4 ms·
Most ransomware attacks involve windows domains. The chain of events is usually: land a beach head (perimeter vuln or phishing), find domain admin with bloodhou
by ericalexander0 5y ago
Most ransomware attacks involve windows domains. The chain of events is usually: land a beach head (perimeter vuln or phishing), find domain admin with bloodhound or similar, steal domain admin creds with mimikatz or similar, encrypt everything.
There's multiple points in that chain to address. You'll get the most leverage by reducing domain admin population size through privileged access management.
Tool to help understand the problem: https://github.com/ericalexanderorg/easyhound https://github.com/ericalexanderorg/easyhound