56
The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager, Microsoft ATA, @TalBeerySec Marina Simakov, Security Researcher, Microsoft ATA

The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Embed Size (px)

Citation preview

Page 1: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

The Enemy Within: Stopping Advanced Attacks

Against Local Users

Tal Be’ery, Sr. Security Research Manager, Microsoft ATA, @TalBeerySecMarina Simakov, Security Researcher, Microsoft ATA

Page 2: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 3: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 4: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 5: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Intro

Page 6: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 7: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 8: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 9: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 10: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

• Authentication

• Authorization

DC

waza1234/

LSASS (NTLM)

NTLM(rc4_hmac_nt)

cc36cf7a8514893efccd332446158b1a

User

Server① Negotiate

③ Response

② Challenge

⑥ Auth verified

Page 11: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 12: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

waza1234/

des_cbc_md5 f8fd987fa7153185

LSASS (kerberos)

rc4_hmac_nt(NTLM/md4)

cc36cf7a8514893efccd332446158b1a

aes128_hmac8451bb37aa6d7ce3d2a5c2d24d317af3

aes256_hmac

1a7ddce7264573ae1f498ff41614cc78001cbf6e3142857cce2

566ce74a7f25b

DC

DC

TGT

TGS

③ TGS-REQ (Server)

④ TGS-REP

⑤ UsageUser

Server

Page 13: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 14: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 15: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 16: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 17: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 18: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

“When the Cyber Kill-Chain Met Local Users”

Page 19: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Group:

IT

Admins

User:

Bob

Computer:

Server1

User:

Mary

Group:

Domain

Admins

http://www.slideshare.net/AndyRobbins3/six-degrees-of-

domain-admin-bloodhound-at-def-con-24

Page 20: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 21: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 22: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 23: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

https://www.safety.com/wp-content/uploads/2012/12/Burglar-Entry-300x300.jpg

Page 24: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 25: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 26: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 27: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 28: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 29: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Admin Recon

Page 30: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 31: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 32: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 33: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 35: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Defending

Page 36: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 37: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 38: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 39: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 40: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 41: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 42: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 43: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 44: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 45: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 46: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 47: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

http://s1206.photobucket.com/user/harbottle1/media/Posters%202/LocalHeroQuad.jpg.html

Page 48: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Parting Thoughts

Page 49: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 50: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 51: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 52: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,

Win version Who can query SAMR by default Can default be changed

< Win10 Any domain user No

Win10 Any domain user Yes (only via registry)

> Win10 (e.g.

anniversary)

Only local administrators Yes (registry or GPO)

Page 53: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 54: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 55: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,
Page 56: The Enemy Within: Stopping Advanced Attacks … Kit/BlueHat IL Decks...The Enemy Within: Stopping Advanced Attacks Against Local Users Tal Be’ery, Sr. Security Research Manager,