How to remediate – AD Starter Scan – Kerberoasting 1. Introduction AD Starter Scan has identified a vulnerability, AD Starter Scan – Kerberoasting, where privileged accounts are susceptible to...
How to remediate – AD Starter Scan – Kerberos Krbtgt 1. Introduction The vulnerability “AD Starter Scan – Kerberos Krbtgt” means the password for the KRBTGT account in Active Directory...
How to remediate – AD Starter Scan – Kerberos Pre-authentication Validation 1. Introduction Kerberos pre-authentication is disabled on a user account, creating a vulnerability known as AD Starter Scan – Kerberos...
How to remediate – AD Starter Scan – Non-Expiring Account Password 1. Introduction AD Starter Scan identifies Active Directory accounts with passwords that never expire. This means these accounts are not...
How to remediate – AD Starter Scan – Null sessions 1. Introduction The vulnerability “AD Starter Scan – Null sessions” occurs when the Everyone group has read permissions on Active...
How to remediate – AD Starter Scan – Primary Group ID integrity 1. Introduction AD Starter Scan has identified a potential backdoor using the Primary Group ID attribute on user accounts. This...
How to remediate – AD Starter Scan – Unconstrained delegation 1. Introduction AD Starter Scan – Unconstrained delegation is a dangerous Kerberos delegation setting that allows compromised servers to impersonate...
How to remediate – AD Starter Scan – Weak Kerberos encryption 1. Introduction AD Starter Scan identifies weak Kerberos encryption configurations, specifically the use of DES. This matters because DES is...
How to remediate – ADFS Relying Party Trusts Disclosure 1. Introduction ADFS Relying Party Trusts Disclosure is a vulnerability in Microsoft Active Directory Federation Services (ADFS) where the IdP-initiated...
How to remediate – Adobe Acrobat Detection 1. Introduction Adobe Acrobat is installed on remote Windows hosts. It’s a PDF creation and editing tool widely used in...