{"id":5837,"date":"2022-02-14T12:46:03","date_gmt":"2022-02-14T16:46:03","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=5837"},"modified":"2022-02-14T17:16:05","modified_gmt":"2022-02-14T21:16:05","slug":"how-to-recognize-and-prevent-active-directory-attacks","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/","title":{"rendered":"How to Recognize and Prevent Active Directory Attacks"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-5839\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2022\/02\/How-to-Recognize-and-Prevent-Active-Directory-Attacks.jpg\" alt=\"Active Directory Attacks\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2022\/02\/How-to-Recognize-and-Prevent-Active-Directory-Attacks.jpg 800w, https:\/\/solutionsreview.com\/identity-management\/files\/2022\/02\/How-to-Recognize-and-Prevent-Active-Directory-Attacks-300x150.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2022\/02\/How-to-Recognize-and-Prevent-Active-Directory-Attacks-768x384.jpg 768w, https:\/\/solutionsreview.com\/identity-management\/files\/2022\/02\/How-to-Recognize-and-Prevent-Active-Directory-Attacks-540x270.jpg 540w, https:\/\/solutionsreview.com\/identity-management\/files\/2022\/02\/How-to-Recognize-and-Prevent-Active-Directory-Attacks-162x81.jpg 162w, https:\/\/solutionsreview.com\/identity-management\/files\/2022\/02\/How-to-Recognize-and-Prevent-Active-Directory-Attacks-360x180.jpg 360w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify;\"><strong><em>As part of Solutions Review&#8217;s Premium Content Series\u2014a collection of contributed columns written by industry experts in maturing software categories\u2014<span class=\"TextRun SCXW248727732 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW248727732 BCX0\">Carolyn Crandall, the <\/span><\/span><\/em><\/strong><em><b>Chief Security Advocate at <a href=\"https:\/\/www.attivonetworks.com\/\" target=\"_blank\" rel=\"noopener\">Attivo Networks<\/a>, shares some expert insights on how to recognize and avoid active directory attacks.<\/b><\/em><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3778 alignleft\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2022\/01\/SR-Premium-Content.gif\" alt=\"\" width=\"84\" height=\"88\" \/>Active Directory (AD) is under attack. That isn&#8217;t an exaggeration, an intentionally provocative statement, or a clickbait headline, but a fact. Five years ago, <\/span><a href=\"https:\/\/www.zdnet.com\/article\/active-directory-czar-rallies-industry-for-better-security-identity\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">Microsoft stated<\/span><\/a><span data-contrast=\"auto\"> that more than 95 million AD accounts come under attack daily. That number has exploded, with <\/span><a href=\"https:\/\/venturebeat.com\/2022\/02\/03\/microsoft-dangerous-mismatch-in-security-battle-due-to-slow-mfa-adoption\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">Microsoft sharing<\/span><\/a><span data-contrast=\"auto\"> that in 2021, Azure Active Directory alone saw more than 25.6 billion brute force attacks. It isn&#8217;t difficult to see what makes AD an attractive target for attackers: it effectively serves as the GPS for the entire organization, handling identity and authentication services for more than 90% of today&#8217;s enterprises. Compromising AD can give today&#8217;s attackers a skeleton key to the entire network.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Unfortunately, too many of these attacks are succeeding. One of the primary reasons for this is that AD is notoriously difficult to secure. Because it controls authentication across the network, every user, device, application, or identity on the web requires some level of access to AD, making it challenging to distinguish suspicious activities from standard behavior patterns without certain protections in place. <\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Fortunately, modern <strong><a href=\"https:\/\/solutionsreview.com\/identity-management\/get-a-free-identity-and-access-management-software-solutions-buyers-guide\/\" target=\"_blank\" rel=\"noopener\">identity protection tools<\/a><\/strong> like those in the emerging Identity Detection and Response (IDR) category give defenders a better idea of what to look for\u2014and help them detect and deflect adversaries before they can escalate their attacks.<\/span><\/p>\n<div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a class=\"iam-inject\" href=\"https:\/\/suggestionengine.solutionsreview.com\/buyer\/signup\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1682\" title=\"\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2021\/02\/Identity_Suggestion_Engine_Horiz_800.gif\" alt=\"IAM Solution Suggestion Engine\" width=\"800\" height=\"100\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div>\n<h3 style=\"text-align: justify;\"><b><span data-contrast=\"auto\">The Danger of Credential-Based Attacks<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:259}\">\u00a0<\/span><\/h3>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Credential-based attacks have risen steadily over the past several years, with the most recent Verizon <\/span><a href=\"https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">Data Breach Investigations Report<\/span><\/a><span data-contrast=\"auto\"> (DBIR) indicating that 61% of attacks now involve credential data. That is a shockingly high number, but it makes sense. After all, if a user accesses the network using a valid username and password, most defenses have little reason to suspect that the behavior is suspicious. Without the ability to identify abnormal behavior even from those users perceived to be valid, an adversary with a working set of credentials can often move about the network unnoticed and unconcerned.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Unfortunately, organizations often store credentials in places that adversaries can easily access. For example, <strong><a href=\"https:\/\/solutionsreview.com\/identity-management\/passwords-are-not-dead-the-increasing-need-for-sso\/\" target=\"_blank\" rel=\"noopener\">many passwords<\/a><\/strong> live on the endpoint, network passwords reside in memory, and browsers, emails, and other applications store all kinds of passwords. Attackers who compromise a workstation or user account will often have little difficulty gaining access to stored credentials\u2014some of which may even be administrator credentials. From there, it&#8217;s a straight line to Active Directory, where they can escalate their privileges and gain access to things like on-premises groups, applications, and file storage.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">These tactics exacerbate what is already a significant issue for today&#8217;s enterprises. Recent Enterprise Management Associates (EMA) <\/span><a href=\"https:\/\/www.enterprisemanagement.com\/research\/asset.php\/4087\/The-Rise-of-Active-Directory-Exploits:-ls-it-Time-to-Sound-the-Alarm?\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">research indicates<\/span><\/a><span data-contrast=\"auto\"> that 50% of businesses have experienced attacks on AD within the past one to two years, and more than 40% reported those attacks were successful. That is an unacceptable success rate for adversaries, but it isn&#8217;t surprising. Stopping AD attacks requires defenders to know what to look for\u2014and have the tools in place to make an attacker&#8217;s life as difficult as possible. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify;\"><strong>The Signs of an AD Attack\u2014and What to Do About Them\u00a0<\/strong><\/h3>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Looking for weaknesses that could allow an attacker to gain access to Active Directory is the first place to start. If defenders can find identity exposures, they should assume that attackers could use (and likely have used) them to escalate their attack. Stopping AD attacks requires visibility across the entire network, starting at the <strong><a href=\"https:\/\/solutionsreview.com\/endpoint-security\/what-is-endpoint-detection-and-how-can-it-help-your-company\/\" target=\"_blank\" rel=\"noopener\">endpoint<\/a><\/strong>, where adversaries steal credentials. <\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Defenders need prompt visibility into vulnerabilities like admin credential exposures, potential attack paths, and shadow admin accounts. Reducing the attack surface is critical, restricting and alerting unauthorized access to credentials stored on endpoints. Attackers can do significant damage with a valid set of credentials. For example, those who get their hands on the right set of credentials could use them to gain access to specific resources, reset other passwords, request short-term tokens, request API tokens, or conduct other attack activities.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">AD attacks can happen fast, and dissecting logs for signs of intrusion after the fact is interesting for deep packet inspection, identifying attack signatures, and generating adversary intelligence, but typically insufficient for derailing attacks before an exploit has happened. Organizations need live attack detection, and actions like mass account lockouts or deletions should raise immediate alerts. <\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Suspicious password changes on sensitive accounts or mass password resets should also be flagged (though these may be more indicative of a password spray attack rather than an AD attack). Things like suspicious service creation on a domain controller, use of a default administrator account, or reactivation of previously disabled <strong><a href=\"https:\/\/solutionsreview.com\/identity-management\/get-a-free-privilieged-access-management-solutions-buyers-guide\/\" target=\"_blank\" rel=\"noopener\">privileged accounts<\/a><\/strong> are also potential signs of an AD attack in progress.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Additionally, deploying tools capable of hiding actual AD objects from attackers, intercepting uncategorized queries, and manipulating results with false information will undoubtedly throw attackers off their game. Defenders can also seed the environment with &#8220;admin&#8221; credential lures and AD decoys designed to trick adversaries into giving away their presence. These provide both an active and passive element to AD defense, making it difficult for attackers to see the network accurately, trust their tools, and avoid stepping on landmines that alert their presence. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify;\"><b><span data-contrast=\"auto\">Stopping AD Attacks is Difficult, but Not Impossible<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:259}\">\u00a0<\/span><\/h3>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Active Directory is intrinsically insecure, but that doesn&#8217;t mean organizations are relegated to leaving it unprotected. Defense in depth is achieved with continuous and automated visibility to exposures, which will seriously curtail attackers&#8217; ability to obtain the credentials they need quickly, move laterally within the network, and compromise AD. By adding Identity Detection and Response tools capable of providing this level of visibility, organizations can extend their security coverage well beyond the scope of traditional defenses. <\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">With IDR, security teams gain detection of identity-based attacks that are using stolen credentials, attempting to elevate their privileges, and seeking domain control for the mass distribution of malware or ransomware. AD remains a top target for ransomware attackers, and credential-based attacks increase in frequency given their relative ease and effectiveness. Trends all point to identity being the new battlefield for <strong><a href=\"https:\/\/solutionsreview.com\/identity-management\/trends-in-identity-and-access-management-to-watch-for\/\" target=\"_blank\" rel=\"noopener\">cybersecurity in 2022<\/a><\/strong>. To be prepared, organizations must rethink their security postures with this in mind.<\/span><\/p>\n<hr \/>\n<p style=\"text-align: justify;\"><div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a class=\"iam-inject\" href=\"https:\/\/solutionsreview.com\/identity-management\/identity-governance-and-administration-buyers-guide\/\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1682\" title=\"Identity Governance and Administration Buyer's Guide\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2019\/01\/identity-governance-administration-speedbump-cta.jpg\" alt=\"Download Link to Identity Governance and Administration Buyer's Guide\" width=\"800\" height=\"225\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As part of Solutions Review&#8217;s Premium Content Series\u2014a collection of contributed columns written by industry experts in maturing software categories\u2014Carolyn Crandall, the Chief Security Advocate at Attivo Networks, shares some expert insights on how to recognize and avoid active directory attacks. Active Directory (AD) is under attack. That isn&#8217;t an exaggeration, an intentionally provocative statement, [&hellip;]<\/p>\n","protected":false},"author":105,"featured_media":5839,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[1850,1852,1815,1851,1853,1824],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How to Recognize and Prevent Active Directory Attacks<\/title>\n<meta name=\"description\" content=\"As part of Solutions Review&#039;s Premium Content Series, Carolyn Crandall of Attivo Networks shares insights on avoiding active directory attacks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Carolyn Crandall\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/\",\"name\":\"How to Recognize and Prevent Active Directory Attacks\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2022\/02\/How-to-Recognize-and-Prevent-Active-Directory-Attacks.jpg\",\"datePublished\":\"2022-02-14T16:46:03+00:00\",\"dateModified\":\"2022-02-14T21:16:05+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3ceba5690b311ad503391384111fc5da\"},\"description\":\"As part of Solutions Review's Premium Content Series, Carolyn Crandall of Attivo Networks shares insights on avoiding active directory attacks.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2022\/02\/How-to-Recognize-and-Prevent-Active-Directory-Attacks.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2022\/02\/How-to-Recognize-and-Prevent-Active-Directory-Attacks.jpg\",\"width\":800,\"height\":400,\"caption\":\"Active Directory Attacks\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Recognize and Prevent Active Directory Attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Identity and Access Management Solutions | Solutions Review\",\"description\":\"Evaluating Enterprise IAM Software, Identity Governance &amp; Access Control Tools.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3ceba5690b311ad503391384111fc5da\",\"name\":\"Carolyn Crandall\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/07d8511301a2faab11edea869f5b9285?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/07d8511301a2faab11edea869f5b9285?s=96&d=mm&r=g\",\"caption\":\"Carolyn Crandall\"},\"description\":\"Carolyn Crandall is the Chief Security Advocate at Attivo Networks and an expert in identity security and lateral movement attack prevention. She has worked in high-tech for over 30 years and is recognized as one of the Top 100 women in cybersecurity. She has also been a guest on Fox News and been profiled in the Mercury News. She is an active speaker on security innovation at CISO forums, industry events, and technology education webinars.\",\"sameAs\":[\"https:\/\/www.attivonetworks.com\/\",\"https:\/\/www.linkedin.com\/in\/cacrandall\/\"],\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/ccrandall\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Recognize and Prevent Active Directory Attacks","description":"As part of Solutions Review's Premium Content Series, Carolyn Crandall of Attivo Networks shares insights on avoiding active directory attacks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/","twitter_misc":{"Written by":"Carolyn Crandall","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/","url":"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/","name":"How to Recognize and Prevent Active Directory Attacks","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2022\/02\/How-to-Recognize-and-Prevent-Active-Directory-Attacks.jpg","datePublished":"2022-02-14T16:46:03+00:00","dateModified":"2022-02-14T21:16:05+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3ceba5690b311ad503391384111fc5da"},"description":"As part of Solutions Review's Premium Content Series, Carolyn Crandall of Attivo Networks shares insights on avoiding active directory attacks.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2022\/02\/How-to-Recognize-and-Prevent-Active-Directory-Attacks.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2022\/02\/How-to-Recognize-and-Prevent-Active-Directory-Attacks.jpg","width":800,"height":400,"caption":"Active Directory Attacks"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/how-to-recognize-and-prevent-active-directory-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"How to Recognize and Prevent Active Directory Attacks"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Identity and Access Management Solutions | Solutions Review","description":"Evaluating Enterprise IAM Software, Identity Governance &amp; Access Control Tools.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3ceba5690b311ad503391384111fc5da","name":"Carolyn Crandall","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/07d8511301a2faab11edea869f5b9285?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/07d8511301a2faab11edea869f5b9285?s=96&d=mm&r=g","caption":"Carolyn Crandall"},"description":"Carolyn Crandall is the Chief Security Advocate at Attivo Networks and an expert in identity security and lateral movement attack prevention. She has worked in high-tech for over 30 years and is recognized as one of the Top 100 women in cybersecurity. She has also been a guest on Fox News and been profiled in the Mercury News. She is an active speaker on security innovation at CISO forums, industry events, and technology education webinars.","sameAs":["https:\/\/www.attivonetworks.com\/","https:\/\/www.linkedin.com\/in\/cacrandall\/"],"url":"https:\/\/solutionsreview.com\/identity-management\/author\/ccrandall\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/5837"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/105"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=5837"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/5837\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/5839"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=5837"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=5837"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=5837"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}