Skip to content

[Meta] Explore Detection Opportunities on Active Directory Relay, Spoofing and Coercion Attacks - Part 1 #3544

Closed
@w0rk3r

Description

@w0rk3r

Parent Epic (If Applicable)

https://github.com/elastic/ia-trade-team/issues/276

Summary

Explore how attackers can exploit Active Directory for Credential Access using Relay, spoofing and coercion attacks.

### Tasks
- [x] Build a Lab
- [x] Explore ADIDNS Spoofing
- [x] Explore WSUS Spoofing
- [x] Explore Coercion Attacks
- [ ] Explore PowerShell Tooling

Goals

  • Improve coverage for these attacks.
  • Gain better knowledge of AD DS.

Resources:

PRs

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions