AD | Protect
For Retail
Active Directory
The Root of Domain Compromise
The adage “assume breach” drives awareness that attackers will find a way onto an endpoint in the Domain. After establishing control on an endpoint, they are looking for ways to create persistence that will enable their campaign, and then execute when the time is perfect.
USE CASE
Automotive retailer reduces attack surface
ISSUE
  • Active Directory features can be used for legitimate and illegitimate purposes.
  • This attack surface often goes undiscovered.
APPROACH
  • Javelin ADAssess uses native features of Microsoft Active Directory to crawl the environment like an adversary and detect Dark Corners (opportunities for lateral movement and persistence).
  • This approach is non-invasive to the client environment, and if employed as a security tool beyond the assessment, will provide continuous visibility of attack surface.
 
VALUE DELIVERED
  • The attack simulation showed client had 26 exchange users that had AdminSDHolder and Domain Replication privileges.
  • Client was unaware of these vulnerabilities for persistence, lateral movement, and credential theft.
  • With the remediation suggestions offered by Javelin ADAssess, the client was able to reduce the attack surface of Active Directory
 
Active Directory as the ultimate countermeasure
Javelin AD|Protect turns Active Directory into an Intrusion Detection and Containment system. Using an advanced, Domain forensic methodology, AD|Protect controls the attacker’s perception and uses it against them.
Capture Patient Zero
Letting an attacker roam an environment from Patient Zero yields full Domain compromise, putting every asset and enlisted at risk. By using the attacker’s perspective against them, Javelin AD|Protect automates the discovery of Patient Zero.
Shorten containment time
Counterintelligence can shorten containment time, allowing for a strong defensive position to protect core assets. Using Domain-specific incident response methodologies, an autonomous capability launches forensics for memory and file system artifacts.
 
Reduce alert fatigue
Increasing cyber resilience will raise the cost for the attacker, discourage additional attacks, and allow responders to study advancement in the attacker’s breach tactics. Near real-time containment at the point of breach in the Domain will decrease collateral damage and improve resource utilization by reducing alert fatigue.
Reduce attack surface
Attackers leave backdoors and hooks in the Domain that are used to persist privileges and exploit Active Directory. AD|Protect uncovers attacks in progress and evidence left behind to mitigate risk in real-time, all the time.
 
Javelin vs Microsoft ATA
This video demonstrates a common Domain attack and the results from both Javelin AD|Protect and Microsoft ATA.
PLAY VIDEOarrow
Javelin vs. APT28
PLAY VIDEOarrow
Javelin vs. Olympic Destroyer
PLAY VIDEOarrow
Javelin vs. Empire Deathstar
PLAY VIDEOarrow
Javelin vs. Bloodhound
PLAY VIDEOarrow
Javelin vs. Duqu 2.0
PLAY VIDEOarrow
JAVELIN AD|PROTECT RESOURCES
pdf
What is Javelin AD|Protect?
Datasheet
pdf
Active Directory Attack Simulation
Datasheet
pdf
Active Directory: Exposed by Design
Whitepaper
pdf
Endpoint Obfuscation vs. Distributed Deception
Whitepaper
pdf
11 Commands to Compromise the Domain
Whitepaper
pdf
How Does AD|Protect Work?
Whitepaper
Request a Demo
Required
Required
Required
NUMBER OF EMPLOYEES
FEDERAL ENTITY
*COUNTRY
I'M INTERESTED IN
 
 
 
Request a Demo
Required
Required
Required
NUMBER OF EMPLOYEES
FEDERAL ENTITY
*COUNTRY
I'M INTERESTED IN