OPS104 Securing SMB from within and without

%3CLINGO-SUB%20id%3D%22lingo-sub-2177429%22%20slang%3D%22en-US%22%3EOPS104%20Securing%20SMB%20from%20within%20and%20without%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2177429%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20this%20session%2C%20Ned%20Pyle%20discuss%20how%20widely%20the%20SMB%20protocol%20is%20used%20on%20Windows%2C%20Windows%20Server%20and%20in%20Microsoft%20Azure.%20Learn%20specific%20strategies%20to%20secure%20it%20from%20lateral%20movement%20and%20interception%20attacks.%20%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%20style%3D%22color%3A%20%23008000%3B%22%3E%E2%9C%94%3C%2FSPAN%3E%20Resources%3A%20%3CBR%20%2F%3EIT%20Ops%20Talks%20Hybrid%20Event%3A%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FITOpsTalks%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Faka.ms%2FITOpsTalks%20%3C%2FA%3E%3CBR%20%2F%3EIT%20Ops%20Talks%20Community%20Chat%3A%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FOPS104-chat%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Faka.ms%2FOPS104-chat%20%3C%2FA%3E%3CBR%20%2F%3EAbout%20SMB%20over%20QUIC%3A%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FSMBoverQUIC-Mar20Blog%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Faka.ms%2FSMBoverQUIC-Mar20Blog%20%3C%2FA%3E%3CBR%20%2F%3ESMB%20Interception%20Defense%3A%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Fsmbinterceptiondefense%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Faka.ms%2Fsmbinterceptiondefense%20%3C%2FA%3E%3CBR%20%2F%3EBeyond%20the%20Edge%3A%20How%20to%20Secure%20SMB%20Traffic%20in%20Windows%3A%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Fsmbtrafficcontrol%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Faka.ms%2Fsmbtrafficcontrol%20%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3ETo%20watch%20more%20sessions%20from%20the%20IT%20Ops%20Talks%3A%20All%20Things%20Hybrid%20event%20check%20out%20our%20playlist%3A%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fplaylist%3Flist...%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fwww.youtube.com%2Fplaylist%3Flist...%20%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EChapters%3A%3CBR%20%2F%3E00%3A00%20Introduction%3CBR%20%2F%3E02%3A32%20SMB%20is%20everywhere%3CBR%20%2F%3E06%3A00%20Distributed%20system%20defense%20is%20hard%2C%20not%20impossible%3CBR%20%2F%3E07%3A51%20Interception%20defense%3CBR%20%2F%3E09%3A22%20Paths%20to%20securing%20SMB%3CBR%20%2F%3E13%3A40%20PATCH%3CBR%20%2F%3E14%3A30%20No%20SMB1%3CBR%20%2F%3E19%3A03%20No%20Guest%20Auth%3CBR%20%2F%3E21%3A03%20No%20WebDAV%3CBR%20%2F%3E23%3A30%20SMB%20over%20QUIC%20coming!%3CBR%20%2F%3E24%3A26%20Limit%20outbound%20SMB%3CBR%20%2F%3E25%3A58%20UNC%20Hardening%20%3CBR%20%2F%3E34%3A10%20SMB%203.1.1%3CBR%20%2F%3E41%3A00%20Encryption%3CBR%20%2F%3E44%3A46%20No%20NTLM%2C%20Harden%20Kerberos%3CBR%20%2F%3E57%3A27%20Movement%20defense%20%3CBR%20%2F%3E59%3A58%20Block%20inbound%20edge%3CBR%20%2F%3E1%3A03%3A30%20Inventory%20SMB%3CBR%20%2F%3E1%3A11%3A00%20Firewall%20block%20and%20allow%20%3CBR%20%2F%3E1%3A16%3A39%20Disable%20SMB%20Server%3CBR%20%2F%3E1%3A23%3A00%20Final%20thoughts%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2177429%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESmall%20%26amp%3B%20mid-sized%20business%20(SMB)%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EStorage%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

In this session, Ned Pyle discuss how widely the SMB protocol is used on Windows, Windows Server and in Microsoft Azure. Learn specific strategies to secure it from lateral movement and interception attacks.

Resources:
IT Ops Talks Hybrid Event: https://aka.ms/ITOpsTalks​
IT Ops Talks Community Chat: https://aka.ms/OPS104-chat​
About SMB over QUIC: https://aka.ms/SMBoverQUIC-Mar20Blog​
SMB Interception Defense: https://aka.ms/smbinterceptiondefense​
Beyond the Edge: How to Secure SMB Traffic in Windows: https://aka.ms/smbtrafficcontrol​

To watch more sessions from the IT Ops Talks: All Things Hybrid event check out our playlist: https://www.youtube.com/playlist?list...​

Chapters:
00:00​ Introduction
02:32​ SMB is everywhere
06:00​ Distributed system defense is hard, not impossible
07:51​ Interception defense
09:22​ Paths to securing SMB
13:40​ PATCH
14:30​ No SMB1
19:03​ No Guest Auth
21:03​ No WebDAV
23:30​ SMB over QUIC coming!
24:26​ Limit outbound SMB
25:58​ UNC Hardening
34:10​ SMB 3.1.1
41:00​ Encryption
44:46​ No NTLM, Harden Kerberos
57:27​ Movement defense
59:58​ Block inbound edge
1:03:30​ Inventory SMB
1:11:00​ Firewall block and allow
1:16:39​ Disable SMB Server
1:23:00​ Final thoughts

0 Replies

Session Resources