Detection and Triage of Domain Persistence
Joshua Prager, Nico
BSides NYC 2024 · Day 1 · Tech - Blue
This talk, presented by Nico and Joshua Prager from SpectreOps, delves into the critical and often overlooked area of **domain persistence techniques** utilized by advanced adversaries. Drawing from real-world compromise assessments, the speakers highlight how organizations frequently lack the necessary detective controls to identify sophisticated attacks that establish elevated and enduring control within an Active Directory environment. The presentation meticulously breaks down various persistence methods, from credential theft on domain controllers to advanced abuses of Active Directory Certificate Services (ADCS) and System Center Configuration Manager (SCCM), offering a comprehensive guide for defenders to detect and triage these threats.
AI review
SpectreOps delivers a technically grounded, defender-focused breakdown of domain persistence techniques — LSASS, ntds.dit, DC-Sync, Golden/Diamond Tickets, ADCS, SCCM — with specific event IDs, SACL strategies, and honest caveats about detection noise. The content is practitioner-grade and directly actionable, even if the underlying attack techniques themselves aren't novel territory for the offense side.