<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Active-Directory on CuraSec</title><link>https://curasec.metacog.co.kr/tags/active-directory/</link><description>Recent content in Active-Directory on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 18 Aug 2026 11:37:25 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/active-directory/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-54121: Domain User to Domain Controller via Enterprise CA</title><link>https://curasec.metacog.co.kr/insights/2026-08-18-certighost-and-the-privilege-hiding-in-your-certificate-auth/</link><pubDate>Tue, 18 Aug 2026 11:37:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-18-certighost-and-the-privilege-hiding-in-your-certificate-auth/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A public PoC exists for a flaw that lets any domain user compromise the Enterprise CA at Domain Controller privilege level — patch CVE-2026-54121 immediately, then audit certificate templates and CA permissions for standing privilege that survives the patch.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> With a public PoC available but no active exploitation confirmed, build detections for anomalous ADCS activity: unusual certificate enrollment requests by standard users, low-privileged accounts invoking CA RPC interfaces, or certificates issued against sensitive templates — these are the behavioral signals that precede weaponization of this class of bug.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> This is a useful forcing function to confirm your PKI infrastructure is formally classified and defended as Tier 0 — ask your team to verify the Enterprise CA is in scope for your privileged-access model and that the patch is on an expedited timeline given the public PoC.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-54121 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Certighost PoC enables AD Certificate Services domain hijack</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-new-certighost-poc-exploit-lets-attackers-hijack-windows-dom/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-new-certighost-poc-exploit-lets-attackers-hijack-windows-dom/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A public PoC now exists for a domain-hijack flaw in AD Certificate Services; audit your PKI templates for misconfigured enrollment permissions and apply any available patch or Microsoft-recommended mitigation immediately.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build detections for anomalous certificate enrollment requests and CA template abuse (e.g., unusual Enrollee Supplies Subject flag usage); no confirmed active exploitation reported yet, but PoC availability shortens the runway.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A PoC for a Windows domain-compromise vulnerability is now public; no board-level action needed yet, but monitor for escalation to active exploitation that could affect enterprise AD environments.&lt;/li>
&lt;/ul></description></item><item><title>Graph Optimisation and AI Models for Active Directory Hardening</title><link>https://curasec.metacog.co.kr/insights/2026-07-27-practical-graph-optimisation-and-ai-driven-models-for-active/</link><pubDate>Mon, 27 Jul 2026 15:10:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-27-practical-graph-optimisation-and-ai-driven-models-for-active/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Academic thesis proposing game-theoretic models for AD attack-path hardening, including dynamic graph defense and honeypot placement. No patch or configuration change needed today, but the prioritization framework could inform future AD remediation planning.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The decoy/honeypot placement model—designed to maximize worst-case incident response time in dynamic AD environments—is worth reading for analysts building deception layers, though no actionable detection content or IOCs are included.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Certighost: Low-Privilege AD User Can Impersonate Domain Controller via ADCS</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-certighost-exploit-lets-low-privileged-active-directory-user/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-certighost-exploit-lets-low-privileged-active-directory-user/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A public working exploit now lets any domain user abuse ADCS to obtain a DC certificate and DCSync the krbtgt hash — full domain compromise from low privilege. Immediately audit certificate templates in ADCS for enrollment rights that allow non-admin principals, and restrict or disable any template that can issue DC computer certificates to ordinary users.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Working exploit means this attack path is now within reach of any authenticated user; hunt for ADCS certificate requests from non-computer, non-privileged accounts targeting DC-class templates, and sweep SIEM/EDR for DCSync (DS-Replication-Get-Changes-All) events originating from unexpected principals since July 24.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> No confirmed in-the-wild exploitation yet, but a public PoC dropping a full domain-compromise chain from a low-privilege user is a credible near-term crisis. Ensure your AD/identity team has a remediation task in flight this week, and prepare a brief in case this escalates to customer or board questions the way ADCS misconfigurations have in the past.&lt;/li>
&lt;/ul></description></item><item><title>Attacker Uses AI-Generated PowerShell Script for AD Enumeration</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-attacker-uses-suspected-ai-generated-powershell-script-to-ma/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-attacker-uses-suspected-ai-generated-powershell-script-to-ma/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No vulnerability to patch here — this is a reconnaissance TTP story showing adversaries using AI-generated scripts for AD discovery. Useful context for understanding how attacker tooling is evolving, but no configuration or software change required today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The enumeration pattern — PowerShell querying DC, mapping users/computers/domains, exporting results to a directory, and generating AD_Report.html — is a detectable behavior signature; review PowerShell Script Block Logging coverage and build or tune a Sigma/KQL rule for this AD bulk-export pattern this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Demonstrates that AI tooling is lowering the skill floor for AD reconnaissance, a useful data point for board-level narratives about AI accelerating attacker capability; no immediate leadership action required.&lt;/li>
&lt;/ul></description></item></channel></rss>