CTD-000084

AD domain controller allowing authentication with keys vulnerable to ROCA

Informational
Active Directory
Credential Access Defense Evasion
v33

Signature Identity

CTD-000084
Threat ID
33
Version
Indicator of Exposure
Indicator Type

Threat Description

The ‘Return of Coppersmith’s attack’ or ROCA vulnerability is a cryptographic weakness in a widely used cryptographic library. A threat actor can get access to secret keys using this library and use this keys for authentication. Domain controllers should be configured to block authentications with such vulnerable keys.

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion

D3FEND: Defend Tactics

Application Configuration Hardening Domain Account Monitoring

Remediation

To prevent domain controllers from authentications with vulnerable keys, a group policy with Block setting must be configured as described in this article.

Frequently Asked Questions

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Infrastructure
Attack Tactics
Credential Access Defense Evasion
Defend Tactics
Application Configuration Hardening Domain Account Monitoring
Indicator Types
Indicator of Exposure
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical