Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Recertifying Active Directory Certificate Services

Black Hat via YouTube

Overview

Explore the security implications of Microsoft's Active Directory Certificate Services (AD CS) in this Black Hat conference talk. Delve into the often-overlooked aspects of AD CS, including its potential for credential theft, machine persistence, domain escalation, and subtle domain persistence. Learn about certificate request processes, client authentication methods, and malicious certificate enrollments. Discover escalation scenarios, NTLM relay attacks, and golden certificate techniques. Gain insights into defensive strategies, including how to protect and audit AD CS implementations. Understand high-level architecture guidance and incident response procedures for AD CS-related security issues. Equip yourself with hunting techniques to identify and mitigate potential threats in your AD CS environment.

Syllabus

Introduction
Agenda
Background
Request a Certificate
Certificate Template
Client Authentication
Subject Alternative Name
Authentication to Active Directory
malicious certificate enrollments
Certify
Defenses
Escalation scenarios
Certificate templates
NTLM relay
How to protect
How to audit
Audit the NT auth certificates object
Golden certificates
Hunting techniques
Highlevel architecture guidance
Incident response

Taught by

Black Hat

Reviews

Start your review of Recertifying Active Directory Certificate Services

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.