A few files on a domain controller were encrypted – how could that have happened?

I’ve just realized that the policies on one of our Windows domain have been failing.

I’ve traced the problem and it turned out the INI files were encrypted by Globe ransomware (or one of its variants).

The files affected we… Continue reading A few files on a domain controller were encrypted – how could that have happened?

A few files on a domain controller were encrypted – how could that have happened?

I’ve just realized that the policies on one of our Windows domain have been failing.

I’ve traced the problem and it turned out the INI files were encrypted by Globe ransomware (or one of its variants).

The files affected we… Continue reading A few files on a domain controller were encrypted – how could that have happened?

How does UNC path hardening and SMB signing work under the hood?

With a lot of unpatched versions of Windows in an Active Directory domain, one can man-in-the-middle a client when it connects to the domain controller and inject a group policy that gives an attacker local administrator priv… Continue reading How does UNC path hardening and SMB signing work under the hood?