From fe3e4895a5b0afc6d92f80cc265526ac7d10650e Mon Sep 17 00:00:00 2001 From: carel-v98 <109933205+carel-v98@users.noreply.github.com> Date: Fri, 27 Sep 2024 09:20:52 +0800 Subject: [PATCH] ASD Publishes Joint Advisory - 20240927001 --- .../20240927001-ASD-Publishes-Joint-Advisory.md | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) create mode 100644 docs/advisories/20240927001-ASD-Publishes-Joint-Advisory.md diff --git a/docs/advisories/20240927001-ASD-Publishes-Joint-Advisory.md b/docs/advisories/20240927001-ASD-Publishes-Joint-Advisory.md new file mode 100644 index 00000000..3bd49868 --- /dev/null +++ b/docs/advisories/20240927001-ASD-Publishes-Joint-Advisory.md @@ -0,0 +1,16 @@ +# ASD Publishes Joint Advisory - 20240927001 + +## Overview + +The Australian Signals Directorate Australian Cyber Security Centre (ASD ACSC), the Cybersecurity and Infrastructure Security Agency (CISA), and other U.S. and international partners released the joint guide on **Detecting and Mitigating Active Directory Compromises** + +## What has been observed? + +This guidance aims to inform organisations about 17 common techniques used to target Active Directory as observed by the authoring agencies. This guidance provides an overview of each technique and how it can be leveraged by malicious actors, and recommended strategies to mitigate these techniques. By implementing the recommendations in this guidance, organisations can significantly improve their Active Directory security, and therefore their overall network security, to prevent intrusions by malicious actors. + +## Recommendation + +The WA SOC recommends: +- Review the **ASD Advisory:** +- Review **Appendix A: Active Directory security controls** and implement these controls. +- Review **Appendix B -- Active Directory events** and ensure that the recommended events are being logged. \ No newline at end of file