▾ G11 Media Network: | ChannelCity | ImpresaCity | SecurityOpenLab | Italian Channel Awards | Italian Project Awards | Italian Security Awards | ...
InnovationOpenLab

SpecterOps Adds Industry-Leading Protection for Active Directory Certificate Services to BloodHound Enterprise

SpecterOps, a provider of adversary-focused cybersecurity solutions and unique insights of advanced threat actor tradecraft, today announced updates to BloodHound Enterprise (BHE) that add new Attack ...

Immagine

New attack paths added to BHE make it the most comprehensive and most accurate tool on the market for securing ADCS

SEATTLE: SpecterOps, a provider of adversary-focused cybersecurity solutions and unique insights of advanced threat actor tradecraft, today announced updates to BloodHound Enterprise (BHE) that add new Attack Paths focused on Active Directory Certificate Services (ADCS). These updates make BHE the most advanced tool on the market today for securing ADCS.

ADCS is the Public Key Infrastructure implementation of Microsoft Active Directory and is widely used in enterprise environments including most of the Fortune 1000. If attackers can abuse it to give themselves false authentication certificates, they can gain account and domain-level privileges and establish deep persistence. Unfortunately, misconfigurations in ADCS are common and pose an enormous security risk, but have traditionally been overlooked by the security community with few tools available to help secure it.

These new ADCS attack paths are based on work by SpecterOps researchers Will Schroeder and Lee Chagolla-Christensen, first released in 2021. They discovered many common misconfigurations in enterprise ADCS environments that allow attackers to steal certificates, achieve account persistence, and achieve full control over an Active Directory domain. These updates allow BHE users to easily identify and remediate these misconfigurations and significantly reduce their risk.

“In months of research, nearly every environment with ADCS we looked at was vulnerable to domain escalation - I can’t overstate how serious these issues are,” said Will Schroeder, Security Researcher at SpecterOps. “These updates arm security and IAM teams with the power to find and fix these misconfigurations, shut down these attack paths and dramatically reduce their risk of ADCS abuse.”

ADCS provides the mechanism used for encrypting file systems, digital signatures, user authentication and more. The nature of ADCS makes it very difficult for defenders to detect or respond to attacks on it after they’ve been executed. Removing misconfigurations and weaknesses in ADCS is the best way to reduce the risk of these serious attacks.

In response, SpecterOps is adding multiple attack paths related to ADCS to BloodHound Enterprise. Three of them are available in the product now in Early Access with three to follow later in January. BHE customers can enable these paths through their Early Access page. Additional paths will be added throughout early 2024 as additional research is completed.

BloodHound Enterprise (BHE) is the industry’s first platform for comprehensively removing identity attack paths in Microsoft’s Active Directory (AD) and Entra/Azure AD. It experienced rapid customer adoption in 2022 and 2023 with significant product revenue growth and new customer acquisition growing by more than 600%. Today, BloodHound Enterprise is used worldwide by companies like Capital Group, the University of Texas at Austin and Woodside Energy.

SpecterOps raised a $33.5M Series A funding round from Decibel and Ballistic Ventures in 2023. This update is one of many projects that funding has enabled or accelerated.

About SpecterOps

SpecterOps is a cybersecurity solutions and services provider specializing in deep knowledge of adversary tradecraft to help clients detect and defend against sophisticated attackers. The company releases numerous widely used free and open-source security toolsets, including BloodHound, a penetration testing solution which maps attack paths in Active Directory and Azure environments. BloodHound has been recommended by the Department of Homeland Security, PricewaterhouseCoopers and many more. BloodHound Enterprise is the company’s first defense solution for enterprise security and identity teams. For more information on the company and its solutions, visit https://specterops.io/.

Fonte: Business Wire

If you liked this article and want to stay up to date with news from InnovationOpenLab.com subscribe to ours Free newsletter.

Related news

Last News

RSA at Cybertech Europe 2024

Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…

Italian Security Awards 2024: G11 Media honours the best of Italian cybersecurity

G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes

How Austria is making its AI ecosystem grow

Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries

Sparkle and Telsy test Quantum Key Distribution in practice

Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…

Most read

Integral AI Unveils World’s First AGI-capable Model

#AGI--Integral AI, a global leader in the development of embodied AGI, today announced the successful testing of the world’s first AGI-capable model.…

Reply Achieves the AWS Agentic AI Specialization and Is Named an Implementation…

Reply [EXM, STAR: REY] announced that it has achieved the Amazon Web Services (AWS) Agentic AI Specialization, a new category within the AWS AI Competency.…

Tecnotree Emerges as CX Catalyst Winner for Impact at The Fast Mode Awards…

Tecnotree, a global digital platform and services leader for AI, 5G, and cloud-native technologies, has won the CX Catalyst award for Impact at The Fast…

CoMotion GLOBAL 2025 Launches in Riyadh: Global Mobility Leaders Unite…

Riyadh is rapidly becoming one of the world's most ambitious urban mobility laboratories, where next-generation technologies move from blueprint to real-world…

Newsletter signup

Join our mailing list to get weekly updates delivered to your inbox.

Sign me up!