Top Banner
The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager, Microsoft ATA, @TalBeerySec Marina Simakov, Security Researcher, Microsoft ATA
56

The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Mar 13, 2018

Download

Documents

vanquynh
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

The Enemy Within: Stopping Advanced Attacks

Against Local Users

Tal Be’ery, Sr. Security Research Manager, Microsoft ATA, @TalBeerySecMarina Simakov, Security Researcher, Microsoft ATA

Page 2: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 3: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 4: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 5: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Intro

Page 6: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 7: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 8: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 9: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 10: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

• Authentication

• Authorization

DC

waza1234/

LSASS (NTLM)

NTLM(rc4_hmac_nt)

cc36cf7a8514893efccd332446158b1a

User

Server① Negotiate

③ Response

② Challenge

⑥ Auth verified

Page 11: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 12: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

waza1234/

des_cbc_md5 f8fd987fa7153185

LSASS (kerberos)

rc4_hmac_nt(NTLM/md4)

cc36cf7a8514893efccd332446158b1a

aes128_hmac8451bb37aa6d7ce3d2a5c2d24d317af3

aes256_hmac

1a7ddce7264573ae1f498ff41614cc78001cbf6e3142857cce2

566ce74a7f25b

DC

DC

TGT

TGS

③ TGS-REQ (Server)

④ TGS-REP

⑤ UsageUser

Server

Page 13: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 14: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 15: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 16: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 17: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 18: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

“When the Cyber Kill-Chain Met Local Users”

Page 19: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Group:

IT

Admins

User:

Bob

Computer:

Server1

User:

Mary

Group:

Domain

Admins

http://www.slideshare.net/AndyRobbins3/six-degrees-of-

domain-admin-bloodhound-at-def-con-24

Page 20: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 21: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 22: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 23: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

https://www.safety.com/wp-content/uploads/2012/12/Burglar-Entry-300x300.jpg

Page 24: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 25: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 26: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 27: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 28: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 29: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Admin Recon

Page 30: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 31: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 32: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 33: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 35: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Defending

Page 36: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 37: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 38: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 39: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 40: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 41: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 42: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 43: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 44: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 45: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 46: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 47: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

http://s1206.photobucket.com/user/harbottle1/media/Posters%202/LocalHeroQuad.jpg.html

Page 48: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Parting Thoughts

Page 49: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 50: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 51: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 52: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Win version Who can query SAMR by default Can default be changed

< Win10 Any domain user No

Win10 Any domain user Yes (only via registry)

> Win10 (e.g.

anniversary)

Only local administrators Yes (registry or GPO)

Page 53: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 54: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 55: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 56: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,