Vtim
Vtim
Red Team Lead
DEVCORE

Vtim currently serves as the Red Team Lead at DEVCORE, specializing in researching Web and post-exploitation attack techniques. With extensive experience in Red Team Assessments, penetration testing, and educational training, he is also a CTFer and Bug Bounty Hunter.

Professional Experience:

  • Red Team Assessment experience at DEVCORE (3.5 years)
  • Experience in vulnerability reporting submissions: HackerOne, Bugcrowd, HITCON Zero Day
  • Member of the Synack Red Team
SPEECH
5/16 (Thu.) 09:30 - 10:00 7F 701G Blue Team Forum
分分鐘拿下整個網域- 關於 AD,你還疏忽了什麼?

According to DEVCORE's statistics from dozens of Red Team Assessments conducted over the past year, more than 50% of enterprise internal networks have misconfigurations related to Active Directory Certificate Services (AD CS). These misconfigurations allow attackers to gain domain admin privileges within minutes, even with just a low-privileged domain account.

In this presentation, we will present anonymized examples of these misconfigurations in various enterprises, demonstrate how attackers exploit them, and emphasize the importance of regularly assessing AD CS as a critical infrastructure component within an organization's internal network. We will also provide guidance on avoiding common configuration mistakes and mitigating measures for specific scenarios.