Impacket Defense Basics With an Azure Lab
ID: 55b4ca0d-03be-5722-ba11-0b6442a0fbe9
STIX ID: report--55b4ca0d-03be-5722-ba11-0b6442a0fbe9
Feed Name: Black Hills Infosec Blog
This report provides a defensive walkthrough for detecting and mitigating Impacket-powered techniques in an Azure AD lab, mapping them to MITRE ATT&CK and demonstrating practical detections and controls. It covers ntlmrelayx (LNK/URL relay and AiTM), account creation and discovery detections using decoy AD objects and Event ID 4662, GPP cpassword retrieval, Kerberoasting via GetUserSPNs, and credential dumping/DCSync with secretsdump, recommending tools and practices such as Sysmon (modular config), FSRM for file extensions, robust logging (Event IDs 4656/4662/4688/4720/4722), workstation/server firewalls, LDAP signing/channel binding, and managed service accounts (sMSA/gMSA).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
