• Cyber
  • Aug 13, 2020
  • By QOMPLX

SecurityGuyTV: Jason Crabtree on Kerberos and Active Directory Security

SecurityGuyTV: Jason Crabtree on Kerberos and Active Directory Security

Jason Crabtree, QOMPLX CEO and co-founder, was interviewed by Chuck Harold, host of SecurityGuyTV.com, for Episode 1592. They discussed Kerberos and Active Directory security vulnerabilities.

In the interview, Crabtree explained how Active Directory is designed to figure out ‘who can do what to whom’ in an IT environment. Maintaining that web of connections is one of the major challenges for an organization, he said.

Active Directory in turn relies on Kerberos for the security of its transactions and QOMPLX defends against Kerberos exploitations.

One of the biggest mistakes organizations make is assuming "users are who they say they are," Crabtree told Harold in the interview, noting the ability of attackers to impersonate legitimate, credentialed users. "Anything built on this assumption is fundamentally flawed."

QOMPLX focuses on large-scale analytics and operational risk in particular. The company works to monitor and validate Kerberos, and does so for some of the world’s premier brands.

Watch the full interview here.

You might also be interested in

The path to Trusted Authentication via visibility, detection and analytics

The path to Trusted Authentication via visibility, detection and analytics

Getting to Trusted Authentication

Read more
Q:CYBER Spots Lateral Movement as Used in the SolarWinds (Sunburst) Calamity

Q:CYBER Spots Lateral Movement as Used in the SolarWinds (Sunburst) Calamity

QOMPLX’s leading Q:CYBER software suite detections include Kerberoasting and Golden Ticket attacks, both of which have been reported as being leveraged during lateral movement phases against federal agencies and commercial entities over the course of several months.

Read more
QOMPLX Teams With Splunk To Slam the Door on Lateral Movement

QOMPLX Teams With Splunk To Slam the Door on Lateral Movement

QOMPLX’s Q:CYBER integrates with Splunk Enterprise and Splunk Cloud, providing much-needed visibility into attackers’ lateral movements, including Kerberos ticket forgeries and other attacks on Active Directory.

Read more
Request a Demo

Interested in learning more?

Subscribe today to stay informed and get regular updates from QOMPLX.