Adalanche provides immediate insights into the permissions of users and groups within an Active Directory.
It's an effective open-source tool for visualizing and investigating potential account, machine, or domain takeovers.
It helps identify and display any misconfigurations.
The screenshot above showcases the search for Domain Controller machines and who can successfully reach them.
Tarly has permission to take ownership of a GPO that is applied to a Domain Controller - and on the left, you can see some admin put the plaintext password in the description field.
This is a synthetic example, but these things pop up when doing Active Directory analysis, even for huge companies.
Avalanche collects information from Active Directory or local Windows machines and can then analyze the collected data.
If you're only doing Active Directory analysis, grab the binary for your preferred platform.
Exe for your Windows member machines via a GPO or other orchestration and get even more insight.
This repository provides sample data from the Orange Cyberdefense lab Game of Active Directory project.
It is a vulnerable Active Directory lab comprising 5 Windows machines and two Windows servers.
This Cyber News was published on www.helpnetsecurity.com. Publication date: Mon, 15 Jan 2024 05:43:06 +0000