ATTACK METHODS FOR OBTAINING DOMAIN ADMINISTRATOR RIGHTS IN ACTIVE DIRECTORY
МЕТОДЫ ПРОВЕДЕНИЯ АТАК ДЛЯ ПОЛУЧЕНИЯ ПРАВ АДМИНИСТРАТОРА ДОМЕНА В ACTIVE DIRECTORY

Il'ya Skoropupov, Anna Bubnova, Igor Karmanov
2019 Interexpo GEO-Siberia  
In this article the following attack methods for obtaining domain administrator rights in Active Directory are considered: searching for passwords in the SYSVOL settings and group policies, Kerberoast, swapping of stolen credentials, getting access to AD database file. Recommendations for preventing such attacks and minimization of possible damage from them are formulated.
doi:10.33764/2618-981x-2019-6-1-187-192 fatcat:ro6omq3cq5hgpo53sjjbp6m4u4