Attacks/Breaches

6/16/2017
07:40 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Hacker Bypasses Microsoft ATA for Admin Access

Microsoft's Advanced Threat Analytics defense platform can be cheated, a researcher will show at Black Hat USA next month.

Microsoft's Advanced Threat Analytics (ATA) platform for detecting cyberattacks can be evaded by attackers to achieve organizational control, a security researcher has discovered.

ATA works by reading information from multiple sources: Windows Event Logs, SIEM events, and certain protocols to the Domain Controller. When communication to the Domain Control is done using protocols like Kerberos, NTLM, RPC, DNS, LDAP, etc., ATA parses the traffic to gather data about possible attacks and user behavior. ATA can detect known attacks like pass-the-hash, pass-the-ticket, Directory Services replication, brute-force, and skeleton key, for example.

But Nikhil Mattal, hacker for the Pentester Academy, found a way to bypass ATA and gain administrative access, which he will detail next month at Black Hat USA in Las Vegas in his session there, "Evading Microsoft ATA for Active Directory Domination." 

"In the past couple of years, there have been increasing attacks on how Windows domain works," Mattal says. For example, if someone logs on to a desktop and their credentials are compromised, ATA will sense whether the user is logged on to multiple machines and send an alert.

It's also used to detect lateral movement across machines and throughout the corporate environment. ATA can be used to authenticate to different resources, driving the consequences of what could happen if the system were compromised.

Mattal calls ATA "the new sheriff in town" for enterprise security and many businesses still don't use it, but adds it's among the most effective mechanisms for businesses today. This initial explanation of ATA will serve as a foundation for the crux of his talk, which will focus on how hackers can bypass ATA and achieve organizational dominance.

There are ways for cybercriminals to evade the detection capabilities of ATA, or avoid the system entirely, to launch dangerous attacks. If they can bypass ATA, it's possible for them to gain domain administrative privileges and access each and every resource in the enterprise.

Attackers can slightly alter the so-called golden ticket attack, for example, to evade the detection capabilities of ATA and gain administrative privileges. ATA is designed to detect users trying to create a "golden ticket" to gain this level of access. However, attackers can bypass this by changing a packet in the Kerberos protocol used to connect with the Domain Controller.

"ATA detects anomalies but by changing the structure of the golden ticket, it is possible to completely bypass it," Mattal explains, noting that attackers can use this to access data.

"Consumer records, intellectual property … attackers can persist in that environment using the golden ticket and there would be no detection at all," he continues.

Mattal at Black Hat will dive into the technicalities of the golden ticket as well as other types of possible attacks against ATA and present live demonstrations of how they work. He says he has communicated his findings to Microsoft and is collaborating with its team to address the issues. Microsoft is working to push an update before Black Hat, and Mattal plans to adjust his presentation based on the progress there, he notes.

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada, July 22-27, 2017. Click for information on the conference schedule and to register.

 

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
KpmL136
50%
50%
KpmL136,
User Rank: Apprentice
8/16/2017 | 1:53:45 AM
Upcoming Events of Cyber Security:
ISC2 CISSP Training Kuwait

SC² CISSP CERTIFICATION TRAINING DOHA

ISC² CISSP CERTIFICATION TRAINING RIYADH

ISC² CISSP Training Egypt
theb0x
100%
0%
theb0x,
User Rank: Ninja
6/19/2017 | 9:51:04 AM
ATA Admin Access
Most likely exploits a covert channel.
KpmL136
100%
0%
KpmL136,
User Rank: Apprentice
6/19/2017 | 9:10:45 AM
MICROSOFT MVP: Andy Malone | Cyber Security
Cyber security is an important concern of this era and needs to be tackled properly. There are many professionals working towards protecting the organization from hacking but the end result is known to all. May companies have recently become the victim of cyber attack. Keeping this in concern the Microsoft MVP Andy Malone is going to conduct CISSP 5 days boot camp with kpm learning solutions to help experienced professional complete CISSP certification and also the training will add value to CV which in future will help for a better career by making them capable of handling security threats.
Higher Education: 15 Books to Help Cybersecurity Pros Be Better
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
Worst Password Blunders of 2018 Hit Organizations East and West
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-14623
PUBLISHED: 2018-12-14
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulne...
CVE-2018-18093
PUBLISHED: 2018-12-14
Improper file permissions in the installer for Intel VTune Amplifier 2018 Update 3 and before may allow unprivileged user to potentially gain privileged access via local access.
CVE-2018-18096
PUBLISHED: 2018-12-14
Improper memory handling in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to potentially enable a denial of service via local access.
CVE-2018-18097
PUBLISHED: 2018-12-14
Improper directory permissions in Intel Solid State Drive Toolbox before 3.5.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2018-3704
PUBLISHED: 2018-12-14
Improper directory permissions in the installer for the Intel Parallel Studio before 2019 Gold may allow authenticated users to potentially enable an escalation of privilege via local access.