Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Detecting and Mitigating the PetitPotam Attack on Windows Domains

Summary

How the PetitPotam attack works: EFSRPC authentication coercion relayed via NTLM to AD CS Web Enrollment (ESC8) can yield Domain Admin; the post maps the full chain and covers detection plus mitigations like disabling NTLM or enabling EPA.
Published
Collected

original ↗