Recertifying Active Directory Certificate Services
Offered By: Black Hat via YouTube
Course Description
Overview
Explore the security implications of Microsoft's Active Directory Certificate Services (AD CS) in this Black Hat conference talk. Delve into the often-overlooked aspects of AD CS, including its potential for credential theft, machine persistence, domain escalation, and subtle domain persistence. Learn about certificate request processes, client authentication methods, and malicious certificate enrollments. Discover escalation scenarios, NTLM relay attacks, and golden certificate techniques. Gain insights into defensive strategies, including how to protect and audit AD CS implementations. Understand high-level architecture guidance and incident response procedures for AD CS-related security issues. Equip yourself with hunting techniques to identify and mitigate potential threats in your AD CS environment.
Syllabus
Introduction
Agenda
Background
Request a Certificate
Certificate Template
Client Authentication
Subject Alternative Name
Authentication to Active Directory
malicious certificate enrollments
Certify
Defenses
Escalation scenarios
Certificate templates
NTLM relay
How to protect
How to audit
Audit the NT auth certificates object
Golden certificates
Hunting techniques
Highlevel architecture guidance
Incident response
Taught by
Black Hat
Related Courses
Inglés Empresarial: Finanzas y EconomíaArizona State University via Coursera Business English: Finance and Economics
Arizona State University via Coursera 商务英语课程:财经英语 Finance & Economics
Arizona State University via Coursera Securing Data in Azure and SQL Server
Microsoft via edX Budgeting and Finance for Public Libraries
University of Michigan via edX