Active Directory Attack Surface
To adequately protect an Active Directory deployment, one must be able to clearly identify the attack surface that Active Directory is exposed to. This is vital, because to protect any system, one must identify exactly what needs to be defended.
The attack surface of Active Directory is comprised of the following -
All Domain Controllers in an Active Directory Forest - Each and every single Domain Controller (DC) and Secure Admin Workstation (SAW) in the forest is a high-value target that must be adequately secured and protected.
All administrative accounts and groups in in an Active Directory Forest - Each and every single administrative account and group in the forest is a high-value target that must be adequately secured and protected.
- Note - It is absolutely imperative and paramount to ensure that each and every single account and group that has administrative (privileged) access in Active Directory be correctly identified and subsequently be afforded the highest level of protection.
A domain account or group could be a member of zero default administrative groups, and yet by simply possessing a single security permission in a single ACL somewhere in Active Directory, could have powerful privileged access in Active Directory. -
The entire contents of Active Directory -
Each and every single object that represents a DC, a SAW, a TDO, an administrative account, an administrative group, a privileged service account, the partition root (Domain, Configuration and Schema), the default Domain Controllers OU and the AdminSDHolder object in every domain in the forest is a high-value target that must be adequately secured and protected because the compromise of any one of these could be used to completely compromise the entire Active Directory.
In addition, the thousands of domain user accounts, computer accounts and security groups that exist in Active Directory, and all the OUs and containers in which they reside are also valuable targets that must be adequately secured and protected. This is equally important because a single accidental, inadvertant or malicious change made in any one ACL or to any one group membership in Active Directory could result in these accounts or groups instantly becoming a privileged user/group.
Finally, every domain user account, computer account or security group in any Active Directory domain could potentially have been provisioned access in the network to either a large number of organizatonal assets and/or to high business-value information (HBI) e.g. trade secrets, company financials, proprietary code or algorithms, customer PII data, sales information, quarterly earnings releases, email servers, databases, line-of-business applications etc., and the compromise of any account or group that may have been provisioned such access could result in the perpetrator being able to obtain access to everything that the compromised account or group has access to, resulting in a major security breach.
All physical backups of Active Directory - Each and every single physical backup of Active Directory is a high-value target that must be adequately secured and protected, primarily from unauthorized physical access.
All external and/or cross-forest trust relationships in Active Directory's Logical Structure - Each and every single forest or external trust relationshp is a high-value target that must be adequately secured and protected.
- All critical dependencies - The DNS infrastructure, the PKI infrastructure and the Windows Time Service are also all high-value target that must also be adequately secured and protected.
+