Forum Discussion
Jason Wilson
Apr 18, 2018Former Employee
New Blog: Azure Advanced Threat Protection - CredSSP Exploit Analysis
After announcing the release of Azure Advanced Threat Protection (Azure ATP) last month, we are excited to provide details on how Azure ATP has been updated to better protect customers against a new ...
Ammar Hasayen
Apr 22, 2018Iron Contributor
In Azure ATP, you can see lateral movement maps giving you an idea how hackers can move from hop to hop to reach sensitive accounts.
My question, how can Azure ATP know that if John has a compromised identity, that he can access that TS because he is member of this group. How Azure ATP can know who is the administrators group on servers to do such simulation and map? because when John gets his TGT, it has list of what groups he is member of, and not a list of servers that those groups are set as administrates.