{"id":7193,"date":"2024-10-29T11:38:35","date_gmt":"2024-10-29T15:38:35","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=7193"},"modified":"2024-10-29T11:39:44","modified_gmt":"2024-10-29T15:39:44","slug":"to-secure-active-directory-think-like-an-attacker","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/","title":{"rendered":"To Secure Active Directory, Think Like an Attacker"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium_large wp-image-7195\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/To-Secure-Active-Directory-Think-Like-an-Attacker-768x384.jpg\" alt=\"To Secure Active Directory, Think Like an Attacker\" width=\"768\" height=\"384\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/To-Secure-Active-Directory-Think-Like-an-Attacker-768x384.jpg 768w, https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/To-Secure-Active-Directory-Think-Like-an-Attacker-300x150.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/To-Secure-Active-Directory-Think-Like-an-Attacker.jpg 800w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/><\/p>\n<p style=\"text-align: justify;\"><em><strong><span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\">Craig Birch, a Technology Evangelist and Principal Security Engineer at <a href=\"https:\/\/www.cayosoft.com\/\" target=\"_blank\" rel=\"noopener\">Cayosoft<\/a>, shares his take on how companies can secure their Active Directory solutions by thinking like a cyber-criminal. This article originally appeared in <a class=\"external\" href=\"https:\/\/insightjam.com\/share\/W9PNIZN-ugApeSN3?utm_source=manual\" target=\"_blank\" rel=\"noopener nofollow\">Insight Jam<\/a>, an enterprise IT community that enables human conversation on AI.<\/span><\/strong><\/em><\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/insightjam.com\/share\/W9PNIZN-ugApeSN3?utm_source=manual\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-6886 alignleft\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/10\/insightjam_logo.jpg\" alt=\"Insight Jam\" width=\"100\" height=\"100\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/10\/insightjam_logo.jpg 100w, https:\/\/solutionsreview.com\/identity-management\/files\/2023\/10\/insightjam_logo-60x60.jpg 60w\" sizes=\"(max-width: 100px) 100vw, 100px\" \/><\/a>Microsoft Active Directory (AD) and its cloud counterpart Entra ID form the identity management backbone for over 90 percent of large organizations. AD functions as the &#8216;keys to the kingdom,&#8217; with centralized control of critical resources, making it an irresistible target for cyber-criminals. Many ransomware incidents involve compromising AD to gain widespread access to an organization&#8217;s systems and data. Despite its pivotal role in controlling access to sensitive resources, AD is often overlooked in security strategies.<\/p>\n<p dir=\"ltr\" style=\"text-align: justify;\">To secure AD and Entra ID environments, IT professionals must adopt an attacker&#8217;s perspective, anticipating potential exploits and fortifying defenses accordingly. This approach is crucial, as identity-related security incidents are on the rise. In fact, AD was the entry point for many high-profile cyber-attacks, including the SolarWinds breach, the Colonial Pipeline ransomware attack, and the recent Toyota data leak.<\/p>\n<p dir=\"ltr\" style=\"text-align: justify;\">According to the IDSA\u00a0<a href=\"https:\/\/21078271.fs1.hubspotusercontent-na1.net\/hubfs\/21078271\/IDSA-2024%20Trends%20in%20Identity%20Security.pdf?utm_campaign=2024%20Trends%20Report&amp;utm_medium=email&amp;_hsenc=p2ANqtz-_sBwm5ojnNBlHuxpkc2OBtbKRj2Pnli7waOwX7oGnxrzdwxOp-HS_5kgNvZ1MAVwTIF8Z6SDI67aWo-VOxcYeQR-c7PQ&amp;_hsmi=309098278&amp;utm_content=309098278&amp;utm_source=hs_automation\" target=\"_blank\" rel=\"noopener\">2024 Trends in Identity Security Report<\/a>, 84 percent of identity stakeholders reported that identity-related incidents directly impacted their business \u2013 a significant increase from 68 percent in 2023. By thinking like adversaries, security teams can proactively identify and address AD and Entra ID vulnerabilities to safeguard organizations&#8217; most critical assets.<\/p>\n<h3 dir=\"ltr\" style=\"text-align: justify;\"><strong>Taking on the Attacker&#8217;s Mindset<\/strong><\/h3>\n<p dir=\"ltr\" style=\"text-align: justify;\">Attackers want elevated privileges and aim for the easiest target with the least amount of effort. So, security teams should ask themselves: What&#8217;s the quickest attack pathway that leads to the most privileges? The answer is often Active Directory and Entra ID. This is due to the immense level of access these systems provide and the fact that they are usually managed by infrastructure teams and are thus overlooked by security teams.<\/p>\n<p dir=\"ltr\" style=\"text-align: justify;\">Once inside, attackers focus on lateral movement and immediate privilege escalation. They may also exploit legacy systems, searching for old credentials on outdated machines. This approach is particularly effective against organizations that run hybrid AD environments, making it crucial for security teams to understand the complete picture of all environments to anticipate these tactics.<\/p>\n<h3 dir=\"ltr\" style=\"text-align: justify;\"><strong>Mapping the Attack Surface of Active Directory and Entra ID<\/strong><\/h3>\n<p dir=\"ltr\" style=\"text-align: justify;\">AD and Entra ID are inherently vulnerable due to their default configurations and the complex interplay between on-premises and cloud environments. Neither system is secure by default, exposing organizations to various attack vectors.<\/p>\n<p dir=\"ltr\" style=\"text-align: justify;\">In AD environments, attackers frequently exploit weak passwords, use Kerberos ticket attacks like Golden Ticket and Silver Ticket, and exploit Active Directory Certificate Services to escalate privileges. Hybrid attacks that bridge on-premises and cloud environments pose a significant threat, while AD delegation issues and misconfigured attributes can lead to unintended privilege escalation.<\/p>\n<p dir=\"ltr\" style=\"text-align: justify;\">Password-based attacks remain prevalent for Entra ID, but security token theft and manipulation have become more common. Illicit consent grant attacks exploit OAuth 2.0 permissions, while malicious Entra ID applications can be used to gain unauthorized access. Cross-tenant attacks targeting multi-tenant environments and hybrid identity scenarios present unique challenges that span both AD and Entra ID infrastructures.<\/p>\n<h3 dir=\"ltr\" style=\"text-align: justify;\"><strong>Unmasking Active Directory and Entra ID Misconfigurations\u00a0<\/strong><\/h3>\n<p dir=\"ltr\" style=\"text-align: justify;\">AD and Entra ID environments are plagued by over 270 potential attack pathways that can leave organizations vulnerable to attacks. The complexity of user accounts, computer accounts, and permissions within AD creates ample opportunities for misconfigurations. Attackers often start with those that are the most often overlooked. Here are just a few of the most common ones:<\/p>\n<ul style=\"text-align: justify;\">\n<li dir=\"ltr\">\n<p dir=\"ltr\">The default attribute setting, &#8220;Account is sensitive and cannot be delegated,&#8221; requires manual configuration but is frequently overlooked by AD administrators.<\/p>\n<\/li>\n<li dir=\"ltr\">\n<p dir=\"ltr\">Misconfigured Multi-Factor Authentication (MFA) settings allow attackers to exploit the &#8220;password not required&#8221; option to bypass security measures.<\/p>\n<\/li>\n<li dir=\"ltr\">\n<p dir=\"ltr\">The AdminSDHolder container\u2014used as a permission role template by the process SDProp\u2014controls and secures administrative access to Active Directory. If manipulated by the attacker, it provides an easy way to establish persistence inside Active Directory, allowing complete control over AD and potentially any resources that use AD.<\/p>\n<\/li>\n<\/ul>\n<p dir=\"ltr\" style=\"text-align: justify;\">Active Directory is complicated\u2014it&#8217;s simply not feasible to bulletproof 270 potential attack pathways, especially when security posture isn&#8217;t static. While threat assessments are crucial, they&#8217;re not a comprehensive solution when done sporadically. Infrequent assessments provide only a snapshot in time, potentially lulling organizations into a false sense of security. Identity Threat Detection &amp; Response (ITDR) and <a href=\"https:\/\/solutionsreview.com\/identity-management\/identity-management-is-the-new-perimeter\/\" target=\"_blank\" rel=\"noopener\">Identity Posture Management<\/a> enable organizations to move beyond periodic assessments and implement a continuous monitoring approach to identify the vulnerabilities that Endpoint Detection and Response (EDR) tools may miss.<\/p>\n<h3 dir=\"ltr\" style=\"text-align: justify;\"><strong>Passwords Matter \u00a0<\/strong><\/h3>\n<p dir=\"ltr\" style=\"text-align: justify;\">MFA should be the cornerstone of every defense strategy. The principle of least privilege should also be implemented to ensure users have only the access necessary for their roles. Just-in-time and just-enough access protocols should also be established and closely monitored.<\/p>\n<p dir=\"ltr\" style=\"text-align: justify;\">That said, given the rise in credential attacks, prioritizing password health across the organization is a must. According to 2024&#8217;s <a href=\"https:\/\/www.ibm.com\/reports\/threat-intelligence\" target=\"_blank\" rel=\"noopener\">IBM X-Force Threat Intelligence Index<\/a>, cyber-attacks using stolen or compromised credentials have increased 71 percent yearly.<\/p>\n<p dir=\"ltr\" style=\"text-align: justify;\">While MFA provides an essential layer of security, it is not a silver bullet. Previous breaches have shown that MFA can be bypassed using social engineering and session hijacking. Accounts using weak or compromised passwords boost the success of these techniques significantly. Attackers also often focus on service accounts and other non-human identities, such as those found in Entra ID, which may lack MFA capabilities.<\/p>\n<p dir=\"ltr\" style=\"text-align: justify;\">To strengthen defenses beyond MFA, organizations should consider specialized tools that can pinpoint areas where weak, previously breached, or commonly used passwords are being used within their infrastructure.<\/p>\n<p dir=\"ltr\" style=\"text-align: justify;\">Assessing identity infrastructure through the eyes of an attacker is a continuous effort. By implementing these defensive tactics, organizations can significantly enhance the security posture of their Microsoft environments. Adopting an attacker-centric approach to securing AD and Entra ID is more than a best practice\u2014it&#8217;s a path to safeguarding an organization&#8217;s most valuable assets.<\/p>\n<hr \/>\n<p dir=\"ltr\" style=\"text-align: justify;\">\n","protected":false},"excerpt":{"rendered":"<p>Craig Birch, a Technology Evangelist and Principal Security Engineer at Cayosoft, shares his take on how companies can secure their Active Directory solutions by thinking like a cyber-criminal. This article originally appeared in Insight Jam, an enterprise IT community that enables human conversation on AI. Microsoft Active Directory (AD) and its cloud counterpart Entra ID [&hellip;]<\/p>\n","protected":false},"author":1185,"featured_media":7195,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[1850,1815,2381,107,2380,2379],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>To Secure Active Directory, Think Like an Attacker<\/title>\n<meta name=\"description\" content=\"Craig Birch shares his take on how companies can secure their Active Directory solutions by thinking like a cyber-criminal.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Craig Birch\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/\",\"name\":\"To Secure Active Directory, Think Like an Attacker\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/To-Secure-Active-Directory-Think-Like-an-Attacker.jpg\",\"datePublished\":\"2024-10-29T15:38:35+00:00\",\"dateModified\":\"2024-10-29T15:39:44+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/c7fefdfabd836c28e26cc00fe75af291\"},\"description\":\"Craig Birch shares his take on how companies can secure their Active Directory solutions by thinking like a cyber-criminal.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/To-Secure-Active-Directory-Think-Like-an-Attacker.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/To-Secure-Active-Directory-Think-Like-an-Attacker.jpg\",\"width\":800,\"height\":400,\"caption\":\"To Secure Active Directory, Think Like an Attacker\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"To Secure Active Directory, Think Like an Attacker\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/c7fefdfabd836c28e26cc00fe75af291\",\"name\":\"Craig Birch\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/craig-birch.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/craig-birch.jpg\",\"caption\":\"Craig Birch\"},\"description\":\"Craig Birch is passionate about Identity Security, and has made it his mission to teach organizations about Active Directory and Entra ID Security and how they can keep the bad actors out and, if they get in, teach users how to recover quickly and not pay ransomware.\",\"sameAs\":[\"https:\/\/www.cayosoft.com\/\",\"https:\/\/www.linkedin.com\/in\/craigdbirch\/\"],\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/cbirch\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"To Secure Active Directory, Think Like an Attacker","description":"Craig Birch shares his take on how companies can secure their Active Directory solutions by thinking like a cyber-criminal.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/","twitter_misc":{"Written by":"Craig Birch","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/","url":"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/","name":"To Secure Active Directory, Think Like an Attacker","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/To-Secure-Active-Directory-Think-Like-an-Attacker.jpg","datePublished":"2024-10-29T15:38:35+00:00","dateModified":"2024-10-29T15:39:44+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/c7fefdfabd836c28e26cc00fe75af291"},"description":"Craig Birch shares his take on how companies can secure their Active Directory solutions by thinking like a cyber-criminal.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/To-Secure-Active-Directory-Think-Like-an-Attacker.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/To-Secure-Active-Directory-Think-Like-an-Attacker.jpg","width":800,"height":400,"caption":"To Secure Active Directory, Think Like an Attacker"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/to-secure-active-directory-think-like-an-attacker\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"To Secure Active Directory, Think Like an Attacker"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/c7fefdfabd836c28e26cc00fe75af291","name":"Craig Birch","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/craig-birch.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2024\/10\/craig-birch.jpg","caption":"Craig Birch"},"description":"Craig Birch is passionate about Identity Security, and has made it his mission to teach organizations about Active Directory and Entra ID Security and how they can keep the bad actors out and, if they get in, teach users how to recover quickly and not pay ransomware.","sameAs":["https:\/\/www.cayosoft.com\/","https:\/\/www.linkedin.com\/in\/craigdbirch\/"],"url":"https:\/\/solutionsreview.com\/identity-management\/author\/cbirch\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/7193"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/1185"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=7193"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/7193\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/7195"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=7193"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=7193"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=7193"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}