Attack Surface Analyzer
ADAudit Plus' Attack Surface Analyzer lets you detect threats and defend against various attacks within your on-premises, cloud, and hybrid Active Directory (AD) environments with curated dashboards and exclusive reports.
Attack Surface Analyzer for AD
The Attack Surface Analyzer for AD is equipped with over 25 exclusive reports that help you spot various AD attacks.
The different attacks that you can detect using ADAudit Plus' Attack Surface Analyzer for on-premises AD are listed below:
- Pass the ticket
- Pass the hash
- DCShadow
- DCSync
- AdminSDHolder ACL tampering
- RID hijacking
- AS-REP roasting
- Kerberoasting
- Recent use of default admin
- Shadow admin
- Primary Group ID
- Golden Ticket
- Silver Ticket
- Security log killer
- PowerShell script block logging
- Constrained delegation
- Unconstrained delegation
- Password extraction
- Password spray
- Reversible password encryption
- Plaintext password in GPO
- Brute-force password detection
- Brute-force username detection
- DSRM password change
- DNS admin escalation
- Suspicious process
- Remote thread
- Ransomware attack
Attack Surface Analyzer for Azure
With the Attack Surface Analyzer for Azure, you can spot threats within your Azure Cloud and enhance cloud security.
Configure Azure Cloud for attack surface analysis
Before configuring your Azure Cloud for attack surface analysis, you need to create an application in the Azure portal and assign the appropriate role.
Create an application in the Azure portal:
- Log in to the Azure portal and navigate to Microsoft Entra ID (previously Azure AD).
- Go to Manage > App registrations > + New registration to open the Register an application window.
- Enter a suitable Name for the application (for example, ADAudit Plus Application), retain the default values for other options, and click Register.
- On the application's Overview page, copy the Application ID as this will be needed when configuring the Azure cloud directory in ADAudit Plus.
- Go to Manage > Certificates & secrets > New client secret.
- In the Add a client secret panel, give a suitable Description, select the Expiry time, and click Add.
- Copy the Secret ID as this will be needed when configuring the Azure cloud directory in ADAudit Plus.
- Navigate to Subscriptions in the Azure portal and select the subscription you want to configure in ADAudit Plus.
- From the left menu, go to Access control (IAM) > + Add > Add role assignment.
- In the Role tab, search for and select the Reader role and click Next.
- In the Members tab, click + Select Members, search for the name of the application that you created in step 3, click Select, and then click Review + Assign.
- Repeat steps 9 to 11 for the Storage Account Contributor role.
- If you want ADAudit Plus to verify policies against your keys, secrets, and certificates in Azure Key Vaults, then navigate to the Key Vault resource you want to monitor, click Access Configuration from the left menu, and based on the permission model you have selected, follow the steps below:
- If you have selected Vault Access Policy, click Go to access policies, and then click Create. Under Key permissions, Secret permissions, and Certificate permissions, select the check box next to List and click Next. In the Principal tab, search for and select the name of the application that you created, and click Next. Review your settings and click Review + Create.
- If you have selected Azure role-based access control (recommended), click Access control (IAM) and add the Key Vault Contributor role for the application by following steps 9 to 11.
Configure Azure Cloud for attack surface analysis in ADAudit Plus:
- Log in to the ADAudit Plus web console.
- Navigate to the Azure AD tab > Attack Surface Analyzer > Configuration > Cloud Directory.
- Click +Add Cloud Directory in the top-right.
- Select Azure Cloud from the Add Cloud Directory pop-up.
- Enter the Display Name, Tenant Name, Client ID, Client Secret, Subscription ID, and Cloud Type.
- Select the Audit Log check box if you want to fetch the audit logs and monitor all the operations performed in Azure Cloud, and then click Next.
- Review your settings and click Finish.
Don't see what you're looking for?
-
Visit our community
Post your questions in the forum.
-
Request additional resources
Send us your requirements.
-
Need implementation assistance?
Try onboarding