3 ms·
The gist of it is gathering credentials from the initialy compromised machines, and using them to access other computers on the network. A lot of this is possib
by DownGoat 7y ago
The gist of it is gathering credentials from the initialy compromised machines, and using them to access other computers on the network. A lot of this is possible because of the way Windows handles authentication between computers. Mimikatz is a tool that really made this method of lateral movement much easier for attackers, and Microsoft has been slow to adapt defences. Over time the attackers will eventually gather some admin credentials, and then it is really game over.
It is hard to defend against, unless you want a system that constantly prompts you for your password everytime you want to do something. Frequent password prompts is not really good for security either. Current mitigations really just slow down the attacks and gives you time to respond. If they are left alone they will manage to gather credentials over time.
https://github.com/gentilkiwi/mimikatz https://github.com/gentilkiwi/mimikatz
https://www.sans.org/reading-room/whitepapers/detection/mimikatz-overview-defenses-detection-36780 https://www.sans.org/reading-room/whitepapers/detection/mimi...
- mox1 7y agoThe "mimikatz" problem (aka memory protections on the lsass.exe process) has basically been solved by Microsoft, they call it "Credential Guard". It works by doing some trusted boot stuff and using the hyper-v hypervisor to protect certain regions of memory from even the OS itself. It's pretty complicated and requires server 2016 or windows 10. More info here - https://docs.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard https://docs.microsoft.com/en-us/windows/security/identity-p...
- Stierlitz 7y ago@mox1: ‘The "mimikatz" problem (aka memory protections on the lsass.exe process) has basically been solved by Microsoft, they call it "Credential Guard". It works by doing some trusted boot stuff and using the hyper-v hypervisor to protect certain regions of memory from even the OS itself.’ How about running the OS in a Virtual Machine, that evaporates on exit and you get a new clean image on each invocation. “All the King's horses and all the King's men couldn't put Humpty together again”