Ransomware Attack on Identity and Access Management Framework
Once simple explanation of hierarchy within Active Directory is Creation of Forest (Company), then creating Domains under a Forest, in each Domain there are Domain Controllers that in turn manage Groups and Users, which enable the organization to manage its Role-Based Access.
So, for Ransomware Attacks to use Active Directory as a medium towards gaining un-authorized access, it requires privileged access to directory. Majorly, it has been observed that organization manage privileged access Active Directory accounts in a way, if a resource has left the company and it is not de-provisioned from directory, thus still having access to various security groups. Hence, such users with privileged access serve as a gateway for these Ransomware Attacks to propagate throughout machines. Even in cases, where IT staff has gone extra mile to protect domain controllers within organization, Hackers can get access via User connected to Active Directory. Thus, it’s important to follow the best practices for Active Directory maintenance.
As per Microsoft,
“To a hacker, an infected or stolen identity is measurable in two ways: the breadth of computers that trust and grant authorization to the account and the level of authorization granted upon successful authentication. Since encryption can be performed by any user account, ransomware benefits most when it infects an account which can convey write authorization to a large amount of data.”
https://www.imanami.com/how-ransomware-attacks-on-active-directory-and-azure-ad/
0 comments
[ 38.3 ms ] story [ 195 ms ] threadNo comments yet.