BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Don’t be trusted: Active Directory trust attacks\n
    When: Sunday\, Aug 14\, 10:00 - 10:45 PDT\n   Where: Flamingo - Sunset-
 Scenic Ballroom (Adversary Village) - [1]Map\n   Speakers:Jonas Bülow Knu
 dsen\,Martin Sohn Christensen\n\n   SpeakerBio:Jonas Bülow Knudsen\n   Jo
 nas is a passionate Active Directory security professional. At\n   Improse
 c\, Jonas got experience as an AD hardening consultant helping\n   organiz
 ations remediate their vulnerabilities and misconfiguration in\n   and aro
 und Active Directory. This work included Windows OS hardening\,\n   clean-
 up in AD\, and the AD tier model implementation. Additionally\, he\n   wor
 ked in incident response for a period\, again focusing on AD. In\n   Sprin
 g 2021\, Jonas published a FOSS tool called ImproHound\, which is a\n   to
 ol to identify the attack paths in breaking AD tiering\, using\n   BloodHo
 und: [2]https://github.com/improsec/ImproHound. ImproHound was\n   present
 ed at DEF CON 29 Adversary Village: [3]https://www.youtube.com/watch?v=MTs
 PTI7OoqM.\n   Jonas recently joined the BloodHound Enterprise team at Spec
 terOps as\n   Technical Account Manager to help organizations identify and
  remediate\n   attack paths in Active Directory and Azure.\n   Twitter: [4
 ]@jonas_b_k\n\n   SpeakerBio:Martin Sohn Christensen\n   Martin Sohn Chris
 tensen \,Martin is a security consultant at Improsec\,\n   a pragmatic sec
 urity consulting firm in Denmark. With a background in\n   Windows IT oper
 ations\, he has pivoted to security in mainly Windows\n   and Active Direc
 tory where he performs offence\, analysis\, and\n   assessments. Although 
 new to the industry\, both his security passion\n   and knowledge is stron
 g because of a desire to understand concepts\,\n   technologies\, and prob
 lems to their core. He enjoys researching\, brain\n   sharing\, and solvin
 g hard problems in a team.\n   Twitter: [5]@martinsohndk\n\n   Description
 :\n   Not understanding Active Directory domain- and forest trusts can be 
 a\n   big risk. We often have to stress\, to quote from Microsoft: “the\
 n   forest (not the domain) is the security boundary in an Active\n   Dire
 ctory implementation”. This means that any compromised child\n   domain 
 could result in a compromised root domain. But why is it so? We\n   guesse
 d the answer must be because of the attack/technique known as\n   Access T
 oken Manipulation: SID-History Injection\, which enable a\n   Domain Admin
  of a child domain to escalate to Enterprise Admin and\n   gain full contr
 ol of the forest. The attack can be mitigated by\n   enabling SID filterin
 g on the trust relationship\, but it is not\n   enabled by default for int
 ra-forest domain trusts. SID Filtering is\n   however enabled for inter-fo
 rest trusts by default\, as Microsoft\n   explains: “SID filtering helps
  prevent malicious users with\n   administrative credentials in a trusted 
 forest from taking control of\n   a trusting forest”.\n\n   What is inte
 resting is that SID filtering can be enabled on\n   intra-forest domain tr
 ust as well and in theory prevent the\n   SID-History injection technique.
  This posed the question – could SID\n   filtering make the domain a sec
 urity boundary? Our talk will take the\n   audience through our research o
 n this question. We will demonstrate\n   typical trust attacks\, how they 
 can be mitigated\, and present our SID\n   filtering research including ne
 w techniques we discovered that make\n   intra-forest SID filtering obsole
 te. Finally\, we will explain and\n   demonstrate a trust attack technique
  for moving from a TRUSTING domain\n   to a TRUSTED domain (opposite direc
 tion of other trust attacks) which\n   works even over one-way forest trus
 ts (thereby breaking both\n   Microsoft’s “forest is security boundary
 ” statement and the\n   “Red Forest”/ESAE design). Deep knowledge of
  Kerberos\n   authentication is not necessary as the attacks are of low co
 mplexity\,\n   but a basic understanding of the protocol is an advantage. 
 Attacks\n   will be demonstrated using living-off-the-land tools and FOSS 
 tools\n   like Mimikatz and Rubeus. The talk is a summary of our work publ
 ished\n   in the “SID filter as security boundary between domains?” bl
 og\n   post series where part 1 explains Kerberos authentication between\n
    domains: [6]https://improsec.com/tech-blog/o83i79jgzk65bbwn1fwib1ela0rl
 2d\n\n   '\n\n   1. https://defcon.outel.org/consolidated_page.html#Flamin
 goThirdFloor\n   2. https://github.com/improsec/ImproHound.\n   3. https:/
 /www.youtube.com/watch?v=MTsPTI7OoqM.\n   4. https://twitter.com/jonas_b_k
 \n   5. https://twitter.com/martinsohndk\n   6. https://improsec.com/tech-
 blog/o83i79jgzk65bbwn1fwib1ela0rl2d\n\n\n
DTEND:20220814T174500Z
DTSTART:20220814T170000Z
LOCATION:AVV - Flamingo - Sunset-Scenic Ballroom (Adversary Village)
SUMMARY:Don’t be trusted: Active Directory trust attacks
END:VEVENT
END:VCALENDAR
