Harnessing adaptive authentication with Microsoft ITDR

Поділитися
Вставка
  • Опубліковано 12 лис 2024

КОМЕНТАРІ • 4

  • @AlienWarTycoon
    @AlienWarTycoon 5 місяців тому

    Just a thought, if you want to invalidate all of the cached Kerberos tickets when you are reacting and disabling an account, you should build into defender for endpoint the ability to run klist Purge on every device that is running Windows.

  • @AlienWarTycoon
    @AlienWarTycoon 5 місяців тому

    Maybe that last comment could be scoped to only if the compromised account has a ticket on the computer running defender for endpoint

  • @AlienWarTycoon
    @AlienWarTycoon 5 місяців тому +1

    You should define acronyms more often.