YoVDO

Red Team Revenge - Attacking Microsoft ATA

Offered By: 44CON Information Security Conference via YouTube

Tags

44CON Courses Cybersecurity Courses Penetration Testing Courses Threat Detection Courses

Course Description

Overview

Explore advanced techniques for attacking Microsoft Advanced Threat Analytics (ATA) in this 53-minute conference talk from 44CON 2017. Delve into the inner workings of ATA, a defense platform that monitors various data sources to detect security threats. Learn about ATA's capabilities in identifying common attacks like Pass-the-Hash, Pass-the-Ticket, and Golden Ticket. Discover methods to identify and exploit ATA installations, including strategies to suppress alerts, exempt specific identities from detection, and remotely control or cripple ATA. Gain insights into the noise levels associated with attacking ATA and understand its limitations. The presentation covers topics such as SPN scanning, AES key manipulation, false event generation, and MongoDB backend exploitation. Conclude with a discussion on ATA's limitations and how to detect its presence in a network.

Syllabus

Introduction
About Nikhil
What is ATA
Threats of Interest
Avoiding ATA Detection
SPN Scanning
AES Keys
False Events
Golden Ticket
AES Key Bypass
Ticket Lifetime
MongoDB Backend
Change attribution
Defense
Limitations of ATA
How to detect ATA
Limitations
Conclusion


Taught by

44CON Information Security Conference

Related Courses

Network Security
Georgia Institute of Technology via Udacity
Proactive Computer Security
University of Colorado System via Coursera
Identifying, Monitoring, and Analyzing Risk and Incident Response and Recovery
(ISC)² via Coursera
Hacker101
HackerOne via Independent
CNIT 127: Exploit Development
CNIT - City College of San Francisco via Independent