Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

6/16/2017
07:40 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Hacker Bypasses Microsoft ATA for Admin Access

Microsoft's Advanced Threat Analytics defense platform can be cheated, a researcher will show at Black Hat USA next month.

Microsoft's Advanced Threat Analytics (ATA) platform for detecting cyberattacks can be evaded by attackers to achieve organizational control, a security researcher has discovered.

ATA works by reading information from multiple sources: Windows Event Logs, SIEM events, and certain protocols to the Domain Controller. When communication to the Domain Control is done using protocols like Kerberos, NTLM, RPC, DNS, LDAP, etc., ATA parses the traffic to gather data about possible attacks and user behavior. ATA can detect known attacks like pass-the-hash, pass-the-ticket, Directory Services replication, brute-force, and skeleton key, for example.

But Nikhil Mattal, hacker for the Pentester Academy, found a way to bypass ATA and gain administrative access, which he will detail next month at Black Hat USA in Las Vegas in his session there, "Evading Microsoft ATA for Active Directory Domination." 

"In the past couple of years, there have been increasing attacks on how Windows domain works," Mattal says. For example, if someone logs on to a desktop and their credentials are compromised, ATA will sense whether the user is logged on to multiple machines and send an alert.

It's also used to detect lateral movement across machines and throughout the corporate environment. ATA can be used to authenticate to different resources, driving the consequences of what could happen if the system were compromised.

Mattal calls ATA "the new sheriff in town" for enterprise security and many businesses still don't use it, but adds it's among the most effective mechanisms for businesses today. This initial explanation of ATA will serve as a foundation for the crux of his talk, which will focus on how hackers can bypass ATA and achieve organizational dominance.

There are ways for cybercriminals to evade the detection capabilities of ATA, or avoid the system entirely, to launch dangerous attacks. If they can bypass ATA, it's possible for them to gain domain administrative privileges and access each and every resource in the enterprise.

Attackers can slightly alter the so-called golden ticket attack, for example, to evade the detection capabilities of ATA and gain administrative privileges. ATA is designed to detect users trying to create a "golden ticket" to gain this level of access. However, attackers can bypass this by changing a packet in the Kerberos protocol used to connect with the Domain Controller.

"ATA detects anomalies but by changing the structure of the golden ticket, it is possible to completely bypass it," Mattal explains, noting that attackers can use this to access data.

"Consumer records, intellectual property … attackers can persist in that environment using the golden ticket and there would be no detection at all," he continues.

Mattal at Black Hat will dive into the technicalities of the golden ticket as well as other types of possible attacks against ATA and present live demonstrations of how they work. He says he has communicated his findings to Microsoft and is collaborating with its team to address the issues. Microsoft is working to push an update before Black Hat, and Mattal plans to adjust his presentation based on the progress there, he notes.

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada, July 22-27, 2017. Click for information on the conference schedule and to register.

 

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
KpmL136
50%
50%
KpmL136,
User Rank: Apprentice
8/16/2017 | 1:53:45 AM
Upcoming Events of Cyber Security:
ISC2 CISSP Training Kuwait

SC² CISSP CERTIFICATION TRAINING DOHA

ISC² CISSP CERTIFICATION TRAINING RIYADH

ISC² CISSP Training Egypt
theb0x
100%
0%
theb0x,
User Rank: Ninja
6/19/2017 | 9:51:04 AM
ATA Admin Access
Most likely exploits a covert channel.
KpmL136
100%
0%
KpmL136,
User Rank: Apprentice
6/19/2017 | 9:10:45 AM
MICROSOFT MVP: Andy Malone | Cyber Security
Cyber security is an important concern of this era and needs to be tackled properly. There are many professionals working towards protecting the organization from hacking but the end result is known to all. May companies have recently become the victim of cyber attack. Keeping this in concern the Microsoft MVP Andy Malone is going to conduct CISSP 5 days boot camp with kpm learning solutions to help experienced professional complete CISSP certification and also the training will add value to CV which in future will help for a better career by making them capable of handling security threats.
10 Ways to Keep a Rogue RasPi From Wrecking Your Network
Curtis Franklin Jr., Senior Editor at Dark Reading,  7/10/2019
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, Protego,  7/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13611
PUBLISHED: 2019-07-16
An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.
CVE-2019-0234
PUBLISHED: 2019-07-15
A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). The mitigation for this vulnerability is to upgrade to the latest version of ...
CVE-2018-7838
PUBLISHED: 2019-07-15
A CWE-119 Buffer Errors vulnerability exists in Modicon M580 CPU - BMEP582040, all versions before V2.90, and Modicon Ethernet Module BMENOC0301, all versions before V2.16, which could cause denial of service on the FTP service of the controller or the Ethernet BMENOC module when it receives a FTP C...
CVE-2019-6822
PUBLISHED: 2019-07-15
A Use After Free: CWE-416 vulnerability exists in Zelio Soft 2, V5.2 and earlier, which could cause remote code execution when opening a specially crafted Zelio Soft 2 project file.
CVE-2019-6823
PUBLISHED: 2019-07-15
A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0.