1. [CVE-2026-15409] 英国地方议会攻击事件与 SonicWall SMA 1000 攻击活动相关联 漏洞 | 2026-09-10 00:00 | CVE-2026-15409 | hunt.io | 原文 ↗ | #incident-response | #threat-intelligence | #active-directory
2. Migrator 2.0 发布:从容迁移 Active Directory 博客 | 2026-09-09 15:35 | semperis.com | 原文 ↗ | #active-directory | #identity-security | #migration
3. AD-PathFinder:基于 BloodHound CE + OpenGraph 的 AD/ADCS/SCCM/MSSQL 攻击路径测绘 工具 | 2026-09-02 23:54 | github.com | 原文 ↗ | #pentesting | #open-source | #active-directory
4. 身份危机:导致 Kerberos 降级、DoS 和完全域接管的新型漏洞 研究 | 2026-08-05 22:35 | semperis.com | 原文 ↗ | #active-directory | #denial-of-service | #privilege-escalation
5. 毫秒级可预测性:CVE-2026-11374 为何难以利用 漏洞 | 严重 | 2026-07-21 00:00 | CVE-2026-11374 | bishopfox.com | 原文 ↗ | #featured | #vulnerability-research | #account-takeover
6. AD 组风险:Backup Operators 中隐藏的危险 博客 | 2026-07-28 16:40 | semperis.com | 原文 ↗ | #active-directory | #backup-security | #privilege-escalation
7. 最小可行公司 第 3 部分:实现可见性、控制与运营弹性 博客 | 2026-07-21 22:28 | semperis.com | 原文 ↗ | #incident-response | #active-directory | #cyber-resilience
8. 备份服务器是否应该加入域? 博客 | 2026-07-19 08:06 | projectblack.io | 原文 ↗ | #active-directory | #backup-security | #ransomware
9. Windows 权限滥用:攻击者如何从拥有危险权限的账户提升到攻陷 Active Directory 研究 | 2026-07-06 18:15 | semperis.com | 原文 ↗ | #active-directory | #privilege-escalation | #identity-security
10. 实践检查点 1:使用 MS Graph 构建 Agent ID 博客 | 2026-06-30 22:59 | semperis.com | 原文 ↗ | #agentic-ai | #active-directory | #entra-id
11. 用户帐户限制阻止你登录?教你解决 RDP 登录被拒问题 研究 | 2026-06-27 07:39 | projectblack.io | 原文 ↗ | #active-directory | #kerberos | #windows-security
12. Entra ID 中工作负载身份的分类:服务主体、企业应用及其他“有组织的混乱”形式 博客 | 2026-06-27 01:41 | semperis.com | 原文 ↗ | #agentic-ai | #active-directory | #entra-id
13. 认识 Entra ID Agent 身份(顺便说一句:它们不是人) 博客 | 2026-06-27 01:35 | semperis.com | 原文 ↗ | #agentic-ai | #active-directory | #identity-security
14. 理解并预防 Entra ID Agent 身份攻击:综合指南 博客 | 2026-06-27 01:23 | semperis.com | 原文 ↗ | #agentic-ai | #active-directory | #identity-security
15. 当灯熄灭:富士康失陷事件告诉我们的身份优先勒索软件真相 事件 | 2026-06-19 14:59 | semperis.com | 原文 ↗ | #incident-response | #active-directory | #ransomware
16. 当 EPA 不起作用时:Certify、Certipy 和 checkMSSQLStatus.py 遗漏了什么 博客 | 2026-06-24 00:00 | abdulmhsblog.com | 原文 ↗ | #ai-security | #active-directory | #penetration-testing
17. 将身份上下文带入 Microsoft 安全工作流:Semperis 与 Sentinel 和 Copilot 的集成 博客 | 2026-06-23 12:19 | semperis.com | 原文 ↗ | #cloud | #incident-response | #threat-detection
18. 隐藏在 Active Directory 迁移中的 11 个现实风险 博客 | 2026-06-12 17:07 | semperis.com | 原文 ↗ | #attack-chains | #active-directory | #privilege-escalation
19. 零信任与失陷预防:你的身份安全目标是什么? 博客 | 2026-06-04 11:00 | semperis.com | 原文 ↗ | #vulnerability-management | #active-directory | #entra-id
20. RC4 与 AD 迁移:发现隐藏在你源域中的故障场景 博客 | 2026-05-29 17:20 | semperis.com | 原文 ↗ | #active-directory | #kerberos | #windows-security
21. 移除SPN并修复Kerberoasting攻击 研究 | 2026-05-24 05:55 | projectblack.io | 原文 ↗ | #remediation | #active-directory | #privilege-escalation
22. 实现 Impacket 的最新协议:MS-RAA 博客 | 2026-05-27 00:00 | abdulmhsblog.com | 原文 ↗ | #pentesting | #active-directory | #windows
23. 剖析 Impacket:好与坏的两面 博客 | 2026-05-10 00:00 | abdulmhsblog.com | 原文 ↗ | #active-directory | #kerberos | #smb
24. 身份弹性清单:超越备份的 6 种思考方式 博客 | 2026-05-04 19:56 | semperis.com | 原文 ↗ | #incident-response | #active-directory | #disaster-recovery
25. 修复ESC4——用户拥有危险权限 研究 | 2026-04-30 23:32 | projectblack.io | 原文 ↗ | #remediation | #active-directory | #hardening
26. 使用 IPAHound 进行图思维 研究 | 2026-04-30 09:01 | swarm.ptsecurity.com | 原文 ↗ | #attack-chains | #active-directory | #red-team
27. 审计Microsoft Entra ID应用权限:隐藏风险、陷阱与Quarkslab的QAZPT工具 研究 | 2026-04-29 22:00 | blog.quarkslab.com | 原文 ↗ | #cloud-security | #active-directory | #entra-id
28. 渗透测试人员的噩梦:当你的工具包失灵时 博客 | 2026-04-23 00:00 | abdulmhsblog.com | 原文 ↗ | #pentesting | #active-directory | #penetration-testing
29. 越过边界:一次本地 Domain Admin 沦陷如何打开云端大门 研究 | 2026-04-17 11:55 | labs.cognisys.group | 原文 ↗ | #cloud | #cloud-security | #active-directory
30. 修复 ESC8——Web 注册通过 HTTP 和 HTTPS 启用,且通道绑定已禁用 研究 | 2026-04-06 10:59 | projectblack.io | 原文 ↗ | #ai-security | #active-directory | #hardening