Top 10 Things to Stay Out of the News Ron Schlecht Intro Ron - - PowerPoint PPT Presentation

top 10 things to stay out of the news
SMART_READER_LITE
LIVE PREVIEW

Top 10 Things to Stay Out of the News Ron Schlecht Intro Ron - - PowerPoint PPT Presentation

Top 10 Things to Stay Out of the News Ron Schlecht Intro Ron Schlecht , Managing Partner 18 years of Information Security experience G Contracting, Law Enforcement, Consulting, CISO Founded BTB Security in 2006 Company Profile


slide-1
SLIDE 1

Top 10 Things to Stay Out of the News

Ron Schlecht

slide-2
SLIDE 2

Intro

  • Ron Schlecht, Managing Partner
  • 18 years of Information Security experience

– G Contracting, Law Enforcement, Consulting, CISO – Founded BTB Security in 2006

slide-3
SLIDE 3

Company Profile

  • The BTB Group, LLC / BTB Security

– Founded in 2006 – Offices in Philadelphia, Chicago, Austin – coverage nationally – Backgrounds include years of experience with Big Four and similarly sized organizations, and experience building, managing, and operating corporate security groups. – 3 partners

  • Brian Bailey, Managing Partner (Chicago)
  • Chris McGinley, Managing Partner (Philly)
  • Ron Schlecht, Founder / Managing Partner (Philly)

Company Profile

slide-4
SLIDE 4

What we do

We are hackers …well…not exactly like that

slide-5
SLIDE 5

These days

  • A lot of breaches in the

news

  • We see that a lot of

environments are vulnerable to simple issues

slide-6
SLIDE 6

What we find

  • Some attacks are

complicated…

  • But most take

advantage of simple misconfiguration

slide-7
SLIDE 7

Top Security Controls

This talk will focus on the top security controls that can be implemented with low cost and low impact to your network, ensuring maximum ROI of your Domain Admin’s valuable time.

slide-8
SLIDE 8

1-Separate DA from “everyday” Accounts

Domain Admin Account

slide-9
SLIDE 9

2-Separate DA Password Policy

slide-10
SLIDE 10

3-DA is Allowed to only Log in to Domain Controllers

slide-11
SLIDE 11

4-Delegate Rights to Users (Restrict User Access)

slide-12
SLIDE 12

4-Delegate Rights to Users (Restrict User Access)

slide-13
SLIDE 13

5-Disable Cached Credentials

slide-14
SLIDE 14

6-Microsoft Security Compliance Manager

slide-15
SLIDE 15

7-Disable NULL Sessions

slide-16
SLIDE 16

8-Disable LLMNR/NBNS Protocols

LL What? NB Who?

1)Hosts File 2)DNS Server 3)LLMNR Multicast or NBNS Broadcast

Link-Local Multicast Name Resolution and NetBIOS Naming Service

slide-17
SLIDE 17

8-Disable LLMNR/NBNS Protocols

slide-18
SLIDE 18

9-Set SMB Signing to Enabled and Required

http://btbsecurity.com/resources/videos/204-smbrelay-and- llmnr-zero-to-breach-in-ten-minutes

slide-19
SLIDE 19

10-Do Not Store Passwords within Group Policy Preferences (GPP)

slide-20
SLIDE 20

10-Do Not Store Passwords within Group Policy Preferences (GPP)

slide-21
SLIDE 21
slide-22
SLIDE 22

#Bonus 1 - Disable Interactive Logon for Service Accounts

slide-23
SLIDE 23

#Bonus 2 - Use Managed Service Accounts

slide-24
SLIDE 24

#Bonus 3 - Use NTLMv2 and Set it to Required

slide-25
SLIDE 25

#Bonus 4 - Who can Add Workstations to your Domain?

slide-26
SLIDE 26

#Bonus 5 - Disable Powershell and CMD

slide-27
SLIDE 27

Ron Schlecht

ron.schlecht@btbsecurity.com

Questions?