Systematically Identifying Absolutely Every Privileged User and Detecting New Ones

3/9/2017 12:00:00 PM [(UTC-05:00) Eastern Time (US & Canada)] - Can't make the live event? Register anyway to receive a link to the recording.

Show/Hide All Time Zones

All Time Zones

Dateline Standard Time-(UTC-12:00) International Date Line West 3/9/2017 5:00:00 AM
UTC-11-(UTC-11:00) Coordinated Universal Time-11 3/9/2017 6:00:00 AM
Aleutian Standard Time-(UTC-10:00) Aleutian Islands 3/9/2017 7:00:00 AM
Hawaiian Standard Time-(UTC-10:00) Hawaii 3/9/2017 7:00:00 AM
Marquesas Standard Time-(UTC-09:30) Marquesas Islands 3/9/2017 7:30:00 AM
Alaskan Standard Time-(UTC-09:00) Alaska 3/9/2017 8:00:00 AM
UTC-09-(UTC-09:00) Coordinated Universal Time-09 3/9/2017 8:00:00 AM
Pacific Standard Time (Mexico)-(UTC-08:00) Baja California 3/9/2017 9:00:00 AM
UTC-08-(UTC-08:00) Coordinated Universal Time-08 3/9/2017 9:00:00 AM
Pacific Standard Time-(UTC-08:00) Pacific Time (US & Canada) 3/9/2017 9:00:00 AM
US Mountain Standard Time-(UTC-07:00) Arizona 3/9/2017 10:00:00 AM
Mountain Standard Time (Mexico)-(UTC-07:00) Chihuahua, La Paz, Mazatlan 3/9/2017 10:00:00 AM
Mountain Standard Time-(UTC-07:00) Mountain Time (US & Canada) 3/9/2017 10:00:00 AM
Central America Standard Time-(UTC-06:00) Central America 3/9/2017 11:00:00 AM
Central Standard Time-(UTC-06:00) Central Time (US & Canada) 3/9/2017 11:00:00 AM
Easter Island Standard Time-(UTC-06:00) Easter Island 3/9/2017 12:00:00 PM
Central Standard Time (Mexico)-(UTC-06:00) Guadalajara, Mexico City, Monterrey 3/9/2017 11:00:00 AM
Canada Central Standard Time-(UTC-06:00) Saskatchewan 3/9/2017 11:00:00 AM
SA Pacific Standard Time-(UTC-05:00) Bogota, Lima, Quito, Rio Branco 3/9/2017 12:00:00 PM
Eastern Standard Time (Mexico)-(UTC-05:00) Chetumal 3/9/2017 12:00:00 PM
Eastern Standard Time-(UTC-05:00) Eastern Time (US & Canada) 3/9/2017 12:00:00 PM
Haiti Standard Time-(UTC-05:00) Haiti 3/9/2017 12:00:00 PM
Cuba Standard Time-(UTC-05:00) Havana 3/9/2017 12:00:00 PM
US Eastern Standard Time-(UTC-05:00) Indiana (East) 3/9/2017 12:00:00 PM
Paraguay Standard Time-(UTC-04:00) Asuncion 3/9/2017 2:00:00 PM
Atlantic Standard Time-(UTC-04:00) Atlantic Time (Canada) 3/9/2017 1:00:00 PM
Venezuela Standard Time-(UTC-04:00) Caracas 3/9/2017 1:00:00 PM
Central Brazilian Standard Time-(UTC-04:00) Cuiaba 3/9/2017 1:00:00 PM
SA Western Standard Time-(UTC-04:00) Georgetown, La Paz, Manaus, San Juan 3/9/2017 1:00:00 PM
Pacific SA Standard Time-(UTC-04:00) Santiago 3/9/2017 2:00:00 PM
Turks And Caicos Standard Time-(UTC-04:00) Turks and Caicos 3/9/2017 1:00:00 PM
Newfoundland Standard Time-(UTC-03:30) Newfoundland 3/9/2017 1:30:00 PM
Tocantins Standard Time-(UTC-03:00) Araguaina 3/9/2017 2:00:00 PM
E. South America Standard Time-(UTC-03:00) Brasilia 3/9/2017 2:00:00 PM
SA Eastern Standard Time-(UTC-03:00) Cayenne, Fortaleza 3/9/2017 2:00:00 PM
Argentina Standard Time-(UTC-03:00) City of Buenos Aires 3/9/2017 2:00:00 PM
Greenland Standard Time-(UTC-03:00) Greenland 3/9/2017 2:00:00 PM
Montevideo Standard Time-(UTC-03:00) Montevideo 3/9/2017 2:00:00 PM
Saint Pierre Standard Time-(UTC-03:00) Saint Pierre and Miquelon 3/9/2017 2:00:00 PM
Bahia Standard Time-(UTC-03:00) Salvador 3/9/2017 2:00:00 PM
UTC-02-(UTC-02:00) Coordinated Universal Time-02 3/9/2017 3:00:00 PM
Mid-Atlantic Standard Time-(UTC-02:00) Mid-Atlantic - Old 3/9/2017 3:00:00 PM
Azores Standard Time-(UTC-01:00) Azores 3/9/2017 4:00:00 PM
Cape Verde Standard Time-(UTC-01:00) Cabo Verde Is. 3/9/2017 4:00:00 PM
UTC-(UTC) Coordinated Universal Time 3/9/2017 5:00:00 PM
Morocco Standard Time-(UTC+00:00) Casablanca 3/9/2017 5:00:00 PM
GMT Standard Time-(UTC+00:00) Dublin, Edinburgh, Lisbon, London 3/9/2017 5:00:00 PM
Greenwich Standard Time-(UTC+00:00) Monrovia, Reykjavik 3/9/2017 5:00:00 PM
W. Europe Standard Time-(UTC+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna 3/9/2017 6:00:00 PM
Central Europe Standard Time-(UTC+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague 3/9/2017 6:00:00 PM
Romance Standard Time-(UTC+01:00) Brussels, Copenhagen, Madrid, Paris 3/9/2017 6:00:00 PM
Central European Standard Time-(UTC+01:00) Sarajevo, Skopje, Warsaw, Zagreb 3/9/2017 6:00:00 PM
W. Central Africa Standard Time-(UTC+01:00) West Central Africa 3/9/2017 6:00:00 PM
Namibia Standard Time-(UTC+01:00) Windhoek 3/9/2017 7:00:00 PM
Jordan Standard Time-(UTC+02:00) Amman 3/9/2017 7:00:00 PM
GTB Standard Time-(UTC+02:00) Athens, Bucharest 3/9/2017 7:00:00 PM
Middle East Standard Time-(UTC+02:00) Beirut 3/9/2017 7:00:00 PM
Egypt Standard Time-(UTC+02:00) Cairo 3/9/2017 7:00:00 PM
E. Europe Standard Time-(UTC+02:00) Chisinau 3/9/2017 7:00:00 PM
Syria Standard Time-(UTC+02:00) Damascus 3/9/2017 7:00:00 PM
West Bank Standard Time-(UTC+02:00) Gaza, Hebron 3/9/2017 7:00:00 PM
South Africa Standard Time-(UTC+02:00) Harare, Pretoria 3/9/2017 7:00:00 PM
FLE Standard Time-(UTC+02:00) Helsinki, Kyiv, Riga, Sofia, Tallinn, Vilnius 3/9/2017 7:00:00 PM
Israel Standard Time-(UTC+02:00) Jerusalem 3/9/2017 7:00:00 PM
Kaliningrad Standard Time-(UTC+02:00) Kaliningrad 3/9/2017 7:00:00 PM
Libya Standard Time-(UTC+02:00) Tripoli 3/9/2017 7:00:00 PM
Arabic Standard Time-(UTC+03:00) Baghdad 3/9/2017 8:00:00 PM
Turkey Standard Time-(UTC+03:00) Istanbul 3/9/2017 8:00:00 PM
Arab Standard Time-(UTC+03:00) Kuwait, Riyadh 3/9/2017 8:00:00 PM
Belarus Standard Time-(UTC+03:00) Minsk 3/9/2017 8:00:00 PM
Russian Standard Time-(UTC+03:00) Moscow, St. Petersburg, Volgograd 3/9/2017 8:00:00 PM
E. Africa Standard Time-(UTC+03:00) Nairobi 3/9/2017 8:00:00 PM
Iran Standard Time-(UTC+03:30) Tehran 3/9/2017 8:30:00 PM
Arabian Standard Time-(UTC+04:00) Abu Dhabi, Muscat 3/9/2017 9:00:00 PM
Astrakhan Standard Time-(UTC+04:00) Astrakhan, Ulyanovsk 3/9/2017 9:00:00 PM
Azerbaijan Standard Time-(UTC+04:00) Baku 3/9/2017 9:00:00 PM
Russia Time Zone 3-(UTC+04:00) Izhevsk, Samara 3/9/2017 9:00:00 PM
Mauritius Standard Time-(UTC+04:00) Port Louis 3/9/2017 9:00:00 PM
Georgian Standard Time-(UTC+04:00) Tbilisi 3/9/2017 9:00:00 PM
Caucasus Standard Time-(UTC+04:00) Yerevan 3/9/2017 9:00:00 PM
Afghanistan Standard Time-(UTC+04:30) Kabul 3/9/2017 9:30:00 PM
West Asia Standard Time-(UTC+05:00) Ashgabat, Tashkent 3/9/2017 10:00:00 PM
Ekaterinburg Standard Time-(UTC+05:00) Ekaterinburg 3/9/2017 10:00:00 PM
Pakistan Standard Time-(UTC+05:00) Islamabad, Karachi 3/9/2017 10:00:00 PM
India Standard Time-(UTC+05:30) Chennai, Kolkata, Mumbai, New Delhi 3/9/2017 10:30:00 PM
Sri Lanka Standard Time-(UTC+05:30) Sri Jayawardenepura 3/9/2017 10:30:00 PM
Nepal Standard Time-(UTC+05:45) Kathmandu 3/9/2017 10:45:00 PM
Central Asia Standard Time-(UTC+06:00) Astana 3/9/2017 11:00:00 PM
Bangladesh Standard Time-(UTC+06:00) Dhaka 3/9/2017 11:00:00 PM
Omsk Standard Time-(UTC+06:00) Omsk 3/9/2017 11:00:00 PM
Myanmar Standard Time-(UTC+06:30) Yangon (Rangoon) 3/9/2017 11:30:00 PM
SE Asia Standard Time-(UTC+07:00) Bangkok, Hanoi, Jakarta 3/10/2017 12:00:00 AM
Altai Standard Time-(UTC+07:00) Barnaul, Gorno-Altaysk 3/10/2017 12:00:00 AM
W. Mongolia Standard Time-(UTC+07:00) Hovd 3/10/2017 12:00:00 AM
North Asia Standard Time-(UTC+07:00) Krasnoyarsk 3/10/2017 12:00:00 AM
N. Central Asia Standard Time-(UTC+07:00) Novosibirsk 3/10/2017 12:00:00 AM
Tomsk Standard Time-(UTC+07:00) Tomsk 3/10/2017 12:00:00 AM
China Standard Time-(UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi 3/10/2017 1:00:00 AM
North Asia East Standard Time-(UTC+08:00) Irkutsk 3/10/2017 1:00:00 AM
Singapore Standard Time-(UTC+08:00) Kuala Lumpur, Singapore 3/10/2017 1:00:00 AM
W. Australia Standard Time-(UTC+08:00) Perth 3/10/2017 1:00:00 AM
Taipei Standard Time-(UTC+08:00) Taipei 3/10/2017 1:00:00 AM
Ulaanbaatar Standard Time-(UTC+08:00) Ulaanbaatar 3/10/2017 1:00:00 AM
North Korea Standard Time-(UTC+08:30) Pyongyang 3/10/2017 1:30:00 AM
Aus Central W. Standard Time-(UTC+08:45) Eucla 3/10/2017 1:45:00 AM
Transbaikal Standard Time-(UTC+09:00) Chita 3/10/2017 2:00:00 AM
Tokyo Standard Time-(UTC+09:00) Osaka, Sapporo, Tokyo 3/10/2017 2:00:00 AM
Korea Standard Time-(UTC+09:00) Seoul 3/10/2017 2:00:00 AM
Yakutsk Standard Time-(UTC+09:00) Yakutsk 3/10/2017 2:00:00 AM
Cen. Australia Standard Time-(UTC+09:30) Adelaide 3/10/2017 3:30:00 AM
AUS Central Standard Time-(UTC+09:30) Darwin 3/10/2017 2:30:00 AM
E. Australia Standard Time-(UTC+10:00) Brisbane 3/10/2017 3:00:00 AM
AUS Eastern Standard Time-(UTC+10:00) Canberra, Melbourne, Sydney 3/10/2017 4:00:00 AM
West Pacific Standard Time-(UTC+10:00) Guam, Port Moresby 3/10/2017 3:00:00 AM
Tasmania Standard Time-(UTC+10:00) Hobart 3/10/2017 4:00:00 AM
Vladivostok Standard Time-(UTC+10:00) Vladivostok 3/10/2017 3:00:00 AM
Lord Howe Standard Time-(UTC+10:30) Lord Howe Island 3/10/2017 4:00:00 AM
Bougainville Standard Time-(UTC+11:00) Bougainville Island 3/10/2017 4:00:00 AM
Russia Time Zone 10-(UTC+11:00) Chokurdakh 3/10/2017 4:00:00 AM
Magadan Standard Time-(UTC+11:00) Magadan 3/10/2017 4:00:00 AM
Norfolk Standard Time-(UTC+11:00) Norfolk Island 3/10/2017 4:00:00 AM
Sakhalin Standard Time-(UTC+11:00) Sakhalin 3/10/2017 4:00:00 AM
Central Pacific Standard Time-(UTC+11:00) Solomon Is., New Caledonia 3/10/2017 4:00:00 AM
Russia Time Zone 11-(UTC+12:00) Anadyr, Petropavlovsk-Kamchatsky 3/10/2017 5:00:00 AM
New Zealand Standard Time-(UTC+12:00) Auckland, Wellington 3/10/2017 6:00:00 AM
UTC+12-(UTC+12:00) Coordinated Universal Time+12 3/10/2017 5:00:00 AM
Fiji Standard Time-(UTC+12:00) Fiji 3/10/2017 5:00:00 AM
Kamchatka Standard Time-(UTC+12:00) Petropavlovsk-Kamchatsky - Old 3/10/2017 5:00:00 AM
Chatham Islands Standard Time-(UTC+12:45) Chatham Islands 3/10/2017 6:45:00 AM
Tonga Standard Time-(UTC+13:00) Nuku'alofa 3/10/2017 6:00:00 AM
Samoa Standard Time-(UTC+13:00) Samoa 3/10/2017 7:00:00 AM
Line Islands Standard Time-(UTC+14:00) Kiritimati Island 3/10/2017 7:00:00 AM

Webinar Registration

When I perform AD security assessments I always ask for a list of privileged users and the controls over that list. Then I collect real evidence from domain controllers and compare it to the list and controls provided. I've never once failed to find privileged users that management was not aware of. Ineffective controls or failure to follow controls certainly contributes to this; but let's also face that it's really difficult to keep a handle on everyone with admin access. There are so many ways to grant admin authority and there's no place in Windows you can go to see them all in one pane of glass. Let me count the ways:

  1. Built-in groups like Domain Admins (that's a gimmie)
  2. Groups nested in Domain Admins, et. al.
  3. Organizational unit permissions
  4. Admin equivalent rights on domain controllers
  5. Users with password reset authority over users
  6. Users with knowledge of any privileged service accounts
  7. Users with write access to GPOs applied to DCs or servers running applications with domain privileged access
  8. Users with access to any AD management solutions
    1. Or the OS or DB that hosts that solution
  9. Virtualization infrastructure admins
  10. Physical access

The biggest ones where I invariably have the most findings are 1-6.

In this real training for free ™ webinar I will show you how to assess and catalog all users with any level of privileged access to AD. I'll show you how to use tools like PowerShell and the “ds” commands to script as much of this as you can. Some of the most difficult tasks are:

  • Tracing out nested groups to get a flat, normalized list of everyone-ultimately a member of one of the built-in admin groups
  • Finding objects in the organizational unit hierarchy with non-inherited permissions

Once you've cataloged every privileged user, what's the next step? Remediation of course. Great. But that is just a point in time. Don't repeat this process every few months. That's neither efficient nor is it continuous security. Instead, how do you detect when new privileged access grants occur in any of the direct and indirect ways possible?

I'll show you what the Windows Security Log has to offer. Some of the events and their volume and noise aren't particularly pretty but it's possible.

Then Brad Bussie, from our sponsor STEALTHbits, will show you their 3-point solution that helps you assess, remediate and monitor all aspects of your environment but in particular I think you'll be impressed with the deep automated analysis they perform on the above issues. Some of the reports you'll see are amazing when you understand what went into compiling them.

First Name:   
Last Name:   
Work Email:  
Job Title:  

Your information will be shared with the sponsor.