Burning Bridges - Stopping Lateral Movement via the RPC Firewall
Автор: Black Hat
Загружено: 2022-01-31
Просмотров: 2366
Описание:
In Windows based environments, RPC is the main underlying protocol required for remote administration and for Active Directory services. As such, it is often used by IT admins, but also by ransomware and advanced attackers to spread by creating remote services, scheduled tasks, DCOM objects, etc. It is also a major component in the persistency phase of attacks such as active directory DCSync, and even DC vulnerabilities such as Zerologon. The issue for defenders is that defending against remote RPC attacks is not trivial...
By: Sagie Dulce
Full Abstract & Presentation Materials: https://www.blackhat.com/eu-21/briefi...
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: