Məzmuna keç
7/24 Təcili Cavab Xətti
az
Xidmətlər
Həllər
Tədqiqat
Şirkət
AlətlərTrust Center

24 sentyabr 2026Texniki Məqalələr

Active Directory-də ən çox rastlaşdığımız 10 hücum yolu

The road to domain admin rarely runs through one critical flaw. It usually runs through small misconfigurations chained together.

2 dəq oxuma

Bu məzmun hazırda yalnız ingilis dilində təqdim olunur.

Why Active Directory, still?

Active Directory remains the identity and privilege backbone of most organizations. Accounts, exceptions and legacy settings accumulated over the years give attackers paths from a single user account to the entire domain.

The list below summarizes the paths we meet in internal network tests and red team engagements, together with fixes.

Ten attack paths

Attack pathWhy it worksFix
KerberoastingPasswords of service accounts with SPNs can be cracked offline.Use gMSA; 25+ character passwords and AES for service accounts
AS-REP roastingHashes can be requested for accounts without pre-authentication.Remove the DONT_REQ_PREAUTH flag
Unconstrained delegationTGTs of admins connecting to the server can be captured.Move to constrained delegation; mark sensitive accounts as non-delegable
RBCD abuseWrite access to a computer object leads to admin on that machine.Set MachineAccountQuota to 0; audit object ACLs
AD CS ESC1Templates where the enrollee supplies the subject issue certificates for anyone.Disable “Supply in request”; require manager approval
AD CS ESC8 / NTLM relayRelaying NTLM to web enrollment yields a DC certificate.Enforce EPA and HTTPS on Web Enrollment; restrict NTLM
LLMNR / NBT-NS poisoningName resolution fallbacks leak credentials.Disable LLMNR and NBT-NS via GPO; require SMB signing
DCSync rightsReplication rights on non-DC accounts expose every hash.Audit Replicating Directory Changes rights regularly
Local admin password reuseThe same password everywhere enables lateral movement.Enable Windows LAPS on all endpoints
Exposed admin sessionsTier 0 accounts logging on to workstations leave credentials behind.Tiering model, PAWs and the Protected Users group

Where to start

  1. 01

    Visibility

    Map privilege relationships with an attack path analysis tool and identify your Tier 0 assets.

  2. 02

    Quick wins

    Disabling LLMNR/NBT-NS, requiring SMB signing and deploying LAPS break the first link of most chains.

  3. 03

    Certificate services

    Review AD CS templates — the most critical paths increasingly run through them.

  4. 04

    Monitoring

    Write detections for Kerberoasting, DCSync and certificate requests.

To have your environment analyzed from an attacker’s perspective, see our Active Directory Security service.

Əhatəni birlikdə müəyyən edək.

Ehtiyacınızı bildirin — mütəxəssislərimiz sizə xüsusi təklif hazırlasın.

Bütün tədqiqatlar