jan-karel.com
Home / Security Measures / Network & Active Directory

Network & Active Directory

Network & Active Directory

Network & AD Hardening

21 chapters on securing networks and Active Directory — from preventing initial access to zero trust architecture.

Reducing Risk

  1. Preventing Initial Access — Patch management, credential hygiene, and reducing the attack surface
  2. Stopping Detection & EvasionAMSI, logging, and attack detection
  3. Preventing Privilege Escalation — Blocking local and domain privilege escalation
  4. Active Directory Hardening — GPOs, tiering, and AD object security
  5. Kerberos Hardening — Preventing Kerberoasting, delegation, and ticket attacks
  6. Stopping Lateral Movement — Restricting PsExec, WMI, WinRM, and RDP
  7. Credential ProtectionLSASS protection, Credential Guard, and password policy
  8. ADCS Hardening — Securing Active Directory Certificate Services
  9. Detecting Persistence — Tracking down backdoors, scheduled tasks, and golden tickets
  10. Preventing Tunneling — Blocking DNS tunneling, SSH tunnels, and covert channels

Infrastructure Hardening

  1. Linux HardeningSSH, sudo, file permissions, and auditd
  2. Windows Hardening — AppLocker, Windows Defender, and group policy
  3. Email & DNS HardeningSPF, DKIM, DMARC, and DNS security
  4. MSSQL Hardening — Securing SQL Server against abuse
  5. Network Segmentation & Firewall — VLANs, firewall rules, and microsegmentation
  6. Logging, Monitoring & SIEM — Centralized logging, alerting, and incident detection
  7. Backup & Disaster Recovery — 3-2-1 backups, testing restores, and ransomware resilience
  8. Vulnerability Management — Scanning, prioritizing, and patching
  9. Zero Trust Architecture — Never trust, always verify in practice
  10. Wireless & Physical Security — Wi-Fi, physical access, and social engineering
  11. Security Awareness — Employees as the first line of defense

Op de hoogte blijven?

Ontvang maandelijks cybersecurity-inzichten in je inbox.

← Security Measures ← Home