Apr 22 2018
11:50 PM
- last edited on
Nov 30 2021
10:09 AM
by
TechCommunityAP
Apr 22 2018
11:50 PM
- last edited on
Nov 30 2021
10:09 AM
by
TechCommunityAP
Hi everyone,
In Azure ATP, you can see lateral movement maps giving you an idea how hackers can move from hop to hop to reach sensitive accounts.
My question, how can Azure ATP know that if John has a compromised identity, that he can access that TS because he is member of this group. How Azure ATP can know who is the administrators group on servers to do such simulation and map? because when John gets his TGT, it has list of what groups he is member of, and not a list of servers that those groups are set as administrates.
Apr 23 2018 12:54 AM
SolutionThe Sensor can query endpoints for local administrators group membership.
(Giving that you allowed it as the documentation requests)
https://docs.microsoft.com/en-us/advanced-threat-analytics/install-ata-step9-samr
Apr 23 2018 12:54 AM
SolutionThe Sensor can query endpoints for local administrators group membership.
(Giving that you allowed it as the documentation requests)
https://docs.microsoft.com/en-us/advanced-threat-analytics/install-ata-step9-samr