Protecting Public Safety with Purple Knight

“As a public safety entity, we seem to be a target for criminal activity,” said Micah Clark, Information Technology Director at Central Utah 911 and a user of Purple Knight, a free Active Directory security assessment tool from Semperis. “Making sure that our Active...

Identity Attack Watch: August 2022

Cyberattacks targeting Active Directory are on the upswing, putting pressure on AD, identity, and security teams to monitor the constantly shifting AD-focused threat landscape. To help IT pros better understand and guard against attacks involving AD, the Semperis...

SMTP Matching Abuse in Azure AD

In his TROOPERS19 talk (“I’m in your cloud … reading everyone’s email”), Dirk-jan Mollema discussed an issue he discovered that enabled the use of SMTP matching (also called soft matching) to synchronize Active Directory (AD) users to Azure AD, with the goal of...

Closing Attack Paths to Tier 0 Assets with Forest Druid

Active Directory is a complex system with numerous configurable settings, making it notoriously hard to secure. Design flaws, operational mistakes, and misconfigurations accumulate over time, exposing AD to a spectrum of attacks. For years, attackers have had the...

SIEM and SOAR—and Identity Security

Organizations are looking for cutting-edge technologies to facilitate increasing business demands. But as your organization grows, so does its attack surface. Understanding potential vulnerabilities—especially those related to Tier 0 identity assets like Active...

Power up Azure AD Security Assessments

Want to use the free Purple Knight tool to evaluate your Azure AD  security posture? To run Purple Knight in your Azure AD environment, you need to create and update the app registration in Azure AD with a defined and consented set of application permissions for the...