CTD-000192

AD domain with misconfigured UNC paths policies

High
Active Directory
Credential Access Defense Evasion Initial Access Lateral Movement Privilege Escalation
v21

Signature Identity

CTD-000192
Threat ID
21
Version
IOE
Indicator Type

Threat Description

Domain Controllers (DCs) host the SYSVOL and NETLOGON shared folders via SMB, which are critical for distributing Group Policy and logon scripts. If Hardened UNC Paths are not enforced on DCs, these shares become vulnerable to NTLM relay, man-in-the-middle, and SMB downgrade attacks. Such attacks can enable adversaries to intercept or manipulate authentication traffic, steal user credentials, impersonate domain controllers, or distribute malicious Group Policy objects across the environment.

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion Initial Access Lateral Movement Privilege Escalation

D3FEND: Defend Tactics

D3-ACH (Application Configuration Hardening)

Remediation

  1. Open Group Policy Management (gpmc.msc).
  2. Create a new Group Policy Object (GPO) or edit an existing one linked to the Domain Controllers Organizational Unit (OU).
  3. Navigate to:
    Computer Configuration > Policies > Administrative Templates > Network > Network Provider > Hardened UNC Paths
  4. Set the policy to Enabled and configure the following values:
    • \*SYSVOL RequireMutualAuthentication=1, RequireIntegrity=1
    • \*NETLOGON RequireMutualAuthentication=1, RequireIntegrity=1
  5. Optional:Add RequirePrivacy=1 to enforce SMB encryption where supported.
  6. Apply the GPO and refresh settings on all domain controllers by running: gpupdate /force

Frequently Asked Questions

What does AD domain with misconfigured UNC paths policies mean?

The Hardened UNC Paths policy is not enforced on Domain Controllers (DCs), making SYSVOL and NETLOGON shares vulnerable to NTLM relay attacks, which allow attackers to intercept authentication traffic. This also enables SMB downgrade attacks, allowing attackers to manipulate authentication traffic or steal user credentials.

A misconfigured UNC path directly enables NTLM relay and SMB downgrade attacks, allowing attackers to intercept authentication traffic and steal user credentials. This can lead to serious compromise of the Active Directory environment due to unauthorized access to sensitive data.

Attackers can use NTLM relay or SMB downgrade attacks to intercept authentication traffic and steal user credentials, allowing them to impersonate domain controllers or gain unauthorized access to sensitive data. This also enables the attacker to maintain persistence in the environment.

Cayosoft Guardian detects AD domain with misconfigured UNC paths policies by continuously monitoring the configuration of Hardened UNC Paths on Domain Controllers. When a misconfigured UNC path is detected, Guardian flags it as a security issue so administrators can take corrective action to enforce the policy and prevent attacks.

Cayosoft Guardian helps reduce the risk of AD domain with misconfigured UNC paths policies by alerting administrators to take corrective action, such as creating a new Group Policy Object (GPO) or editing an existing one linked to the Domain Controllers Organizational Unit. This ensures that Hardened UNC Paths are enforced on DCs and prevents NTLM relay and SMB downgrade attacks.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Forest-wide Infrastructure
Attack Tactics
Credential Access Defense Evasion Initial Access Lateral Movement Privilege Escalation
Defend Tactics
D3-ACH (Application Configuration Hardening)
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical