Friday, December 22, 2017

Advanced Threat Analytics–Attack Simulation and Demo – Part1

Advanced Threat Analytics–Attack Simulation and Demo–Part2
Advanced Threat Analytics–Attack Simulation and Demo–Part3
Microsoft Advanced Threat Analytics (ATA) is an user and entity behavior analytics solution to identify and protect protect organizations from advanced targeted attacks (APTs).  You can read more information about Microsoft Advanced Threat Analytics (ATA) here.  The purpose of this blog is to provide a few methods which can be used to simulate and demonstrate some of the basic attacks for demo and testing purpose.
Suspicious Activity Simulation #1 – ATA Gateway Stopped Communicating 
We will start with the most obvious one! – ATA communication issue.   In this scenario, I am using ATA Light Weight Gateway(LWGW).  In this case Microsoft Advanced Threat Analytics Gateway (ATAGateway) service should be running on Domain Controllers. 
To simulate this scenario,
  1. Identify all Domain Controllers from the forest/domain. You can use the following DSQUERY command to get all DCs from the domain.  
    • DsQuery Server -Forest
  2. Stop the ATAGateway service remotely
    • Here are a few scripts -  Script1 or Script2 or Script3 – if you want to go a script based approach
    • Or we can use a simple SC command – SC \\Lab-DC01 stop ATAGateway
    • image
You will receive the following high alert – ATA Gateway Stopped Communicating – in Health Center. 
Suspicious Activity Simulation #2Honey Token Account Activities
In general, the Honey Token accounts are non-interactive accounts.  These accounts can be dummy accounts for detect malicious activities.
To simulate this scenario,
  1. Create two 2 user accounts in Active Directory (ATA-Test1 and ATA-Test2)
  2. Add ATA-Test2 to Domain Admins group
  3. Get the SID of ATA-Test1 and ATA-Test2 using PowerShell or DSQUERY command
    • dsquery * -filter (samaccountname=ata-test1) -attr objectsid (Reference)
    • Get-ADUser Ata-test1 -Properties objectSID (Reference)
  4. Add this SID as Honey token accounts (ATA Console –> Configuration –> Detection –> Honeytoken Account SIDs). Save the configuration. 
  5. image
  6. Establish an integrative logon session using these accounts. You can RDP into a machine use these accounts
Honey Token accounts (non-sensitive)
You will receive the following alert/email with recommended actions in the ATA console. 
Honey Token accounts (Sensitive)
Since ATA-Test2 account is a domain admin account, you will receive the same alert with "Sensitive (S )" indicating that this account is a high privileged account in Active Directory. 
Suspicious Activity Simulation #3 – Massive Object Deletion
Bulk object deletion can be a suspicious activity in an Active Directory environment.  ATA can alert alert you based on massive object deletion activities. 
To simulate this scenario,
  1. Create a few users in Active directory. Here is a sample PowerShell  script which you can use to create test accounts in Active Directory
Import-module activedirectory
$pass = ConvertTo-SecureString "MyPassword0!" –asplaintext –force
for ($i=0;$i -lt 100;$i++)
$accountname = "Test-Account$i"
Write-Host "Creating $accountname" -NoNewline
New-ADUser –SamAccountName $accountname –name $accountname -OtherAttributes @{'description'="ATA Test User Account"} -Path "OU=Test Accounts,OU=User Accounts,DC=labanddemo,DC=com"
Set-ADAccountPassword –identity $accountname –NewPassword $pass
Write-Host "...Done"
  1. Make sure ATA is "learned" about these account.
  2. image
  3. Delete these accounts from Active Directory 
You will receive the Massive Object Deletion alert in the ATA console right away as shown below. 
Suspicious Activity Simulation #4 - Reconnaissance using DNS
The DNS or name resolution information in a network would be  useful reconnaissance information. In general, DNS data contains a list of all the servers and workstations and the mapping to their IP addresses. Verifying this  information may provide attackers with a detailed view of the environment allowing attackers to focus their efforts on the relevant entities. 
For this simulation, the plan is to perform a DNS zone lookup using NSLOOKUP LS command. 
To simulate this scenario,
  1. Logon to a remote server. 
  2. Open Command Prompt and run NSLOOKUP command
  3. From the NSLOOKUP window, run LS command to list the DNS zone
You will receive the following Reconnaissance using DNS alert the ATA console. 
Advanced Threat Analytics–Attack Simulation and Demo–Part2
Advanced Threat Analytics–Attack Simulation and Demo–Part3


Hi Santhosh, Sanjay here. I just wanted to say that over the years you've been sharing helpful info and helping people learn more about AD, please keep up the good work. Last week I wrote a post titled A Few Notable Names in Active Directory, and you're on the list :-)

Alright then, keep up the good work Santhosh!

Best wishes, Sanjay

I think this should be the best replica watch I have ever bought.Best UK Swiss watches I share this website with my friends. They are very happy, the price is so cheap,Fake rolex Watches and I can buy such a good watch.

I am sure that on you can learn a lot about teacher resume. It means a lot if you want to achieve success

Those ESL assignment writing services have an advantage of hiring the best English language coursework writing service company that is familiar with ESL assignment help services for their English Language Writing Services.

That’s a nice article, thank you for a great article. It helped me a lot. Keep it up Must Visit Epson Printer belgie

I am really enjoying your site.It’s simple, yet effective, thank you for this article.Now I have to share some information about How To Fix “mcafee Antivirus” problem. If you have any problem rearding Mcafee so click on this site:mcafee antivirus nummer belgie

I like your blog.You have done Excellent work. I appreciate.Here I want to inform all of you if you are looking for to resolve your Norton Antivirus problems,so you are in right place.we always available for your support.So whenever you need any help so just click on this link- norton Antivirus ondersteuningsnummer

I’m really impressed with your writing skills and also with the layout on your blog it's Very interesting to read.Now Here i would llike to share some information about HP Printer If you are facing any problem relate to your HP Printer's we wil resolve your queries at sam time.For any help please visit on our website:hp printer contact belgie

Excellent post. I certainly appreciate this website.Keep writing.well here if you want to Overcome the issues of Avast antivirus.Pick the Best Assistance over our site to resolve your queries.Visit us :avast antivirus ondersteuning

hi, your post is very helpful for me. Finally, I found exactly what i want. If need information regarding printers then you can visit our site Xerox Printer ondersteuning for help.

hi, Your post is very helpful for me, If you want to know more about antivirus then you can visit our site Canon Printer contacteren for help.

hi, Your post is very helpful for me,finally i got exactly what I want. If you want to know more about antivirus then you can visit our site Bitdefender belgie help.

Commenting as
Comment as:

hi, Your post is very helpful for me, finally i found exactly what i want , If you want to know more about antivirus then you can visit our site Kaspersky antivirus nummer for help.

When you setup or connect your HP printer with your PC framework, the extremely essential thing you need is the unaffected HP printer driver to hard with the printing procedure. Like the vast majority of the minimal gadgets or machines, HP printer likewise requires reasonable drivers first to introduce inside your framework so as to perform. Be that as it may, you can without much of a stretch download and introduce printer driver from .However, you can generally have the decision to physically download the driver and after that introduce it in your PC framework.

Writing in style and getting good compliments on the article is hard enough, to be honest, but you did it so calmly and with such a great feeling and got the job done. This item is owned with style and I give it a nice compliment. Better!
Cyber Security Training in Bangalore

The effectiveness of IEEE Project Domains depends very much on the situation in which they are applied. In order to further improve IEEE Final Year

Project Domains practices we need to explicitly describe and utilise our knowledge about software domains of software engineering Final Year Project

Domains for CSE
technologies. This paper suggests a modelling formalism for supporting systematic reuse of software engineering technologies

during planning of software projects and improvement programmes in Final Year Projects for CSE.

Software management seeks for decision support to identify technologies like JavaScript that meet best the goals and characteristics of a software

project or improvement programme. JavaScript Training in

Accessible experiences and repositories that effectively guide that technology selection are still lacking.

Aim of technology domain analysis is to describe the class of context situations (e.g., kinds of JavaScript software projects) in which a software

engineering technology JavaScript Training in Chennai can be applied successfully

The Angular Training covers a wide range of topics including Components, Angular Directives, Angular Services, Pipes, security fundamentals, Routing,

and Angular programmability. The new Angular TRaining will lay the foundation you need to specialise in Single Page Application developer. Angular Training

Thanks for information and keep updating us with valuable content and if possible provide us with

jibjab alternative|similar to hautelook|lola Iolani Momoa|Sydney Brooke Simpson|

This comment has been removed by the author.

writing these types of articles is very helpful to the people and this is the reason what makes people do visit a website frequently. muslim women gym Derby

Excellent Blog! I would like to thank you for the efforts you have made in writing this post. Gained lots fo knowledge.
Data Analytics Course

What an incredible message this is. Truly one of the best posts I have ever seen in my life. Wow, keep it up.
AI Courses in Bangalore

I feel very grateful that I read this. It is very helpful and very informative and I really learned a lot from it.
Data Science Course in Chennai

We have made order weed online USA to be a very easy and simple process for everyone to Buy marijuana online. We have successfully shipped thousands of weed for sale online orders around the world using extreme stealth, regardless of your country or state’s laws to buy marijuana online from dispensaries shipping worldwide. We offer reliable payment methods and we safeguard your packages, and your privacy is our main priority.

Order weed online USA
For more details contact us at:
Contact us on Text, WhatsApp or call
USA: +17202487228
EUROPE, UK: +31657792266
Email us: cannabis online The Best Cannabis Store for Mail Order Marijuana/
online dispensaries that ship
best online dispensary USA shipping
online marijuana dispensary home delivery
buy cannabis edibles online nationwide
online weed delivery California
mail order marijuana edibles online
Colorado marijuana dispensaries that ship
buy weed online
marijuana dispensaries that ship nationwide
mail order marijuana edibles online
cannabis delivery near me
online marijuana delivery nationwide
online dispensary mail order cheap
marijuana dispensary that ships everywhere
mail order dispensaries in USA
online dispensaries that ship anywhere in USA
mail order marijuana edibles online
best online dispensary USA shipping
best online marijuana dispensary
Colorado dispensaries that ship
buy cannabis edibles online nationwide
online dispensaries that ship
marijuana dispensary that ships everywhere
mail order cannabis from Colorado
Colorado mail order marijuana stores
marijuana dispensaries that ship nationwide
can you order marijuana online?
Colorado marijuana dispensaries that ship
marijuana dispensary that ships everywhere
mail order marijuana edibles online
can you order medical marijuana online?
mail order marijuana united states
California wholesale cannabis prices
mail order marijuana edibles online
Colorado marijuana for sale online
Colorado marijuana dispensaries that ship
marijuana dispensaries that ship nationwide
marijuana for sale by mail order Colorado
marijuana online store free shipping
marijuana online shopping
buy cannabis by post uk
buy legal cannabis in uk
buy hash online Amsterdam
buy hash uk delivery
buy hash online USA
best websites to buy weed
buy cannabis online uk delivery
buy weed online uk
marijuana online store free shipping
buying marijuana edibles online legal
buy marijuana online USA cheap
best online marijuana store
order marijuana online from Colorado
buying marijuana online legal
real weed for sale online
online weed delivery
cheap marijuana online
cheap marijuana online sales
cheap marijuana seeds USA
buy legal weed online cheap
marijuana for sale online
best online marijuana store
cheap marijuana stocks
weed online cheap
cheap weed Canada
cheap weed dispensary
reddit cheapest weed online
cheap bud Canada
cheap weed ca
cheap buds ca
cheap bud
where to get weed wholesale
wholesale weed USA
cheap wholesale weed
wholesale weed products
wholesale marijuana for sale
buy wholesale weed online
wholesale marijuana
wholesale weed prices
buy medical cannabis online
can i buy cannabis online
cannabis online store
USA cannabis seeds shop
cannabis seeds sold in USA
best place to buy cannabis seeds online
is buying cannabis online legal
cannabis seeds for sale online
best marijuana seeds by mail
best cannabis seed company
best cannabis seed banks
best online seed store
best online cannabis seed store
most trusted cannabis seed banks
best seed bank uk

Are you wondering how you can get your project written by an expert? At it's the easiest thing in the world! We have the expert assignment writers due to which we can provide the best help for the accounting homework help to our customers. has experts who can work super-fast without missing any requirements or hampering the quality of assignments. Our professional assignment helpers are trained to complete superior quality Assignment help within challenging deadlines. Many companies will provide to do this, but there’s just one that you can trust completely – If you choose our company, we will cover all aspects so that you receive remarkable writing in the shortest time. We will share all the perks which you can enjoy from our statistics homework help, assignment writing help service. Pay less and enjoy our wide slew of academic services to hand over a perfect paper to your professors within your deadlines. It is so easy to get in touch with us and, through a real-time chat, phone number or an email and you can be sure all your queries will be solved.

Thank you for sharing the useful post. A reader got a lot of information from this post and utilized it in their research. I also provide independent support for the outlook email. So if you are facing issues with the outlook account then contact me for outlook customer service.
Also Read: Outlook not connecting to server | Outlook send receive error | outlook cannot connect to server | outlook not receiving emails.

It is really helpful for readers who are looking for online assignment help. I also work in the same area and provide assignment help to students for various subjects. Most of my students are from parts of the UK, USA, India, and Singapore. Our team of professors are from reputed Colleges. Visit our website to know our areas of expertise and let us know if we can be of help. Also Read:
how many pages is 1000 words,
how many pages is 2000 words,
how many pages is 1500 words,
about us
informative speech subjects.

Your post is very helpful and information is reliable. I am satisfied with your post. Thank you so much for sharing this wonderful post. I recommend you to visit 50 most popular women.

Buy real passport online ..
buy counterfeit money online …
buy genuine driving licence ...
buy ssn online ...
buy residence permit online ...
buy counterfeit money with credit card ....
buy ssn card ...
buy real driver license online ...
buy registered driving license ...
buy real documents online ...

Look no further for Assignment Help in Canada, as we have experienced professionals who can craft your content in no time. We deliver authentic assignments that are written from scratch by gathering relevant information from reliable sources.

If you want to progress in academic writing, you need to count every single step. Ensure to follow the right path and add essential qualities to your writing curve. Asking the Assignment Help of someone to write my assignment may sound instant solution but it can help you to boost your learning exposure. Write my assignment | Homework Help | Accounting Assignment Help

Nice post! If you want someone to assist you with online Assignment help then you can reach out to us. By visiting our site you can get access to some of the qualified assignment writers and they will help you.

You have done a great job on this article. It’s very readable and highly intelligent.
You have even managed to make it understandable and easy to read. You have some real writing talent. Thank you
amazon quiz
gk quiz
general knowledge quiz
english stories
bedtime stories
short stories kids
english short stories
short bedtime stories
english stories collection

Are you unable to get Assignment help in UK? Don’t worry! We offer you the best quality assignment assistance. We have highly qualified writers who will provide you supreme quality help regarding your assignment.

I'm impressed after reading your article titled, How to activate Roku using You have explained Roku com/link activation steps clearly.My review rating for the blog post would be 100 Starz. Keep posting more interesting blogs
Let me share the post with new users who do not know how to activate Roku

Excellent information you have shared, thanks for taking the time to share with us such a great article. I really appreciate your work.
career in fashion design
courses in design
graphic designing
career in graphic design
career in interior design

Acadecraft leverages cutting-edge tools and technologies to enhance classroom learning. Here, the proficient and certified subject matter experts enhance classroom learning to provide interactive education. Clients receive high-quality video solutions for education. Also, the platform is the industry leader in educational content and quality solutions.
online language translation services
subtitle translation services

For getting instant Assignment Help , you can check our website and order assistance. Assignments are written on a priority basis and delivered to you without any delay. If you choose our writing services then you will have thousands of other advantages as well.

Students of Engineering and especially, Mechanical Engineering, have to continuously attend classes and seminars, submit assignments and homework. Be present for the practicals whenever needed, give tests and exams, and so very often intern or work part-time. With so many things to do, it is but natural to lose patience and feel that everything is unfair. Our experts at Help in Homework are here to help you grow academically and personally and feel lucky. They offer customized mechanical engineering assignment help at an absolute reduced cost so that you score as per your desire and be one of the top scorers of your class. Our experts will make certain that they remove all your hurdles effectively

Forget paying hundreds for paid guest posts backlinks based on organic traffic or domain authority alone. Great Guest Posts is the best and professional link-building Platform and fits with your pocket. Find a new path to reach your niche audience in moments by browsing through our extensive catalog of websites that accept guest posts!

If you feel you can afford an expert only when you have a good amount to spare, you are wrong. We at Help in Homework offer excellent and personalized If you feel you can afford an expert only when you have a good amount to spare, you are wrong. We at Help in Homework offer excellent and personalized Physics homework help at an unbelievably low cost. We are aware that many students are already working part-time to fund their education or to be independent; so we have a very affordable cost structure. Our experts are, however, top rankers of their academic institutes and have real experience of helping students with their assignments and homework. They will assiduously complete your homework on time and ensure that it is free from plagiarism so that you easily become one of the top rankers of your class too. at an unbelievably low cost. We are aware that many students are already working part-time to fund their education or to be independent; so we have a very affordable cost structure. Our experts are, however, top rankers of their academic institutes and have real experience of helping students with their assignments and homework. They will assiduously complete your homework on time and ensure that it is free from plagiarism so that you easily become one of the top rankers of your class too.

We at Help In Homework have selected the best and brilliant experts after a stringent process. Our experts have academic and professional credentials to match up any of your problems. They will provide you with personalized Essay Writing Services at a tremendously low price. Our experts have consistently helped students around the world with their specialized courses and subjects as they know it like the back of their hand. Our experts will complete your assignment within the deadline and help you score the perfect A grade. Trust our experts and be sure to win the hearts of your professor and classmates.

Need to watch Chinese Drama Online but don’t have genuine websites? You don’t have to worry about it. In this post, we have mentioned the best websites to watch Chinese Drama Online in Mandarin language or with English subtitles. It is a great way to learn the Chinese language with fun. So, let’s check how to watch Chinese dramas online and learn the Chinese language dramatically.

Algebra Homework Help better understand this; thus, we attempt to provide students with unique assignment help to keep them out of trouble. We have specialist assignment helpers on staff, allowing us to deliver the best assignment help to our consumers. Students who want to get good scores can use our assignment writing service and rest, knowing that they will get work that will never let them down.

Surfing the valuable and industry oriented content is my choice. That’s why I am internet savvy to know to dig out the amazing piece to increase our experience. Our Assignment Helper service chain is doing the best approach to let reflect valuable content effort in their work.

There was a delay with my original order for the boxes custom donut boxes but once they got them back in stock I received very useful large blue plastic boxes.

Website is very clear and easy to navigate through.custom donut boxes Clear descriptions of items available, easy check out and fast delivery.

Hi, I love to see your recent post for expanding the knowledge set as much as I can. We like to see latest work with the proper linking of Assignment Help Online service.

Wow! Really a nice topic. College and university students have to write different types of academic papers, and coursework is one of them. To write a complete thesis, a student must first choose an effective topic. This stage is one of the most important in writing a Coursework help. A student must find a captivating topic that requires investigation and which can be developed into interesting and informative independent research.

Clenbuterol has become popular as a weight loss supplement. It has properties similar to those of salbutamol. Order now from official website of mediseller. This medicine available with the name clenbuterol 40mcg.

Do you also want Assignment help? We lend expert writers for assisting you with the projects. Our qualified writers will assist you with everything. You will get 100% original content within the deadline. Hire our assignment helper online and finish your project works.

Post a Comment

Popular Posts


Twitter Delicious Facebook Digg Stumbleupon Favorites More