CIO Influence
CIO Influence News Security

XM Cyber Reveals Hidden Attack Paths Using Active Directory to Operationalize Accurate Remediation and Prevent Breaches

XM Cyber Reveals Hidden Attack Paths Using Active Directory to Operationalize Accurate Remediation and Prevent Breaches
XM Cyber First to Combine MS Active Directory Exposures with Other Attack Techniques to Continuously Eradicate AD Risks and Protect Critical Assets

XM Cyber, the multi-award-winning attack path management company, announced a new security capability for Microsoft’s Active Directory (AD). XM Cyber is the first in the industry to link the use of AD into the entire attack path, bringing multiple attack techniques together and offering a complete and accurate view of an organization’s cybersecurity risk, across on-prem and cloud environments. With this new capability, enterprises gain end-to-end attack path visualization for easy understanding and prioritized remediation of all weaknesses before an attack can take place.

Latest ITechnology News: Selligent Marketing Cloud Boosts Customer Engagement with New Smart Subject Capabilities

A chain of attack vectors (vulnerabilities, misconfigurations, user privileges, human errors, etc.) that enables lateral movement through an organization’s network is called an attack path. Once an attacker is inside the network, they can move laterally, escalating their privileges and targeting systems to gain access to sensitive data and business-critical resources, and even gain access to the cloud environment by moving from a compromised enterprise AD user to the associated Azure AD user.

AD is widely used by enterprises around the world (including approximately 90% of Global Fortune 1000 companies) to connect and manage endpoints inside corporate networks. This makes it an attractive target for hackers seeking to obtain domain admin-level access. An attacker that has compromised an AD user can elevate privileges, conceal malicious activity in the network, execute malicious code, and gain access to the cloud environment to compromise assets. The XM Cyber Research team recently reported that 73% of the top attack techniques used to compromise critical assets in 2021 involved mismanaged or stolen credentials; and according to EMA research, at least 50% of organizational attacks are due to AD compromise.

“It is critical to make concentrated efforts to comprehensively secure and monitor AD, proactively look for threats and misconfigurations, and remediate to prevent dangerous actions from taking place,” according to Gartner®. [1]

The XM Cyber Attack Path Management platform demonstrates how AD abuse comes into play across the entire attack path, bringing together multiple attack techniques to pinpoint the riskiest credentials and permissions across users, endpoints and services managed in AD. This enables organizations to direct resources to remediate the most impactful risks first, with step-by-step guidance. The platform’s comprehensive security posture analysis surfaces AD weaknesses in real time, correlating the likelihood of attacks that can compromise critical assets. In the following illustration, we see how an attacker leverages a vulnerability to compromise an AD user and exploit a legitimate set of configurations to escalate privileges and compromise the enterprise domain.

Latest ITechnology News: Cloud Tech Recruitment Titan Frank Recruitment Group Edge Further Into Canadian Market With New Montreal Hub

“Existing solutions provide security teams with limited visibility into which users can expose critical assets,” said Boaz Gorodissky, CTO, XM Cyber. “Our unique ability to chain together AD attack techniques gives organizations the edge against attackers, enabling them to reduce their risk before the attack ever happens. We are committed to providing proactive security so CISOs can focus on maximizing resources to protect their most business-critical applications and data.”

XM Cyber will debut its AD capabilities at the 2022 RSA Conference, taking place June 6-9 in San Francisco.  Interested parties can book a personal demo here or visit us at booth #4328 at the Moscone North Expo. Learn more about XM Cyber Active Directory security here.

[1] Gartner, “Emerging Technologies and Trends Impact Radar: Security”, Ruggero Contu, Mark Driver, et al, 12 October 2021. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.

Latest ITechnology News: Schneider Electric Announces Grid Operations Platform as a Service on Microsoft Azure

[To share your insights with us, please write to sghosh@martechseries.com]

Related posts

Entitle Launches With $15 Million in Seed Funding to Bake Security Into Permissions Management

PR Newswire

Zscaler ThreatLabz 2022 Ransomware Report Reveals Record Number of Attacks and Nearly 120% Growth in Double Extortion Ransomware

Fortinet Becomes Official Cybersecurity Partner of the European Tour

CIO Influence News Desk

Leave a Comment