Anatomy of a Hack: Hands-on Red Teaming with the “Zerologon” Netlogon Elevation of Privilege Vulnerability with Mimikatz Integration

11/3/2020 12:00:00 PM [(UTC-05:00) Eastern Time (US & Canada)] - Can't make the live event? Register anyway to receive a link to the recording.

Show/Hide All Time Zones

All Time Zones

Dateline Standard Time-(UTC-12:00) International Date Line West 11/3/2020 5:00:00 AM
UTC-11-(UTC-11:00) Coordinated Universal Time-11 11/3/2020 6:00:00 AM
Aleutian Standard Time-(UTC-10:00) Aleutian Islands 11/3/2020 7:00:00 AM
Hawaiian Standard Time-(UTC-10:00) Hawaii 11/3/2020 7:00:00 AM
Marquesas Standard Time-(UTC-09:30) Marquesas Islands 11/3/2020 7:30:00 AM
Alaskan Standard Time-(UTC-09:00) Alaska 11/3/2020 8:00:00 AM
UTC-09-(UTC-09:00) Coordinated Universal Time-09 11/3/2020 8:00:00 AM
Yukon Standard Time-(UTC-07:00) Yukon 11/3/2020 10:00:00 AM
Pacific Standard Time (Mexico)-(UTC-08:00) Baja California 11/3/2020 9:00:00 AM
UTC-08-(UTC-08:00) Coordinated Universal Time-08 11/3/2020 9:00:00 AM
Pacific Standard Time-(UTC-08:00) Pacific Time (US & Canada) 11/3/2020 9:00:00 AM
US Mountain Standard Time-(UTC-07:00) Arizona 11/3/2020 10:00:00 AM
Mountain Standard Time (Mexico)-(UTC-07:00) Chihuahua, La Paz, Mazatlan 11/3/2020 10:00:00 AM
Mountain Standard Time-(UTC-07:00) Mountain Time (US & Canada) 11/3/2020 10:00:00 AM
Central America Standard Time-(UTC-06:00) Central America 11/3/2020 11:00:00 AM
Central Standard Time-(UTC-06:00) Central Time (US & Canada) 11/3/2020 11:00:00 AM
Easter Island Standard Time-(UTC-06:00) Easter Island 11/3/2020 12:00:00 PM
Central Standard Time (Mexico)-(UTC-06:00) Guadalajara, Mexico City, Monterrey 11/3/2020 11:00:00 AM
Canada Central Standard Time-(UTC-06:00) Saskatchewan 11/3/2020 11:00:00 AM
SA Pacific Standard Time-(UTC-05:00) Bogota, Lima, Quito, Rio Branco 11/3/2020 12:00:00 PM
Eastern Standard Time (Mexico)-(UTC-05:00) Chetumal 11/3/2020 12:00:00 PM
Eastern Standard Time-(UTC-05:00) Eastern Time (US & Canada) 11/3/2020 12:00:00 PM
Haiti Standard Time-(UTC-05:00) Haiti 11/3/2020 12:00:00 PM
Cuba Standard Time-(UTC-05:00) Havana 11/3/2020 12:00:00 PM
US Eastern Standard Time-(UTC-05:00) Indiana (East) 11/3/2020 12:00:00 PM
Turks And Caicos Standard Time-(UTC-05:00) Turks and Caicos 11/3/2020 12:00:00 PM
Paraguay Standard Time-(UTC-04:00) Asuncion 11/3/2020 2:00:00 PM
Atlantic Standard Time-(UTC-04:00) Atlantic Time (Canada) 11/3/2020 1:00:00 PM
Venezuela Standard Time-(UTC-04:00) Caracas 11/3/2020 1:00:00 PM
Central Brazilian Standard Time-(UTC-04:00) Cuiaba 11/3/2020 1:00:00 PM
SA Western Standard Time-(UTC-04:00) Georgetown, La Paz, Manaus, San Juan 11/3/2020 1:00:00 PM
Pacific SA Standard Time-(UTC-04:00) Santiago 11/3/2020 2:00:00 PM
Newfoundland Standard Time-(UTC-03:30) Newfoundland 11/3/2020 1:30:00 PM
Tocantins Standard Time-(UTC-03:00) Araguaina 11/3/2020 2:00:00 PM
E. South America Standard Time-(UTC-03:00) Brasilia 11/3/2020 2:00:00 PM
SA Eastern Standard Time-(UTC-03:00) Cayenne, Fortaleza 11/3/2020 2:00:00 PM
Argentina Standard Time-(UTC-03:00) City of Buenos Aires 11/3/2020 2:00:00 PM
Greenland Standard Time-(UTC-03:00) Greenland 11/3/2020 2:00:00 PM
Montevideo Standard Time-(UTC-03:00) Montevideo 11/3/2020 2:00:00 PM
Magallanes Standard Time-(UTC-03:00) Punta Arenas 11/3/2020 2:00:00 PM
Saint Pierre Standard Time-(UTC-03:00) Saint Pierre and Miquelon 11/3/2020 2:00:00 PM
Bahia Standard Time-(UTC-03:00) Salvador 11/3/2020 2:00:00 PM
UTC-02-(UTC-02:00) Coordinated Universal Time-02 11/3/2020 3:00:00 PM
Mid-Atlantic Standard Time-(UTC-02:00) Mid-Atlantic - Old 11/3/2020 3:00:00 PM
Azores Standard Time-(UTC-01:00) Azores 11/3/2020 4:00:00 PM
Cape Verde Standard Time-(UTC-01:00) Cabo Verde Is. 11/3/2020 4:00:00 PM
UTC-(UTC) Coordinated Universal Time 11/3/2020 5:00:00 PM
GMT Standard Time-(UTC+00:00) Dublin, Edinburgh, Lisbon, London 11/3/2020 5:00:00 PM
Greenwich Standard Time-(UTC+00:00) Monrovia, Reykjavik 11/3/2020 5:00:00 PM
Sao Tome Standard Time-(UTC+00:00) Sao Tome 11/3/2020 5:00:00 PM
Morocco Standard Time-(UTC+01:00) Casablanca 11/3/2020 6:00:00 PM
W. Europe Standard Time-(UTC+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna 11/3/2020 6:00:00 PM
Central Europe Standard Time-(UTC+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague 11/3/2020 6:00:00 PM
Romance Standard Time-(UTC+01:00) Brussels, Copenhagen, Madrid, Paris 11/3/2020 6:00:00 PM
Central European Standard Time-(UTC+01:00) Sarajevo, Skopje, Warsaw, Zagreb 11/3/2020 6:00:00 PM
W. Central Africa Standard Time-(UTC+01:00) West Central Africa 11/3/2020 6:00:00 PM
Jordan Standard Time-(UTC+02:00) Amman 11/3/2020 7:00:00 PM
GTB Standard Time-(UTC+02:00) Athens, Bucharest 11/3/2020 7:00:00 PM
Middle East Standard Time-(UTC+02:00) Beirut 11/3/2020 7:00:00 PM
Egypt Standard Time-(UTC+02:00) Cairo 11/3/2020 7:00:00 PM
E. Europe Standard Time-(UTC+02:00) Chisinau 11/3/2020 7:00:00 PM
Syria Standard Time-(UTC+02:00) Damascus 11/3/2020 7:00:00 PM
West Bank Standard Time-(UTC+02:00) Gaza, Hebron 11/3/2020 7:00:00 PM
South Africa Standard Time-(UTC+02:00) Harare, Pretoria 11/3/2020 7:00:00 PM
FLE Standard Time-(UTC+02:00) Helsinki, Kyiv, Riga, Sofia, Tallinn, Vilnius 11/3/2020 7:00:00 PM
Israel Standard Time-(UTC+02:00) Jerusalem 11/3/2020 7:00:00 PM
Kaliningrad Standard Time-(UTC+02:00) Kaliningrad 11/3/2020 7:00:00 PM
Sudan Standard Time-(UTC+02:00) Khartoum 11/3/2020 7:00:00 PM
Libya Standard Time-(UTC+02:00) Tripoli 11/3/2020 7:00:00 PM
Namibia Standard Time-(UTC+02:00) Windhoek 11/3/2020 7:00:00 PM
Arabic Standard Time-(UTC+03:00) Baghdad 11/3/2020 8:00:00 PM
Turkey Standard Time-(UTC+03:00) Istanbul 11/3/2020 8:00:00 PM
Arab Standard Time-(UTC+03:00) Kuwait, Riyadh 11/3/2020 8:00:00 PM
Belarus Standard Time-(UTC+03:00) Minsk 11/3/2020 8:00:00 PM
Russian Standard Time-(UTC+03:00) Moscow, St. Petersburg 11/3/2020 8:00:00 PM
E. Africa Standard Time-(UTC+03:00) Nairobi 11/3/2020 8:00:00 PM
Iran Standard Time-(UTC+03:30) Tehran 11/3/2020 8:30:00 PM
Arabian Standard Time-(UTC+04:00) Abu Dhabi, Muscat 11/3/2020 9:00:00 PM
Astrakhan Standard Time-(UTC+04:00) Astrakhan, Ulyanovsk 11/3/2020 9:00:00 PM
Azerbaijan Standard Time-(UTC+04:00) Baku 11/3/2020 9:00:00 PM
Russia Time Zone 3-(UTC+04:00) Izhevsk, Samara 11/3/2020 9:00:00 PM
Mauritius Standard Time-(UTC+04:00) Port Louis 11/3/2020 9:00:00 PM
Saratov Standard Time-(UTC+04:00) Saratov 11/3/2020 9:00:00 PM
Georgian Standard Time-(UTC+04:00) Tbilisi 11/3/2020 9:00:00 PM
Volgograd Standard Time-(UTC+04:00) Volgograd 11/3/2020 9:00:00 PM
Caucasus Standard Time-(UTC+04:00) Yerevan 11/3/2020 9:00:00 PM
Afghanistan Standard Time-(UTC+04:30) Kabul 11/3/2020 9:30:00 PM
West Asia Standard Time-(UTC+05:00) Ashgabat, Tashkent 11/3/2020 10:00:00 PM
Ekaterinburg Standard Time-(UTC+05:00) Ekaterinburg 11/3/2020 10:00:00 PM
Pakistan Standard Time-(UTC+05:00) Islamabad, Karachi 11/3/2020 10:00:00 PM
Qyzylorda Standard Time-(UTC+05:00) Qyzylorda 11/3/2020 10:00:00 PM
India Standard Time-(UTC+05:30) Chennai, Kolkata, Mumbai, New Delhi 11/3/2020 10:30:00 PM
Sri Lanka Standard Time-(UTC+05:30) Sri Jayawardenepura 11/3/2020 10:30:00 PM
Nepal Standard Time-(UTC+05:45) Kathmandu 11/3/2020 10:45:00 PM
Central Asia Standard Time-(UTC+06:00) Astana 11/3/2020 11:00:00 PM
Bangladesh Standard Time-(UTC+06:00) Dhaka 11/3/2020 11:00:00 PM
Omsk Standard Time-(UTC+06:00) Omsk 11/3/2020 11:00:00 PM
Myanmar Standard Time-(UTC+06:30) Yangon (Rangoon) 11/3/2020 11:30:00 PM
SE Asia Standard Time-(UTC+07:00) Bangkok, Hanoi, Jakarta 11/4/2020 12:00:00 AM
Altai Standard Time-(UTC+07:00) Barnaul, Gorno-Altaysk 11/4/2020 12:00:00 AM
W. Mongolia Standard Time-(UTC+07:00) Hovd 11/4/2020 12:00:00 AM
North Asia Standard Time-(UTC+07:00) Krasnoyarsk 11/4/2020 12:00:00 AM
N. Central Asia Standard Time-(UTC+07:00) Novosibirsk 11/4/2020 12:00:00 AM
Tomsk Standard Time-(UTC+07:00) Tomsk 11/4/2020 12:00:00 AM
China Standard Time-(UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi 11/4/2020 1:00:00 AM
North Asia East Standard Time-(UTC+08:00) Irkutsk 11/4/2020 1:00:00 AM
Singapore Standard Time-(UTC+08:00) Kuala Lumpur, Singapore 11/4/2020 1:00:00 AM
W. Australia Standard Time-(UTC+08:00) Perth 11/4/2020 1:00:00 AM
Taipei Standard Time-(UTC+08:00) Taipei 11/4/2020 1:00:00 AM
Ulaanbaatar Standard Time-(UTC+08:00) Ulaanbaatar 11/4/2020 1:00:00 AM
Aus Central W. Standard Time-(UTC+08:45) Eucla 11/4/2020 1:45:00 AM
Transbaikal Standard Time-(UTC+09:00) Chita 11/4/2020 2:00:00 AM
Tokyo Standard Time-(UTC+09:00) Osaka, Sapporo, Tokyo 11/4/2020 2:00:00 AM
North Korea Standard Time-(UTC+09:00) Pyongyang 11/4/2020 2:00:00 AM
Korea Standard Time-(UTC+09:00) Seoul 11/4/2020 2:00:00 AM
Yakutsk Standard Time-(UTC+09:00) Yakutsk 11/4/2020 2:00:00 AM
Cen. Australia Standard Time-(UTC+09:30) Adelaide 11/4/2020 3:30:00 AM
AUS Central Standard Time-(UTC+09:30) Darwin 11/4/2020 2:30:00 AM
E. Australia Standard Time-(UTC+10:00) Brisbane 11/4/2020 3:00:00 AM
AUS Eastern Standard Time-(UTC+10:00) Canberra, Melbourne, Sydney 11/4/2020 4:00:00 AM
West Pacific Standard Time-(UTC+10:00) Guam, Port Moresby 11/4/2020 3:00:00 AM
Tasmania Standard Time-(UTC+10:00) Hobart 11/4/2020 4:00:00 AM
Vladivostok Standard Time-(UTC+10:00) Vladivostok 11/4/2020 3:00:00 AM
Lord Howe Standard Time-(UTC+10:30) Lord Howe Island 11/4/2020 4:00:00 AM
Bougainville Standard Time-(UTC+11:00) Bougainville Island 11/4/2020 4:00:00 AM
Russia Time Zone 10-(UTC+11:00) Chokurdakh 11/4/2020 4:00:00 AM
Magadan Standard Time-(UTC+11:00) Magadan 11/4/2020 4:00:00 AM
Norfolk Standard Time-(UTC+11:00) Norfolk Island 11/4/2020 5:00:00 AM
Sakhalin Standard Time-(UTC+11:00) Sakhalin 11/4/2020 4:00:00 AM
Central Pacific Standard Time-(UTC+11:00) Solomon Is., New Caledonia 11/4/2020 4:00:00 AM
Russia Time Zone 11-(UTC+12:00) Anadyr, Petropavlovsk-Kamchatsky 11/4/2020 5:00:00 AM
New Zealand Standard Time-(UTC+12:00) Auckland, Wellington 11/4/2020 6:00:00 AM
UTC+12-(UTC+12:00) Coordinated Universal Time+12 11/4/2020 5:00:00 AM
Fiji Standard Time-(UTC+12:00) Fiji 11/4/2020 5:00:00 AM
Kamchatka Standard Time-(UTC+12:00) Petropavlovsk-Kamchatsky - Old 11/4/2020 5:00:00 AM
Chatham Islands Standard Time-(UTC+12:45) Chatham Islands 11/4/2020 6:45:00 AM
UTC+13-(UTC+13:00) Coordinated Universal Time+13 11/4/2020 6:00:00 AM
Tonga Standard Time-(UTC+13:00) Nuku'alofa 11/4/2020 6:00:00 AM
Samoa Standard Time-(UTC+13:00) Samoa 11/4/2020 7:00:00 AM
Line Islands Standard Time-(UTC+14:00) Kiritimati Island 11/4/2020 7:00:00 AM

Webinar Registration

In August, Microsoft announced the release of a patch to address an attacker’s ability to establish a Netlogon secure channel to a domain controller via the Netlogon Remote Protocol (MS-NRPC) under CVE-2020-1472. Using a weak cryptographic algorithm in Netlogon’s authentication process, the attacker is able to achieve an elevation in privileges by impersonating any account desired and have control over all of Active Directory. Windows Server OSes from Server 2008 through 2019 are vulnerable to this attack and require an immediate update.

Dubbed Zerologon, this vulnerability is only partially patched today, with Microsoft admittedly only addressing how the secure RPC channel encryption is established, leaving the enforcement of the secured channel to be handled manually today and required in an update to be released in February of 2021.

Weaknesses in Microsoft’s cryptography are nothing new; the Curveball vulnerability from earlier this year took advantage of Windows crypt32.dll to create false certificates allowing for websites, applications, and systems to appear trusted. Curveball’s success put the attacker’s focus squarely on Microsoft’s cryptography, with Zerologon being indicative that additional vulnerability was found.

Microsoft isn’t alone in this; cryptography is strong but many implementations are weak. It’s hard to do cryptography right.

Mimikatz already has integrated support for Zerologon, making the exploitation of domain controllers and identifying easily compromised credentials an even easier task for attackers.

In this Anatomy of a Hack session, I’ll discuss the details around the vulnerability, how it works, and what’s at risk.

We’re going totally hands-on and live with this one! The extremely smart Kevin Breen, Director Cyber Threat Research at Immersive Labs, will demonstrate how to use this attack in red teaming, using their hands-on training platform.

He’ll also discuss how to effectively perform blue team efforts, including:

  • Detection of non-compliance devices
  • Identification of denied connections (indicating a potential attempt)
  • What details are available to respond to suspected attacks

This real training for free event will be jam packed with technical detail and real-world application. Register today!

First Name:   
Last Name:   
Work Email:  
Job Title:  

Your information will be shared with the sponsor.

By clicking "Submit", you're agreeing to our Privacy Policy and consenting to be contacted by us.



Additional Resources