Summary
In this chapter, we learned how standard computer communications protocols are used as attack vectors in MiTM attacks. We learned how to configure policies to mitigate them and that in a well-administered network, protocols such as LLMNR, NBT-NS, mDNS, and WPAD can be disabled. Next, we talked about relay attacks and covered different security settings that can be used to protect against exploits that target Kerberos authentication, SMB, LDAP, IPv6, and ARP. After that, we covered how an attacker can use discovery tactics to move laterally and escalate privileges. We reviewed different attack techniques, such as golden and silver tickets, that can be used to exploit Kerberos authentication, and covered areas targeted to steal credentials on an OS.
Finally, we reviewed the privacy settings that are listed in the Privacy & Security section of the Windows Settings app. We discussed how to control these settings using Intune and listed where to find the relevant policies...