Forum Discussion

Ammar Hasayen's avatar
Ammar Hasayen
Iron Contributor
Apr 23, 2018

Azure ATP lateral Movement

Hi everyone,

 

In Azure ATP,  you can see lateral movement maps giving you an idea how hackers can move from hop to hop to reach sensitive accounts.

 

My question, how can Azure ATP know that if John has a compromised identity, that he can access that TS because he is member of this group. How Azure ATP can know who is the administrators group on servers to do such simulation and map? because when John gets his TGT, it has list of what groups he is member of, and not a list of servers that those groups are set as administrates.

Resources