06.08.2016 Views

Beyond the MCSE Red Teaming Active Directory

DEFCON-24-Sean-Metcalf-Beyond-The-MCSE-Red-Teaming-Active-Directory

DEFCON-24-Sean-Metcalf-Beyond-The-MCSE-Red-Teaming-Active-Directory

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

ESAE Admin Forest (aka “<strong>Red</strong> Forest”)<br />

• The “best” way to secure & protect AD.<br />

• Separate forest with one-way forest trust.<br />

• Separate smart card PKI system.<br />

• Separate updating & patching system.<br />

• All administration performed w/ ESAE<br />

accounts & ESAE computers.<br />

• Completely isolated.<br />

| @PryoTek3 | sean @ adsecurity.org |

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!