Stop AD Threats As They Happen
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
An account with Kerberos pre-authentication disabled doesn´t have sufficient protection against password-guessing attacks.
The Key Distribution Center (KDC) is available as part of the domain controller and performs two key functions which are: Authentication Service (AS) and Ticket-Granting Service (TGS). By default the KDC requires all accounts to use pre-authentication. This is a security feature which offers protection against password-guessing attacks.
If pre-authentication is enabled, a time stamp will be encrypted using the user’s password hash as an encryption key. If the KDC reads a valid time when using the user’s password hash, which is available in the Active Directory, to decrypt the time stamp, the KDC knows that request isn’t a replay of a previous request. When you do not enforce pre-authentication, a malicious actor can directly send a dummy request for authentication. The KDC will return an encrypted TGT and the malicious actor can brute force it offline.
Enable pre-authentication on all users. If disabling pre-authentication is required, consider reducing permissions of accounts with disabled pre-authentication. Kerberos pre-authentication can prevent the active attacker. However, it does not prevent a passive attacker from sniffing the client’s encrypted timestamp message to the KDC. If the attacker can sniff that full packet, he can brute force it offline. To mitigate this problem, it is recommended that the users use lengthy passwords. Additionally, a good password rotation policy should also be implemented in the domain to make the offline brute-forcing infeasible or increasingly difficult.
D3FEND: Defend Tactics
To enable pre-authentication for a user account:
AD domain account with Kerberos pre-authentication disabled means the account is not requiring pre-authentication, allowing an attacker to send a dummy request for authentication and obtain an encrypted Ticket-Granting Service (TGS) ticket, which can be used for offline password cracking attempts.
This configuration allows attackers to perform offline password cracking attacks, but does not grant administrative control directly. The risk is meaningful and can lead to successful compromise if the attacker has sufficient time or resources.
Attackers can abuse this configuration by sending a dummy request for authentication, obtaining an encrypted TGS ticket, and then attempting to crack the password offline using brute-force methods. This method allows attackers to bypass real-time interaction and increases their chances of successful compromise.
Cayosoft Guardian detects this configuration by continuously monitoring the pre-authentication settings for all accounts across the Active Directory environment domain and flags it as a security issue so administrators can take corrective action.
Cayosoft Guardian helps reduce this risk by alerting administrators to enable pre-authentication for affected accounts, limiting the attacker's ability to perform offline password cracking attempts and reducing the overall risk of successful compromise.
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack