CTD-000047

AD domain controller with SMB1 enabled

High
Active Directory
Credential Access
v38

Signature Identity

CTD-000047
Threat ID
38
Version
IOE
Indicator Type

Threat Description

A threat actor can potentially compromise a domain controller that has the SMBv1 protocol enabled by exploiting vulnerabilities in the protocol, such as the EternalBlue exploit. This exploit can allow an attacker to remotely execute code on a vulnerable system and gain unauthorized access, potentially leading to a complete compromise of the domain controller and the associated network. To prevent such attacks, it is recommended to disable SMBv1 and only use newer, more secure versions of the SMB protocol.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To disable SMBv1 protocol on a server, use the following PowerShell cmdlet:

Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol

Learn more about How to detect, enable and disable SMBv1, SMBv2, and SMBv3 in Windows.

Frequently Asked Questions

What does AD domain controller with SMB1 enabled mean?

Enabling SMBv1 on an Active Directory environment's domain controllers allows clients to connect using the outdated SMBv1 protocol, which contains known vulnerabilities that attackers can exploit for remote code execution.

The presence of SMBv1 on a domain controller exposes a critical vulnerability in the SMB protocol stack, allowing an attacker to remotely execute code and gain unauthorized access to the system. This can lead to lateral movement within the domain and privilege escalation.

Attackers can exploit known vulnerabilities in the SMBv1 protocol to send specially crafted packets that allow them to execute arbitrary code on a vulnerable system, potentially leading to lateral movement and privilege escalation within the domain.

Cayosoft Guardian continuously monitors the configuration of Active Directory environment domain controllers for the presence of SMBv1 protocol, flagging it as a security issue when detected to alert administrators and provide visibility into potential attack paths.

Cayosoft Guardian alerts administrators to disable SMBv1 on their domain controllers, preventing attackers from exploiting the vulnerability and reducing the risk of remote code execution and unauthorized access. This helps support investigation and response efforts by providing a clear audit trail of changes made to the environment.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection Infrastructure
Attack Tactics
Credential Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical