Skip to Main Content

The Security Blog

Get up-to-date security insights, tips, and tricks from our amazing team sent to your inbox.

Browse our blogs

We cover it all in The Security Blog. Discover what you’ve been looking for.

Topics
Author
Blog February 20 2025

Exploring NTDS.dit – Part 1: Cracking the Surface with DIT Explorer

NTDS.dit is the file housing the data for Windows Active Directory (AD). In this blog post, I’ll be diving into how the file is organized. I’ll also be walking…

Read about this article
Blog April 09 2024

A Hitch-Hacker's Guide To DACL-Based Detections - The Addendum

 This blog was co-authored by TAC Practice Lead Megan Nilsen and Andrew Schwartz.1    IntroductionLast year, Andrew and I posted a four (4) part blog series…

Read about this article
Blog October 17 2023

A Hitch-hacker's Guide to DACL-Based Detections (Part 3)

Configuring a SACL to prevent unauthorized changes to Active Directory attributes, enabling auditing and monitoring for potential attacks, and detecting…

Read about this article
Blog October 12 2023

A Hitch-hacker's Guide to DACL-Based Detections (Part 2)

This blog series was co-authored by Security Consultant Megan Nilsen and TAC Practice Lead Andrew Schwartz.1    IntroductionThis is a continuation of A…

Read about this article
Blog October 11 2023

A Hitch-hacker's Guide to DACL-Based Detections (Part 1B)

Here is a meta description summarizing the key benefits and value proposition of this webpage, within the 150-160 character limit:

Detecting Windows SACL…

Read about this article
Blog October 10 2023

A Hitch-hacker's Guide to DACL-Based Detections (Part 1A)

blue team

Read about this article
Blog February 09 2023

Azure AD Kerberos Tickets: Pivoting to the Cloud

Compromising an Azure cloud presence via machine account SSO is possible, allowing attackers to impersonate any account without MFA, using compromised service…

Read about this article
Blog January 17 2023

2023 Resolutions for Script Kiddies

Don't rely on being alt, use multifactor authentication and stay current with software updates to protect against evolving threats in 2023.

Read about this article
Blog December 06 2022

More Active Directory for Script Kiddies

Learn how to easily exploit Active Directory for Script Kiddies, a guide to AD enumeration and hacking tools, with TrustedSec.

Read about this article
Blog November 10 2022

Active Directory for Script Kiddies

Introduction It seems like all these corporate types are using Active Directory. What is this “Active Directory”? And how can I use it to make my job as a…

Read about this article
Blog September 20 2022

I Wanna Go Fast, Really Fast, like (Kerberos) FAST

Testing and verifying the effectiveness of Kerberos FAST for protection against offline dictionary attacks, a critical security feature for a defense-in-depth…

Read about this article
Blog January 06 2022

An 'Attack Path' Mapping Approach to CVEs 2021-42287 and 2021-42278

Detect and prevent Windows attack paths using Splunk SPL queries for proactive and reactive defensive operations, including creating new computer accounts,…

Read about this article