惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
I
InfoQ
Engineering at Meta
Engineering at Meta
D
DataBreaches.Net
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Recent Announcements
Recent Announcements
GbyAI
GbyAI
爱范儿
爱范儿
Microsoft Security Blog
Microsoft Security Blog
腾讯CDC
美团技术团队
罗磊的独立博客
Microsoft Azure Blog
Microsoft Azure Blog
WordPress大学
WordPress大学
T
The Blog of Author Tim Ferriss
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
雷峰网
雷峰网
M
MIT News - Artificial intelligence
D
Docker
MongoDB | Blog
MongoDB | Blog
F
Fortinet All Blogs
博客园 - 叶小钗

Black Hills Information Security, Inc.

Bad Habits: An ANTISOC Operation Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other How to Identify and Exploit New Vulnerabilities Swapper – A Pure Regex Match/Replace Burp Extension A Practical Guide to BloodHound Data Collection Network Engineering Basics Signed, Trusted, and Abused: Proxy Execution via WebView2 Getting Started In Pentesting – Advice From The BHIS Pentest Lead Cloud Security: Tips and Resources for Securing the Cloud Lessons From A Chatbot Incident How to Lead Effective Tabletops Understanding GRC: How to Navigate Risks and Compliance Standards The “P” in PAM is for Persistence: Linux Persistence Technique Malware Analysis: How to Analyze and Understand Malware OSINT: How to Find, Use, and Control Open-Source Intelligence What to Do with Your First Home Lab When the SOC Goes to Deadwood: A Night to Remember Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions Common Cyber Threats Finding the Right Penetration Testing Company Deceptive-Auditing: An Active Directory Honeypots Tool The Curious Case of the Comburglar How to Set Smart Goals (That Actually Work For You) Inside the BHIS SOC: A Conversation with Hayden Covington Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation Why You Got Hacked – 2025 Super Edition Abusing Delegation with Impacket (Part 2): Constrained Delegation Abusing Delegation with Impacket (Part 1): Unconstrained Delegation GoSpoof – Turning Attacks into Intel Model Context Protocol (MCP)
Webcast: The Quest for the Kill Chain Killer Continues
BHIS · 2021-09-23 · via Black Hills Information Security, Inc.

, , , , ,





Jordan and Kent have heard from a lot of people that the past Black Hills Information Security (BHIS) webcasts: “Group Policies That Kill Kill Chains” and “Active Directory Best Practices to Frustrate Attackers” have changed their business models for the better.

And since they’ve been offered the BHIS soapbox again, they thought it was time to update this material and combine it.

Security can sometimes move slow and other times blazingly fast. They’ll discuss what they’ve seen in the past year and how it impacts their view on baseline defensive configurations you shouldn’t be operating without.

At the end of the day, we are in this game to make things difficult for attackers, adversaries, and red teamers. We want to reduce mean time to detection. And we really want to help you make your networks and domains more secure.

So… why not update our favorite webcasts with everything we’ve learned since giving them?

Join the BLACK HILLS INFOSEC Discord Server — https://discord.gg/bhis

The Kill Chains Material: https://www.blackhillsinfosec.com/webcast-group-policies-that-kill-kill-chains/

How to Frustrate Attackers Material: https://www.blackhillsinfosec.com/webcast-group-policies-that-kill-kill-chains/

Recorded•2021-05-13

00:00 – FEATURE PRESENTATION BEGINS – The Quest for the Kill Chain Killer Continues

02:15 – What Changed in the Last Year?

06:31 – The Kill Chain

07:47 – Active Directory Best Practices to Frustrate Attackers

09:22 – Pre-Reqs

13:31 – Active Directory

16:16 – Organizational Units ^^ Policies

17:47 – Layer Two Protocols

20:53 – Addressing LLMNR (NBNS and WPAD too)

23:04 – Unaddressing of LLMNR

34:34 – Addressing NBNS

35:17 – Addressing WPAD

37:05 – File Shares

39:48 – SMB Signing

41:26 – IPv6

42:17 – LDAP Channel Binding

43:21 – Microsoft Store

44:21 – Too Many GPOs to Cover

45:07 – Dealing with Local Admins

45:51 – Network Logons

47:18 – Managed Service Accounts

48:59 – Application Controls

49:45 – Speaking of Ransomware…

50:48 – Firewalls

52:29 – Canary Accounts

53:19 – Network Analysis

54:45 – Credentials

57:08 – Wrap-Up and Questions

Want to learn more mad skills from the person who wrote this blog?

Check out these classes from Jordan and Kent: