Today Cyber Security plays a paramount role in global security. On this blog, the CEO of Paramount Defenses shares rare insights on issues related to Cyber Security, including Privileged Access, Organizational Cyber Security, Foundational Security, Windows Security, Active Directory Security, Insider Threats and other topics.


Showing posts with label Free Active Directory Audit Tool. Show all posts
Showing posts with label Free Active Directory Audit Tool. Show all posts

June 23, 2016

The Need for a Trustworthy Free Active Directory Audit Tool

Folks,

Starting July 04, 2016, we're going to start addressing certain matters of cyber security that today have a global impact on the security of a majority of business and government organizations worldwide.


Until then, over the next few days, I just wanted to very briefly cover a few technical aspects.


Today, I wanted to briefly provide some clarity on the need for a trustworthy free Active Directory Audit Tool -

Free Active Directory Audit Tool

Now you might be wondering why a free Active Directory Audit Tool deserves any mention on a blog on cyber security.

There's a very good reason for that, as elucidated below.



Cyber Security 101

"Law #1 of the 10 Immutable Laws of Security states that if a bad guy can persuade you to run his program on your computer, it's not your computer anymore."

A corollary of this law is that if you yourself download and run a program possibly written by a bad guy, on your computer, it may not be your computer anymore, and if you’re a privileged user, your network may no longer be your network anymore too.

To make a long story short, if a privileged user, such as an Active Directory Domain Admin were to download and run software from the Internet that happened to be malicious in nature, since that software would be running in Domain Admin context in that organization, it could cause substantial damage and result in a major cyber security breach.

In fact, depending on the expertise of the author of that malicious software, its execution could not only enable the perpetrator to exfiltrate large amounts of data, it could also possibly cause massive automated destruction of organizational IT assets.



A Worrisome Situation

For months now, our cyber intelligence has indicated that to this day thousands of IT personnel from thousands of organizations worldwide continue to search for a free Active Directory Audit Tool.


(Its worth pausing for a moment to) think about that!

A majority of these IT personnel are administrative personnel at prominent business and government organizations worldwide. They often serve in capacities such as System Admins, Domain Admins etc. and by virtue of their responsibilities typically possess vast and usually unrestricted privileged access in their foundational Active Directory deployments.




One. (Just One.)

Imagine an individual in such a capacity searching for and downloading a free tool from the Wild Wild Web, and then running it, even if once, to fulfill a need. In all likelihood, that tool will run in a privileged security context, typically Domain Admin or the like, because in essence, that individual will be logged in using their administrative account when running such a tool.

Now imagine a scenario wherein the tool that this individual downloaded and run (even if only once), happened to be malicious in nature, written and uploaded by a malicious entity, such as a professional hacker or an Advanced Persistent Threat (APT).

Hacker
You don't need to a PhD. in Cyber Security to conclude that in such a scenario, even if that administrative individual were to run such a tool ONCE, it could result in a security compromise, and possibly grant the perpetrator a door into, and possibly vast control, if not full control, over the organization's IT infrastructure.

In short, just one IT admin need download and execute just one malicious piece of software in their corporate environment just one time, and its effectively GAME OVER.



They Know

In addition to various nefarious entities (e.g. professional hackers. organized crime syndicates etc.) in the Western world, many others, including the Russians and Chinese, not only possess deep Windows and Active Directory technical expertise, they also know that many IT personnel actively seek and download a variety of free tooling, so it would not be unreasonable to assume that they could exploit this knowledge to their malicious gain.

APT
I'll let you infer where I'm going with this; the astute mind should have no problem connecting the dots.



A Trustworthy Alternative

In light of the above, the fact that our cyber intelligence indicates that to this day thousands of IT personnel from thousands of organizations worldwide continue to search for free a Active Directory Audit Tool was quite unsettling and concerning.

Ideally, today no organization should allow the use of free tooling of any kind in their environments.

CISO

Ideally, the CISOs of all organizations should immediately establish and enforce a cyber security policy prohibiting the use of free tooling of any kind in their IT environments by all IT personnel, whether employees or contractors.

Unfortunately, our cyber intelligence indicates that even this basic cyber security 101 measure today largely remains just an ideal, and in most organizations worldwide, IT personnel still seek and rely on free tooling to fulfill various needs.

In other words, the reality on the ground is FAR from ideal.

In light of this reality, we felt that it was imperative to provide organizations worldwide a trustworthy alternative when it comes to free Active Directory audit tooling.


Thus, about two months ago we released a limited free version of our flagship Gold Finger Active Directory Audit Tool.

This limited free version shares the same code-base as does our flagship Gold Finger Active Directory Audit Tool, which today is not only the Gold Standard for Active Directory Audit Tooling, but also the world's most trustworthy Active Directory Audit Tool, trusted by the world's most powerful business and government organizations and deployed in 6 continents worldwide.

It is my privilege to share with you that in less than 50 days of its release, our novel free Active Directory Audit Tool has been downloaded in 50+ countries worldwide and is being used by many of the world's top business and government organizations.



In Summary

If organizations must rely on free Active Directory Audit Tooling, it is our hope that at the very least they exercise sound judgment when choosing such tooling, because a poor choice could mean the difference security and compromise.

As idealists, we hope that the day is not far where no organization allows the use of free tooling of any kind in their environments. As you'll hopefully agree, in today's world, there is simply no reason to rely on free tooling of any sort.

Unfortunately, based on the reality on the ground, that day seems far away, so until such a day arrives, the least we can do is to raise awareness about the inherent dangers in using untrustworthy free tooling, and provide them with a trustworthy free option.

The details on our free tool are over at - http://www.active-directory-security.com/2016/06/free-active-directory-audit-tool.html


Alright, my time's up. Thanks, and stay tuned.

Best wishes,
Sanjay

May 31, 2016

Paramount Defenses to Donate Up To $50 Million in Microsoft Active Directory Audit Software

Folks,

Last month we announced our intention to donate up to $50 Million of our Microsoft Active Directory Audit Tool Software to non-profit and other organizations such as K-12, public universities, hospitals & government agencies in 100+ countries worldwide.

Today, I just wanted to take a few moments to share some relevant details concerning this announcement.


ACTIVE DIRECTORY ON-PREMISES

It is a well-known fact that Microsoft Active Directory On-Premises is the bedrock of organizational cyber security worldwide.


Specifically, over 85% of all business and government organizations worldwide operate on Microsoft Active Directory today.



ACTIVE DIRECTORY IN THE CLOUD

In addition, Microsoft’s recent foray into Cloud Computing and its introduction of Microsoft Azure Active Directory, its multi-tenant cloud based directory and identity management service, as well as Amazon now offering organizations the ability to run Active Directory as a managed service via Amazon Web Services (AWS) Cloud, will further increase the use of Active Directory.


As the world’s use of and reliance on Microsoft Active Directory increases, so does the need to obtain both basic as well as advanced cyber security insight (e.g. the ability to precisely audit privileged users in Active Directory) into Active Directory.




THE NEED FOR TRUSTWORTHY BASIC ACTIVE DIRECTORY CYBER SECURITY INSIGHT

All organizations that operate on Microsoft Active Directory, at a minimum, need to be able to perform basic Active Directory security audits, such as to be able to assess the state of all domain user accounts and security groups in Active Directory.
 
 
Over the years we have found that a large number of organizations have yet to fulfill even these basic needs, and in their attempts to fulfill these basic needs, every day IT personnel from across the world, including from many of the world’s most prominent business and government organizations, continue to seek free tooling in their attempts to fulfill these needs.
 
Unfortunately the concern with most free tooling out there is that there is little to no assurance of it being trustworthy or reliable, and thus, any reliance on it, and especially its use by privileged IT users could seriously jeopardize organizational security.
 
For instance, one such example of a free but highly inaccurate Active Directory Audit Tool can be found here.
 
Similarly, a malicious entity such as a hacking group or an APT could make available a seemingly useful yet covertly malicious tool for free online, which when downloaded and run by an unsuspecting user, could instantly grant them instant unauthorized access privileged access in the organization’s IT network.
 
 
Unfortunately, even though the use of potentially untrustworthy free tooling could substantially endanger organizational security, thousands of IT personnel continue to seek, download and use potentially untrustworthy free Active Directory audit software, thus exposing their organizations to risk. 
 
To help all organizations worldwide trustworthily fulfill their basic Active Directory security audit needs, we have decided to donate $50 Million worth of our entry-level Active Directory Security Audit Software to non-profit organizations, as well as make available a limited version of our trustworthy entry-level Gold Finger Active Directory Security Audit Tool, completely free.

Of course, we primarily help organizations fulfill their advanced Active Directory Audit needs, such as privileged access audit, attack surface reduction, insider threat protection and regulatory audit and compliance, so this is the least we can do for them.





DONATING UP TO $50 MILLION IN ACTIVE DIRECTORY AUDIT TOOLING

To help non-profit and other needy organizations worldwide, we have decided to donate up to $50 Million of our trustworthy  Microsoft Active Directory Security Audit Tool Software, measured at fair market value, to non-profit and other organizations such as K-12 schools, public universities, hospitals and government agencies across over 100 countries worldwide.
 
 
The average donation should be in the vicinity of $10,000 per organization, and we intend to donate our software to approximately 5,000 organizations across 100+ countries. In effect, each such organization will receive an unlimited annual user license of our commercially licensable Active Directory Security Audit Tool, thus empowering all their IT personnel to be able to easily and trustworthily perform basic Active Directory Audits.





OUR FREE ACTIVE DIRECTORY AUDIT TOOL 

In addition to the donation of our entry-level Active Directory Security Audit software, we also made available a free version of the tool, so that all organizations worldwide can trustworthily fulfill their basic Active Directory security audit needs.
 
Free Active Directory Audit Tool
 
Our free Active Directory Audit Tool is a limited version of our licensable Active Directory Security Audit Tool. It lets IT personnel worldwide audit the basic security state of any Active Directory deployment in the world trustworthily and at a button's touch.
 
 
 
Our $50M donation represents a small fraction of the annual potential for our globally deployed Gold Finger product. As the world's top cyber security company, and possibly the world's most security conscious company, this is the least we can do.
 
Best wishes,
Sanjay