
This vulnerability research aimed to establish a controlled environment for simulating a Zerologon on windows Server 2016 through Kali Linux for detection and mtigiation purposes. The primary focus was to perform a vulnerability pentration and show the possiblity of controlling a desktop through not logining in as the user of the desktop while detecting and mitigating the vulnerability.
IMPORTANT Disable security feature
Microsoft has developed available patches to protect Windows Servers (2008, 2016 and 2019); This was how it was planned. In the first phase, when downloading the first patch (August patch), the domain can protect other connected devices from non-compliant devices; there would be an option to protect all joined devices with an explicit exception.
Second patch (February of next year patch), the enforcement phase, when installed, all windows and non-windows devices are forced to use a secure Remote Procedure Call with Netlogon. Or to explicitly allow certain trusted devices. Essentially kicking the non-compliant computer out of the domain.