The Security Blog
Get up-to-date security insights, tips, and tricks from our amazing team sent to your inbox.

Browse our blogs
We cover it all in The Security Blog. Discover what you’ve been looking for.

ARP Around and Find Out: Hijacking GPO UNC Paths for Code Execution and NTLM Relay
TL;DR - If you have WriteGPLink on an Active Directory Organizational Unit (OU) and you’re on the same network segment as a computer within that OU, you can…

LDAP Channel Binding and LDAP Signing
Want stronger LDAP security without breaking production? In this blog, we cover LDAP Signing and Channel Binding, what Server 2025 changes, and why you should…

Adventures in Primary Group Behavior, Reporting, and Exploitation
Not all AD group membership is created equal. In this blog, we explore how the primaryGroupID attribute can be abused to hide privileges as well as how teams…

Limiting Domain Controller Attack Surface: Why Less Services, Less Software, Less Agents = Less Exposure
Before we dive in, let’s get all the TrustedSec Certified Absolutes out of the way:All software presents some level of inherent risk.Only required software…

Holy Shuck! Weaponizing NTLM Hashes as a Wordlist
Password reuse is common in Active Directory (AD). From an attacker’s perspective, it is a reliable path to lateral movement or privilege escalation. Most IT…

WSUS Is SUS: NTLM Relay Attacks in Plain Sight
Even with HTTPS, WSUS can be abused if attackers obtain a trusted certificate, enabling authentication relay. In this blog, we explain how WSUS traffic can be…

Exploring NTDS.dit – Part 1: Cracking the Surface with DIT Explorer
NTDS.dit is the file housing the data for Windows Active Directory (AD). In this blog post, I’ll be diving into how the file is organized. I’ll also be walking…

A Hitch-Hacker's Guide To DACL-Based Detections - The Addendum
This blog was co-authored by TAC Practice Lead Megan Nilsen and Andrew Schwartz.1 IntroductionLast year, Andrew and I posted a four (4) part blog series…

A Hitch-hacker's Guide to DACL-Based Detections (Part 3)
Configuring a SACL to prevent unauthorized changes to Active Directory attributes, enabling auditing and monitoring for potential attacks, and detecting…

A Hitch-hacker's Guide to DACL-Based Detections (Part 2)
This blog series was co-authored by Security Consultant Megan Nilsen and TAC Practice Lead Andrew Schwartz.1 IntroductionThis is a continuation of A…

A Hitch-hacker's Guide to DACL-Based Detections (Part 1B)
Here is a meta description summarizing the key benefits and value proposition of this webpage, within the 150-160 character limit:
Detecting Windows SACL…

A Hitch-hacker's Guide to DACL-Based Detections (Part 1A)
blue team
Loading...