i.e. accurately and swiftly identify and eliminate the billions of unauthorized effective access grants that endanger foundational Active Directory deployments worldwide. Well, except one.

In light of the above, you may want to read Day 1's entry (a few times over, if needed) again - here.

That's all for today.

Good night,
Sanjay


PS: Responsible disclosure/picture-painting: I wouldn't have shed light on this if there was no solution. There is a solution today, and it can help the entire world address and eliminate this problem very quickly, but we can't help these organizations until they themselves first recognize, understand and acknowledge the problem, comprehend its magnitude, & then seek our assistance.

Monday, May 22, 2017

A Trillion $ Letter to Microsoft concerning Cyber Security Worldwide

[This is a letter to all my esteemed former colleagues at Microsoft Corporation, for whom I have the greatest of respect. This is Day-0 of Active Directory Security School so you may want to read it as well as the PS section below.]


Dear Microsoft,

Let me begin by saying that you're one of the world's most high-impact companies, and that I love and respect Microsoft.


I may have spent only a few years at Microsoft, but when you're working 16 hour days, so immersed and in love with what it is you do, driven by the satisfaction and adrenalin of knowing that your work impacts billions of people worldwide, it truly is an incredibly satisfying and gratifying feeling. For me, working at Microsoft was a truly memorable and incredible experience.

If I might add, as Program Manager for Active Directory Security, I was at the epicenter of cyber security in Microsoft's Windows ecosystem, and when your work directly impacts the foundational cyber security of thousands of organizations worldwide, and you get to work with and earn the respect of some of the best security folks on the planet, John Lambert, David Cross, Michael Howard, Stuart Kwan, Paul Leach, Steve Riley, Ben Smith, Scott Charney and so many others, its an indelible experience.



But this isn't about me. This is about the thousands of organizations that we (you and us) have the opportunity to impact (, and in turn the billions of people whose lives they impact,) and the responsibility to do so in a positive manner that betters their lives.



As you know, Active Directory plays a foundational and in fact a monumental role in IT and cyber security across the world, or as I like to put it - "not a leaf moves in the organizational IT and cyber security world without Active Directory being involved."


As former Microsoft Program Manager for Active Directory Security, i.e. someone who spent years on this ocean of an esoteric subject, after having moved on from Microsoft in 2005, upon taking time to reflect back, it became clear to me a decade ago that as solid as Active Directory is, it unfortunately lacks one fundamental capability, the absence of which could likely pose a huge security risk for thousands of (y)our organizational customers worldwide, in years to come.

Thus in the late 2000s, I several times dutifully brought this deficiency in Active Directory to the attention of several individuals at several levels within Microsoft. Unfortunately, for reasons know best to them, no one seemed to want to do much about it.


It is because I knew just how critical this capability would be for the world to have in years to come, that I was convinced that it had to be built. Of course, back then, I was merely an ex-Microsoftie with the mere meagre resources of an average citizen, so I knocked the doors of some of the world's biggest venture capital (VC) firms, who all were kind enough to give me an audience.
(They were Kleiner Perkins Caufield and Byers (KPCB), Greylock Partners, Sequoia Capital, and a few others in Menlo Park.)

Unfortunately [for me then :-( , and for them now :-)] they too didn't " get it ", so they respectfully passed, and wished me luck.

Speaking of luck, there's an old saying - "Luck is the residue of diligence." They (i.e. those VC firms) may not have realized that they not only turned down a former Microsoft cyber security expert, but more importantly, they turned down someone who cares deeply about doing the right thing. Perhaps they may have underestimated the power of human will.


Undeterred, I decided to do something about it myself, within my own meagre financial means. I'll spare you the details of my journey, but in short I worked four years (1,460 days) straight without earning a penny, and when I was done, I had architected and developed one of the most important cyber security capabilities and amongst the most innovative patented intellectual property on the planet, which is today formidably backed and embodied into some of the world's most innovative solutions by some of the world's most professional developers (our employees), and can today do at a button's touch, what no one else can.


As a completely unintended consequence, I ended up creating possibly the most important, relevant and valuable cyber security company on the planet, and today, not all the financial resources at the disposal of all the venture capital companies combined, could possibly compete with us. (You may not yet understand why I say so, but you'll hopefully understand it by the end of this.)


(You see, there are 100s of cyber security companies in the world today, most of whom also run on Active Directory, but not a single one of them can help accurately determine effective permissions in Active Directory. If you can find even one that can do so, on even just one Active Directory object, let alone on an entire domain comprised of 100s of 1000s of objects, let me know.

Now, in case you're wondering why being able to do so is a BIG deal, its because he/she who can accurately and efficiently determine effective permissions on the thousands of objects that reside in each Active Directory domain worldwide, ultimately holds the keys to global security ; don't worry if you don't understand this now, for you will by the time we're done with school.)

Incidentally, given the nature of what it is we so uniquely do, today we are formidably backed by an entity who understands the strategic  importance of our endeavor to the business and national security interests of the United States AND its allies.



But again, this isn't about me. This is about applying the best one is capable of, towards solving one of the most important cyber security challenges on the planet for our customers, the thousands of business and government organizations worldwide that operate Active Directory, to help them stay safe and secure. In other words, this is about you and (y)our customers worldwide.



You're not going to believe this, but imagine our surprise when after having solved arguably the biggest cyber security challenge facing Microsoft's organizational customers today, we found that hardly any of your customers seem to understand this problem!


Thus, last year, we had to bring this to the attention of the executive leadership of the Top-200 organizations worldwide, and to this day we continue to help thousands of your organizational customers understand this, for they all seem to be in the dark.

It appears that the reason most of them are in the dark is perhaps because while you were busy making a paradigm shift, you may have (completely) forgotten to provide them sufficient guidance on one of the most vital aspects of Windows Security.

I believe that it is not our burden to educate your customers about this profoundly important challenge; that's yours to do; we've done the hardest part, which is to solve it; you can do the rest. However, it appears that even you do not seem to understand it.

So, in the best interest of the foundational security of thousands of organizations worldwide, who are (y)our customers, in days to come, I'm going to most respectfully help you understand this profoundly important yet esoteric cyber security challenge.

(Also, I'm sorry if I may have been a little hard on you recently - one, two. That was only because I care deeply about everyone ; as they say, along with great power comes great responsibility, and I felt that you may inadvertently have not been living up to that. When we play such a vital & foundational role in global security, we have an obligation to do so as responsibly as we can.)




Please know that the only reason I'm doing so is so that you can help your customers understand this problem, because we worry greatly that if they don't understand this soon, the not-so-good folks out there could seriously endanger their security.

In fact, considering that 100% of all major recent cyber security breaches involved the compromise and misuse of a single Active Directory privileged user account, organizations that ignore The Paramount Brief may be doing so at their own peril.

(Also and most pertinently, as credential-theft attacks (e.g. Pass-the-Hash, Kerberos Golden Tickets etc.) become harder to enact, perpetrators are shifting their efforts towards directly attacking Active Directory, a fact concretely evidenced by Mimikatz DCSync, which leverages unauthorized / excessive effective permissions in Active Directory to compromise all credentials.)

Thus, I hope that once you understand this risk, you'll see why you need to help organizations worldwide understand it ASAP.


In conclusion, I've been one of you; I represent what every responsible, hard-working individual who passionately believes in solving a problem for the world is capable of, and once you understand this esoteric challenge, you'll realize that I (and today we) have done more to help safeguard the cyber security of Microsoft's global organizational customer base than any other entity (individual or company) on the planet, and that the world needs our combined help and guidance, so in your own (ecosystem's) interest, I hope you'll listen most intently and respectfully to what I have to say in days to come.

Thank you very much.

Most Respectfully,
Sanjay


PS: Active Directory Security School: Today was supposed to be Day-1 of Active Directory Security School, but I decided to make June 2017 Active Directory Security Awareness Month, so I figured it might be best to hold school from June 01 to June 30, 2017. So, the official Day-1 of School will start right here on June 01, 2017.  Until then, you may want to read this.