Stop AD Threats As They Happen
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
VMware ESXi contains an authentication bypass vulnerability.
A threat actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group (‘ESX Admins’ by default) after it was deleted from AD.
D3FEND: Defend Tactics
Note: ESX Admins group does not exist in Active Directory by default.
If this group was not created by your organization or your organization is not using this group name, the existence of this group could be a sign of an active compromise.
Collect the data related to the incident and delete the group immediately:
Get-ADGroup "ESX Admins" -Properties createdGet-ADGroupMember "ESX Admins" -RRemove-ADGroup "ESX Admins"If you are using this group name for management rename the existing group, review group membership, and check your ESXI hosts for potential compromise.
A VMware ESXi host configured for Active Directory user management has an authentication vulnerability. This allows an attacker to exploit the vulnerability, enabling them to authenticate without proper authorization.
This vulnerability enables attackers to bypass access controls and gain control over a VMware ESXi host, allowing for privilege escalation, persistence, and operational impact due to the attacker's ability to execute remote commands and manipulate system settings.
Attackers can exploit this vulnerability by re-creating a deleted Active Directory group ('ESX Admins' by default) using the compromised credentials, enabling them to execute remote commands, manipulate system settings, and maintain persistence on the system.
Cayosoft Guardian continuously monitors VMware ESXi host configurations for signs of this vulnerability. When a vulnerable host is detected, Guardian flags it as a security issue, enabling administrators to take corrective action.
Cayosoft Guardian reduces the risk by alerting administrators to the vulnerability and providing visibility into affected hosts. This enables teams to remediate the issue promptly, delete the vulnerable group in Active Directory, and prevent further exploitation.
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack