logo

Impacket Defense Basics With an Azure Lab 

ID: 55b4ca0d-03be-5722-ba11-0b6442a0fbe9

STIX ID: report--55b4ca0d-03be-5722-ba11-0b6442a0fbe9

Feed Name: Black Hills Infosec Blog

Date Published: 2022-07-26

Date Updated: 2026-04-27

Author: BHIS

...
...

This report provides a defensive walkthrough for detecting and mitigating Impacket-powered techniques in an Azure AD lab, mapping them to MITRE ATT&CK and demonstrating practical detections and controls. It covers ntlmrelayx (LNK/URL relay and AiTM), account creation and discovery detections using decoy AD objects and Event ID 4662, GPP cpassword retrieval, Kerberoasting via GetUserSPNs, and credential dumping/DCSync with secretsdump, recommending tools and practices such as Sysmon (modular config), FSRM for file extensions, robust logging (Event IDs 4656/4662/4688/4720/4722), workstation/server firewalls, LDAP signing/channel binding, and managed service accounts (sMSA/gMSA).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.