home.social

#domaincontroller — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #domaincontroller, aggregated by home.social.

fetched live
  1. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault

  2. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault

  3. Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

    Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...

    Pulse ID: 6a678b1bffd8195d4d34ef68
    Pulse Link: otx.alienvault.com/pulse/6a678
    Pulse Author: AlienVault
    Created: 2026-07-27 16:45:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #DomainController #HTTP #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #PowerShell #Proxy #RAT #RPC #RansomWare #Rust #Troll #bot #AlienVault

  4. Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

    Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...

    Pulse ID: 6a678b1bffd8195d4d34ef68
    Pulse Link: otx.alienvault.com/pulse/6a678
    Pulse Author: AlienVault
    Created: 2026-07-27 16:45:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #DomainController #HTTP #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #PowerShell #Proxy #RAT #RPC #RansomWare #Rust #Troll #bot #AlienVault

  5. Microsoft Warns of Domain Controller Lookup Failures on Windows Server 2016

    If you've installed the KB5087537 update on your Windows Server 2016 system, be aware that domain controller lookup may fail if your server hostname is exactly 15 characters long. This issue affects only those with 15-character hostnames, so check yours to see if you're impacted.

    osintsights.com/microsoft-warn

    #WindowsServer2016 #DomainController #Microsoft #Kb5087537 #EmergingThreats

  6. Windows Server 2025: #DomainController sind nach Neustart nicht mehr erreichbar

    "Windows Server 2025 leidet offenbar unter einem #Konnektivitätsproblem. Laut Microsoft wird bei Domain-Controllern das falsche #Firewall-Profil geladen."
    golem.de/news/windows-server-2

  7. Windows Server 2025: #DomainController sind nach Neustart nicht mehr erreichbar

    "Windows Server 2025 leidet offenbar unter einem #Konnektivitätsproblem. Laut Microsoft wird bei Domain-Controllern das falsche #Firewall-Profil geladen."
    golem.de/news/windows-server-2

  8. From today's ADMIN Update newsletter, Thomas Joos shows you how to configure your domain controller security settings correctly with Policy Analyzer and current Microsoft baselines for a leak-tight Active Directory
    admin-magazine.com/Archive/202
    #security #configuration #ActiveDirectory #PolicyAnalyzer #DCs #Microsoft #DomainController

  9. From today's ADMIN Update newsletter, Thomas Joos shows you how to configure your domain controller security settings correctly with Policy Analyzer and current Microsoft baselines for a leak-tight Active Directory
    admin-magazine.com/Archive/202
    #security #configuration #ActiveDirectory #PolicyAnalyzer #DCs #Microsoft #DomainController

  10. 1. No it the fuck cannot.
    2. No one asked you, literally.
    3. I know this because I DIDN'T ASK YOU.
    4. I really hate that Google is doing this stupid shit. It's so goddamn unnecessary and wasteful.

    When we can't breathe because there's no more oxygen, at least we'll die knowing that 30% of the AI answers contained at least 60% accurate information.

    #windows #google #microsoft #alphabet #waste #ai #windowsdomain #rodc #domaincontroller

  11. 1. No it the fuck cannot.
    2. No one asked you, literally.
    3. I know this because I DIDN'T ASK YOU.
    4. I really hate that Google is doing this stupid shit. It's so goddamn unnecessary and wasteful.

    When we can't breathe because there's no more oxygen, at least we'll die knowing that 30% of the AI answers contained at least 60% accurate information.

    #windows #google #microsoft #alphabet #waste #ai #windowsdomain #rodc #domaincontroller

  12. Intel and Karma partner to develop software-defined car architecture - Enlarge / Karma was started in 2014 when the Wanxiang Group purchased t... - arstechnica.com/?p=2043501 #softwaredefinedvehicle #software-definedcar #domaincontroller #intel #karma #cars

  13. Intel and Karma partner to develop software-defined car architecture - Enlarge / Karma was started in 2014 when the Wanxiang Group purchased t... - arstechnica.com/?p=2043501 #softwaredefinedvehicle #software-definedcar #domaincontroller #intel #karma #cars

  14. Akamai researchers discovered a new privilege escalation technique affecting Active Directory (AD) environments that leverages the DHCP administrators group. In cases where the DHCP server role is installed on a Domain Controller (DC), this could enable them to gain domain admin privileges. The technique is based on abuse of legitimate features and doesn’t rely on any vulnerability. Therefore, a fix for it doesn’t exist. No CVE ID. This EoP technique could also be used to create a stealthy domain persistence mechanism. 🔗 akamai.com/blog/security-resea

    #privilegeescalation #activedirectory #vulnerability #domaincontroller #EoP #persistence

  15. Akamai researchers discovered a new privilege escalation technique affecting Active Directory (AD) environments that leverages the DHCP administrators group. In cases where the DHCP server role is installed on a Domain Controller (DC), this could enable them to gain domain admin privileges. The technique is based on abuse of legitimate features and doesn’t rely on any vulnerability. Therefore, a fix for it doesn’t exist. No CVE ID. This EoP technique could also be used to create a stealthy domain persistence mechanism. 🔗 akamai.com/blog/security-resea

    #privilegeescalation #activedirectory #vulnerability #domaincontroller #EoP #persistence

  16. SEO Poisoning to Domain Control: The Gootloader Saga Continues

    In February 2023, a user downloaded and executed a file from a SEO-poisoned search result, leading to a Gootloader infection. Around nine hours later, Gootloader facilitated Cobalt Strike deployment into the registry and memory. The threat actor used SystemBC to tunnel RDP access, compromising domain controllers, backup servers, and other key servers. The threat actor interactively reviewed sensitive files via RDP, but no data exfiltration was confirmed.

    Pulse ID: 65dc5f0cd3b2b09478de2ba2
    Pulse Link: otx.alienvault.com/pulse/65dc5
    Pulse Author: AlienVault
    Created: 2024-02-26 09:51:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #RDP #RAT #CobaltStrike #SeoPoisoning #GootLoader #DomainController #Troll #AlienVault

  17. Finally, no more Active Directory Domain Controllers running Windows Server 2012 in our environment. Legacy support is just one of the pitfalls of "inheriting" poorly managed domains.
    Next, I will shore up the encryption protocols. #ActiveDirectory #DomainController

  18. 𝗦𝗶𝗺𝗽𝗹𝗶𝗳𝗶𝗲𝗱 𝗱𝗲𝗽𝗹𝗼𝘆𝗺𝗲𝗻𝘁 𝘄𝗶𝘁𝗵 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿 𝗳𝗼𝗿 𝗜𝗱𝗲𝗻𝘁𝗶𝘁𝘆

    "Microsoft Defender for Identity is an essential part of a modern security practice, helping your organization protect against, and respond to, identity-based threats. In this blog we will show you the simple steps for deploying Microsoft Defender for Identity within your environment."

    techcommunity.microsoft.com/t5

    #defenderforidentity #mdi #microsoft #microsoftsecurity #defender #adfs #domaincontroller #activedirectory #itdr #azure #adfs #adcs #deployment

  19. Demoted a #DomainController in a secondary domain, but lots of clients were still using it as their primary DNS. Had to reinstall DNS and transfer the DNS zone, then create a CNAME for those still using the old DC name. Need to be more aggressive with the DNS logs next time. #ActiveDirectory

  20. Learned the hard lesson that Format-Table is intended for a simple display on the screen. I was generating #ActiveDirectory and #DomainController HTML reports, but the FT was not allowing ConvertTo-HTML to work. I was relying on FT to see my data every step of the way, but now I know when and when NOT to use Format-Table. #Powershell

  21. Over engineered a solution a while back but caught it today. Was using Invoke-Command to run DCDiag against each #ActiveDirectory #DomainController But was getting failures on a couple of those tests (either a double hop issue or an SPN caused Replication test to fail). Using DCDiag natively with /s for each DC was the solution. Been collecting invalid results for weeks that ended today.

  22. Throw out all those black boxes and say hello to the software-defined car - Enlarge / The prototype of the Q6 e-tron is the first on the new Premiu... - arstechnica.com/?p=1943172 #premiumplatformelectric #software-definedcar #domaincontroller #audiq6e-tron #elektrobit #cars #adas #audi

  23. in the DC locator process, how does the workstation know which domain to use to create the initial query?

    _ldap._tcp.dc._msdcs.domain.com

    its connected domain must be stored somewhere in the registry I guess, but where?

    #ActiveDirectory #DomainController #Domain #DCLocator

  24. Microsoft is rolling out fixes for problems with the #Kerberos network #authentication protocol on Windows Server after it was broken by a November 8 Patch: theregister.com/2022/11/21/mic | #DomainController #GMSA

  25. New Windows exploit lets you instantly become admin. Have you patched? - Enlarge (credit: VGrigas (WMF))
    Researchers have developed and published a proof-of-concept explo... - arstechnica.com/?p=1706068 #domaincontroller #activedirectory #vulnerabilities #exploits #patches #windows #biz&it #tech