CTD-000145

Backup location with unencrypted AD backups

High
Active Directory Cayosoft Guardian
Collection Credential Access
v22

Signature Identity

CTD-000145
Threat ID
22
Version
IOE
Indicator Type

Threat Description

Encrypting Active Directory backups adds an extra layer of security to sensitive data like user credentials, group policies, and other sensitive data. Encrypting backups ensures that even if threat actors gain access to the backup files, they won’t be able to read or misuse the information.

Encrypted backups are much safer in the event of a data breach. Even if threat actors manage to access the backup files, they won’t be able to decipher the information without the encryption key, minimizing the impact of the breach. In addition, they guard against insider threats. Even employees with access to backup files won’t be able to misuse the data if it’s encrypted without the necessary decryption keys.

When transferring backup files over networks or storing them in cloud services, encryption ensures that the data remains secure throughout the transmission and storage, protecting it from interception or unauthorized access.

MITRE ATT&CK: Attack Tactics

Collection Credential Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To delete the unencrypted backups:

  1. Navigate to Forest Recovery > Backup Plans.
  2. Choose the non-encrypted backup plan.
  3. Click Enable Encryption. The Configure backup encryption window opens.
  4. Enable encryption.
  5. Enter the Backup password.
  6. Confirm the password.
  7. Click Yes.
  8. Run the updated Backup plan job.
  9. Repeat the steps for all the non-encrypted backup plans.
  10. Navigate to DC Backup.
  11. Find non-encrypted backups.
  12. Delete unencrypted backups if there are any.

Frequently Asked Questions

What does Backup location with unencrypted AD backups mean?

Backup location with unencrypted AD backups means that the organization's Active Directory backups are stored in an unencrypted format. This makes sensitive data like user credentials, group policies, and other information accessible to unauthorized parties if the backup files are accessed.

Backup location with unencrypted AD backups is rated high severity because an attacker who gains access to the unencrypted backup files can read and misuse sensitive data, including user credentials. This exposure enables attackers to plan future malicious operations by gathering authentication information.

When Backup location with unencrypted AD backups is present, an attacker can access the sensitive data stored in the backup files and use it for reconnaissance or other malicious activities. This exposure also enables insider threats, as employees with access to the backup files can misuse the data if it's not encrypted.

Cayosoft Guardian detects Backup location with unencrypted AD backups by continuously monitoring the encryption status of Active Directory backups. When an unencrypted backup is detected, Guardian flags it as a security issue so administrators can take corrective action.

Cayosoft Guardian helps reduce the risk of Backup location with unencrypted AD backups by providing visibility into backup encryption status and alerting administrators to enable encryption for Active Directory backups. Guardian also supports ongoing monitoring so that if the backup encryption is disabled later, the change is caught quickly, ensuring the sensitive data remains protected.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory Cayosoft Guardian
Themes
Infrastructure
Attack Tactics
Collection Credential Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical