Windows, AD & Forests
Microsoft offers multiple versions of AD, specifically:
  1. 1.
    Active Directory Domain Services (AD DS)
  2. 2.
    Azure Active Directory (Azure AD)
  3. 3.
    Azure Active Directory Domain Services (Azure AD DS)
NTLM: SMB signing
Windows Virtualization-based Security (VBS): Mitigates kernel-based attacks (by multiple virtualized kernels)
How trusts work for Azure AD Domain Services
docsmsft
Golden ticket attacks: How they work — and how to defend against them
The Quest Blog
Pass the Hash Attack
Netwrix
Copy link