高级 Active Directory 到 Entra ID 横向移动技术.pdf

编号:981951 PDF 85页 4.96MB 下载积分:VIP专享
下载报告请您先登录!

高级 Active Directory 到 Entra ID 横向移动技术.pdf

1、#BHUSA BlackHatEventsAdvanced Active Directory to Entra ID Advanced Active Directory to Entra ID lateral movement techniqueslateral movement techniquesDirk-jan MollemaAbout me Dirk-jan Mollema From The Hague,Netherlands Hacker/Researcher/Founder/Trainer Outsider Security Talks at Black Hat/DEF CON/B

2、lueHat/Troopers/x33fcon Author of several Active Directory and Entra ID toolsmitm6ldapdomaindumpadidnsdumpBloodHound.pyntlmrelayx/krbrelayxROADtoolsSocials Blog/talks:dirkjanm.ioTwitter/X:_dirkjanBlueSky:dirkjanm.ioAgenda Domains in AD and in Entra ID Existing hybrid attacks Policies ExchangeDomains

3、Domains in AD vs Entra Domains in Active Directory Are logical containers with their own structure.Are part of a forest of one or multiple domains,which acts as the security boundary.In Entra ID Domains are custom domains that you can use for sending email or as a suffix for userPrincipalNames.Entra

4、 has a flat structure,which means there is no difference between users in one domain versus another domain.Domains in hybrid AD/Entra ID We can sync multiple AD domains/forests to the same tenant.All users from these domains will be“pooled”together in Entra ID.However,we can configure authentication

5、(managed/federated)on a per domain basis.This is what confuses people(including me).In Entra ID,there is no boundary between different custom domains.However,there is a difference between synced accounts and“cloud-only”accounts.Entra ID hybrid setupMicrosoft Entra Tenant identity layerDomain 1Domain

6、 2Managed(PHS)Federated(AD FS)AD DS 1AD DS 2Entra IDOn-premisesSyncSyncAuthDomain 3Domain NEntra ID hybrid attacks from ADEntra ID cloud only usersManaged(PHS)Federated(AD FS)AD DS 1AD DS 2Entra IDOn-premisesSyncSyncIssue auth tokensEntra ID hybrid usersDomain 1Domain 2Write passwordHybrid domain co

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(高级 Active Directory 到 Entra ID 横向移动技术.pdf)为本站 (竿头日上) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠