CTD-000006

Anonymous access enabled in AD forest

High
Active Directory
Defense Evasion Discovery Initial Access
v80

Signature Identity

CTD-000006
Threat ID
80
Version
IOE
Indicator Type

Threat Description

Enabled anonymous LDAP access exposes directory information to unauthenticated users, allowing attackers to enumerate users, groups, and other Active Directory objects without authentication. This significantly lowers the effort required for reconnaissance and target identification but does not directly provide privilege escalation or persistence capabilities. However, the information obtained can be used to support follow-on attacks such as password spraying, phishing, and privilege escalation through other weaknesses.

MITRE ATT&CK: Attack Tactics

Defense Evasion Discovery Initial Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

Disable anonymous access to the Active Directory:

  1. Go to Start Menu.
  2. Select Run.
  3. Enter adsiedit.msc.
  4. Click OK.
  5. Select ADSI Edit node.
  6. In the Action menu select Connect to…
  7. Enter path in the Connection point section: CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration, {Root domain in forest}.
  8. Expand a new node, right-click on a child node CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration, {Root domain in forest}.
  9. Select Properties.
  10. Find dSHeuristics attribute in the Attribute editor.
  11. Set seventh character value to ‘0’. Do not modify any characters in the DsHeuristics string other than the seventh character.

Frequently Asked Questions

What does Anonymous access enabled in AD forest mean?

Anonymous access enabled in AD forest allows the Lightweight Directory Access Protocol (LDAP) to permit unauthenticated users to query and collect information about the environment, including user and group details.

Anonymous access enabled in AD forest is rated high severity because it enables attackers to collect sensitive information through LDAP queries, which can be used for reconnaissance and planning more serious attacks. This allows attackers to gather information about users, groups, and other object types.

Attackers can use LDAP to collect sensitive data when anonymous access is enabled in AD forest, which can be used for future malicious operations. This includes gathering information about users, groups, and other object types.

Cayosoft Guardian continuously monitors LDAP settings across the Active Directory environment domain and flags anonymous access as a security issue when it is detected, alerting administrators to take action.

Cayosoft Guardian alerts administrators to disable anonymous access, limiting attackers' ability to collect sensitive information through LDAP queries and reducing the risk of more serious attacks. This helps provide visibility into potential security issues and supports investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Forest-wide
Attack Tactics
Defense Evasion Discovery Initial Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical