Active Directory Kill Chain Attack & Defense

요약
이 문서는 공격자가 Active Directory를 손상시키기 위해 사용하는 구체적인 전술, 기술, 절차(TTP)를 이해하고 이를 완화, 탐지, 예방하기 위한 지침을 제공하고자 설계된 유용한 정보 자산입니다. 또한 Active Directory Kill Chain Attack과 현대의 Post Exploitation 적대자 트레이드크래프트 활동을 이해하는 데 도움을 줍니다.
목차
Discovery
SPN Scanning
Data Mining
User Hunting
LAPS
AppLocker
Active Directory Federation Services
Privilege Escalation
BadSuccessor
sAMAccountName Spoofing
Abusing Active Directory Certificate Services
PetitPotam
Zerologon
Passwords in SYSVOL & Group Policy Preferences
MS14-068 Kerberos Vulnerability
DNSAdmins
Kerberos Delegation