#domaincontroller — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #domaincontroller, aggregated by home.social.
-
Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.
Pulse ID: 6a7ca262c4921e41ead16a57
Pulse Link: https://otx.alienvault.com/pulse/6a7ca262c4921e41ead16a57
Pulse Author: AlienVault
Created: 2026-08-12 16:42:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault
-
Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.
Pulse ID: 6a7ca262c4921e41ead16a57
Pulse Link: https://otx.alienvault.com/pulse/6a7ca262c4921e41ead16a57
Pulse Author: AlienVault
Created: 2026-08-12 16:42:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault
-
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...
Pulse ID: 6a678b1bffd8195d4d34ef68
Pulse Link: https://otx.alienvault.com/pulse/6a678b1bffd8195d4d34ef68
Pulse Author: AlienVault
Created: 2026-07-27 16:45:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #DomainController #HTTP #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #PowerShell #Proxy #RAT #RPC #RansomWare #Rust #Troll #bot #AlienVault
-
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...
Pulse ID: 6a678b1bffd8195d4d34ef68
Pulse Link: https://otx.alienvault.com/pulse/6a678b1bffd8195d4d34ef68
Pulse Author: AlienVault
Created: 2026-07-27 16:45:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #DomainController #HTTP #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #PowerShell #Proxy #RAT #RPC #RansomWare #Rust #Troll #bot #AlienVault
-
Microsoft Warns of Domain Controller Lookup Failures on Windows Server 2016
If you've installed the KB5087537 update on your Windows Server 2016 system, be aware that domain controller lookup may fail if your server hostname is exactly 15 characters long. This issue affects only those with 15-character hostnames, so check yours to see if you're impacted.
#WindowsServer2016 #DomainController #Microsoft #Kb5087537 #EmergingThreats
-
Limiting Domain Controller Attack Surface: Why Less Services, Less Software, Less Agents = Less Exposure: https://trustedsec.com/blog/limiting-domain-controller-attack-surface-why-less-services-less-software-less-agents-less-exposure
-
Limiting Domain Controller Attack Surface: Why Less Services, Less Software, Less Agents = Less Exposure: https://trustedsec.com/blog/limiting-domain-controller-attack-surface-why-less-services-less-software-less-agents-less-exposure
-
Windows Server 2025: #DomainController sind nach Neustart nicht mehr erreichbar
"Windows Server 2025 leidet offenbar unter einem #Konnektivitätsproblem. Laut Microsoft wird bei Domain-Controllern das falsche #Firewall-Profil geladen."
https://www.golem.de/news/windows-server-2025-domain-controller-sind-nach-neustart-nicht-mehr-erreichbar-2504-195369.html -
Windows Server 2025: #DomainController sind nach Neustart nicht mehr erreichbar
"Windows Server 2025 leidet offenbar unter einem #Konnektivitätsproblem. Laut Microsoft wird bei Domain-Controllern das falsche #Firewall-Profil geladen."
https://www.golem.de/news/windows-server-2025-domain-controller-sind-nach-neustart-nicht-mehr-erreichbar-2504-195369.html -
From today's ADMIN Update newsletter, Thomas Joos shows you how to configure your domain controller security settings correctly with Policy Analyzer and current Microsoft baselines for a leak-tight Active Directory
https://www.admin-magazine.com/Archive/2024/83/Optimizing-domain-controller-security
#security #configuration #ActiveDirectory #PolicyAnalyzer #DCs #Microsoft #DomainController -
From today's ADMIN Update newsletter, Thomas Joos shows you how to configure your domain controller security settings correctly with Policy Analyzer and current Microsoft baselines for a leak-tight Active Directory
https://www.admin-magazine.com/Archive/2024/83/Optimizing-domain-controller-security
#security #configuration #ActiveDirectory #PolicyAnalyzer #DCs #Microsoft #DomainController -
1. No it the fuck cannot.
2. No one asked you, literally.
3. I know this because I DIDN'T ASK YOU.
4. I really hate that Google is doing this stupid shit. It's so goddamn unnecessary and wasteful.
When we can't breathe because there's no more oxygen, at least we'll die knowing that 30% of the AI answers contained at least 60% accurate information.
#windows #google #microsoft #alphabet #waste #ai #windowsdomain #rodc #domaincontroller -
1. No it the fuck cannot.
2. No one asked you, literally.
3. I know this because I DIDN'T ASK YOU.
4. I really hate that Google is doing this stupid shit. It's so goddamn unnecessary and wasteful.
When we can't breathe because there's no more oxygen, at least we'll die knowing that 30% of the AI answers contained at least 60% accurate information.
#windows #google #microsoft #alphabet #waste #ai #windowsdomain #rodc #domaincontroller -
Intel and Karma partner to develop software-defined car architecture - Enlarge / Karma was started in 2014 when the Wanxiang Group purchased t... - https://arstechnica.com/?p=2043501 #softwaredefinedvehicle #software-definedcar #domaincontroller #intel #karma #cars
-
Intel and Karma partner to develop software-defined car architecture - Enlarge / Karma was started in 2014 when the Wanxiang Group purchased t... - https://arstechnica.com/?p=2043501 #softwaredefinedvehicle #software-definedcar #domaincontroller #intel #karma #cars
-
Akamai researchers discovered a new privilege escalation technique affecting Active Directory (AD) environments that leverages the DHCP administrators group. In cases where the DHCP server role is installed on a Domain Controller (DC), this could enable them to gain domain admin privileges. The technique is based on abuse of legitimate features and doesn’t rely on any vulnerability. Therefore, a fix for it doesn’t exist. No CVE ID. This EoP technique could also be used to create a stealthy domain persistence mechanism. 🔗 https://www.akamai.com/blog/security-research/2024/feb/abusing-dhcp-administrators-group-for-privilege-escalation-in-windows-domains
#privilegeescalation #activedirectory #vulnerability #domaincontroller #EoP #persistence
-
Akamai researchers discovered a new privilege escalation technique affecting Active Directory (AD) environments that leverages the DHCP administrators group. In cases where the DHCP server role is installed on a Domain Controller (DC), this could enable them to gain domain admin privileges. The technique is based on abuse of legitimate features and doesn’t rely on any vulnerability. Therefore, a fix for it doesn’t exist. No CVE ID. This EoP technique could also be used to create a stealthy domain persistence mechanism. 🔗 https://www.akamai.com/blog/security-research/2024/feb/abusing-dhcp-administrators-group-for-privilege-escalation-in-windows-domains
#privilegeescalation #activedirectory #vulnerability #domaincontroller #EoP #persistence
-
SEO Poisoning to Domain Control: The Gootloader Saga Continues
In February 2023, a user downloaded and executed a file from a SEO-poisoned search result, leading to a Gootloader infection. Around nine hours later, Gootloader facilitated Cobalt Strike deployment into the registry and memory. The threat actor used SystemBC to tunnel RDP access, compromising domain controllers, backup servers, and other key servers. The threat actor interactively reviewed sensitive files via RDP, but no data exfiltration was confirmed.
Pulse ID: 65dc5f0cd3b2b09478de2ba2
Pulse Link: https://otx.alienvault.com/pulse/65dc5f0cd3b2b09478de2ba2
Pulse Author: AlienVault
Created: 2024-02-26 09:51:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #RDP #RAT #CobaltStrike #SeoPoisoning #GootLoader #DomainController #Troll #AlienVault
-
Finally, no more Active Directory Domain Controllers running Windows Server 2012 in our environment. Legacy support is just one of the pitfalls of "inheriting" poorly managed domains.
Next, I will shore up the encryption protocols. #ActiveDirectory #DomainController -
𝗦𝗶𝗺𝗽𝗹𝗶𝗳𝗶𝗲𝗱 𝗱𝗲𝗽𝗹𝗼𝘆𝗺𝗲𝗻𝘁 𝘄𝗶𝘁𝗵 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿 𝗳𝗼𝗿 𝗜𝗱𝗲𝗻𝘁𝗶𝘁𝘆
"Microsoft Defender for Identity is an essential part of a modern security practice, helping your organization protect against, and respond to, identity-based threats. In this blog we will show you the simple steps for deploying Microsoft Defender for Identity within your environment."
#defenderforidentity #mdi #microsoft #microsoftsecurity #defender #adfs #domaincontroller #activedirectory #itdr #azure #adfs #adcs #deployment
-
Demoted a #DomainController in a secondary domain, but lots of clients were still using it as their primary DNS. Had to reinstall DNS and transfer the DNS zone, then create a CNAME for those still using the old DC name. Need to be more aggressive with the DNS logs next time. #ActiveDirectory
-
Learned the hard lesson that Format-Table is intended for a simple display on the screen. I was generating #ActiveDirectory and #DomainController HTML reports, but the FT was not allowing ConvertTo-HTML to work. I was relying on FT to see my data every step of the way, but now I know when and when NOT to use Format-Table. #Powershell
-
Over engineered a solution a while back but caught it today. Was using Invoke-Command to run DCDiag against each #ActiveDirectory #DomainController But was getting failures on a couple of those tests (either a double hop issue or an SPN caused Replication test to fail). Using DCDiag natively with /s for each DC was the solution. Been collecting invalid results for weeks that ended today.
-
Throw out all those black boxes and say hello to the software-defined car - Enlarge / The prototype of the Q6 e-tron is the first on the new Premiu... - https://arstechnica.com/?p=1943172 #premiumplatformelectric #software-definedcar #domaincontroller #audiq6e-tron #elektrobit #cars #adas #audi
-
Why do I see LM hashes stored in Active Directory?
https://security.stackexchange.com/questions/268083/why-do-i-see-lm-hashes-stored-in-active-directory
#domaincontroller #activedirectory #kerberos #mimikatz #hash -
in the DC locator process, how does the workstation know which domain to use to create the initial query?
_ldap._tcp.dc._msdcs.domain.com
its connected domain must be stored somewhere in the registry I guess, but where?
-
Wichtige Sicherheitsupdates halten Angreifer aus Systemen mit Samba raus.
Kerberos-Authentifizierung: Sicherheitsprobleme in Samba gelöst -
Microsoft is rolling out fixes for problems with the #Kerberos network #authentication protocol on Windows Server after it was broken by a November 8 Patch: https://www.theregister.com/2022/11/21/microsoft_kerberos_fix_windows/ | #DomainController #GMSA
-
How Do I Know If My AD Environment Is Impacted By The November 8th 2022 Patch? https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/how-do-i-know-if-my-ad-environment-is-impacted-by-the-november/ba-p/3679869 #patchday #activedirectory #domaincontroller #microsoft
-
New Windows exploit lets you instantly become admin. Have you patched? - Enlarge (credit: VGrigas (WMF))
Researchers have developed and published a proof-of-concept explo... - https://arstechnica.com/?p=1706068 #domaincontroller #activedirectory #vulnerabilities #exploits #patches #windows #biz&it #tech