Understanding the difference between seeing an alert and comprehending the risk behind it is crucial. This article provides a comprehensive guide on how to investigate significant alerts and transform them into actionable steps.
The platform, previously known as Security Guardian, is now referred to as Identity Defense. It collects extensive data from on-premises environments, focusing on static data such as permissions within Active Directory and the deployment of agents to domain controllers. This data collection allows for real-time monitoring of changes within the environment.
The platform categorizes data into four specific types:
Identity Defense includes two main components:
When investigating alerts, it is essential to focus on high-severity findings. For example, irregular Active Directory replication and ordinary user accounts with hidden privileges are critical areas to examine.
In the case of irregular replication, it is important to exclude specific accounts from triggering audit events to reduce noise in the system. This can be done by accessing the hybrid audit section and managing the audited events.
When an account is added to a privileged group, its admin count changes from zero to one. If the account is later removed from that group, the count does not revert to zero, which can indicate a potential compromise. The platform flags these accounts for further investigation.
To manage these findings, users can mute specific accounts for particular alerts, allowing for a more streamlined investigation process.
The platform provides a visual representation of user activity, allowing users to filter and focus on relevant actions. This includes tracking changes made by accounts with previously elevated privileges, such as adding users to critical groups.
Protection templates can be created for various Active Directory objects, including group policies. Users can specify which attributes to protect and can add override accounts to ensure that necessary changes can still be made without compromising security.
It is crucial to use the pre-built Shields Up template for protecting Tier 0 assets, while custom templates can be utilized for broader Active Directory object protection.
Shields Up actively prevents unauthorized changes in real-time. For instance, if an admin attempts to modify group memberships, the system blocks the action, ensuring that security protocols remain intact.
All actions, including failed attempts, are logged for auditing purposes. This comprehensive logging helps identify potential attacks and enhances overall security posture.
Identity Defense provides a robust framework for managing identity risks and protecting critical assets. By understanding the tools and processes available, organizations can effectively respond to alerts and maintain a secure environment.