What Is Azure Advanced Threat Protection (Azure ATP)?
Total Page:16
File Type:pdf, Size:1020Kb
Contents Azure Advanced Threat Protection Documentation Overview What is Azure Advanced Threat Protection? Azure ATP architecture Azure ATP prerequisites What's new in Azure ATP Quickstarts Plan your Azure ATP capacity Create your Azure ATP instance Connect to Active Directory Download the Azure ATP sensor package Install the Azure ATP sensor Configure the Azure ATP sensor Tutorials Reconnaissance alerts Compromised credential alerts Lateral movement alerts Domain dominance alerts Exfiltration alerts Investigate a user Investigate a computer Investigate lateral movement paths Investigate entities Concepts Azure ATP portal Azure ATP security alerts Monitored activities Understanding entity profiles Lateral movement paths Understanding Network Name Resolution (NNR) Reports User roles Azure ATP multi-forest support How-to guides Azure ATP using Microsoft Cloud App Security Use Azure ATP with Cloud App Security Filter activities and set policies Security alert lab Lab overview 1 - Lab setup 2 - Reconnaissance playbook 3 - Lateral movement playbook 4 - Domain dominance playbook Understanding security alerts Manage security alerts Exclude entities from detections Manage sensitive accounts Search and filter monitored activities Use exclusions and honeytoken accounts Monitor domain controllers Change domain connectivity password Set Azure ATP notifications Health alerts Work with Azure ATP health center Manage Azure ATP health alerts Azure ATP sensor delayed update Troubleshooting known issues Troubleshoot using logs Integrate with Windows Defender ATP VPN integration Integrate with Syslog Silent installation Configuring the Azure ATP sensor Proxy configuration Advanced Audit Policy check Configure Azure ATP to make remote calls to SAM Azure ATP standalone sensor setup Configure port mirroring Validate port mirroring Configure event collection Configure Windows Event Forwarding Move from ATA to Azure ATP Advanced Threat Analytics (ATA) to Azure ATP Reference SIEM log reference Azure ATP known issues Resources Support and information Frequently asked questions Azure ATP readiness roadmap Azure ATP data security and privacy What is Azure Advanced Threat Protection? 7/25/2019 • 4 minutes to read Azure Advanced Threat Protection (ATP) is a cloud-based security solution that leverages your on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization. Azure ATP enables SecOp analysts and security professionals struggling to detect advanced attacks in hybrid environments to: Monitor users, entity behavior, and activities with learning-based analytics Protect user identities and credentials stored in Active Directory Identify and investigate suspicious user activities and advanced attacks throughout the kill chain Provide clear incident information on a simple timeline for fast triage Monitor and profile user behavior and activities Azure ATP monitors and analyzes user activities and information across your network, such as permissions and group membership, creating a behavioral baseline for each user. Azure ATP then identifies anomalies with adaptive built-in intelligence, giving you insights into suspicious activities and events, revealing the advanced threats, compromised users, and insider threats facing your organization. Azure ATP’s proprietary sensors monitor organizational domain controllers, providing a comprehensive view for all user activities from every device. Protect user identities and reduce the attack surface Azure ATP provides you invaluable insights on identity configurations and suggested security best-practices. Through security reports and user profile analytics, Azure ATP helps dramatically reduce your organizational attack surface, making it harder to compromise user credentials, and advance an attack. Azure ATP’s visual Lateral Movement Paths help you quickly understand exactly how an attacker can move laterally inside your organization to compromise sensitive accounts and assists in preventing those risks in advance. Azure ATP security reports help you identify users and devices that authenticate using clear-text passwords and provide additional insights to improve your organizational security posture and policies. Identify suspicious activities and advanced attacks across the cyber- attack kill-chain Typically, attacks are launched against any accessible entity, such as a low-privileged user, and then quickly move laterally until the attacker gains access to valuable assets – such as sensitive accounts, domain administrators, and highly sensitive data. Azure ATP identifies these advanced threats at the source throughout the entire cyber-attack kill chain: Reconnaissance Identify rogue users and attackers’ attempts to gain information. Attackers are searching for information about user names, users’ group membership, IP addresses assigned to devices, resources, and more, using a variety of methods. Compromised credentials Identify attempts to compromise user credentials using brute force attacks, failed authentications, user group membership changes, and other methods. Lateral movements Detect attempts to move laterally inside the network to gain further control of sensitive users, utilizing methods such as Pass the Ticket, Pass the Hash, Overpass the Hash and more. Domain dominance Highlighting attacker behavior if domain dominance is achieved, through remote code execution on the domain controller, and methods such as DC Shadow, malicious domain controller replication, Golden Ticket activities, and more. Investigate alerts and user activities Azure ATP is designed to reduce general alert noise, providing only relevant, important security alerts in a simple, real-time organizational attack timeline. The Azure ATP attack timeline view allows you to easily stay focused on what matters, leveraging the intelligence of smart analytics. Use Azure ATP to quickly investigate threats, and gain insights across the organization for users, devices, and network resources. Seamless integration with Windows Defender ATP provides another layer of enhanced security by additional detection and protection against advanced persistent threats on the operating system. Additional resources for Azure ATP Start a free trial https://signup.microsoft.com/Signup?OfferId=87dd2714-d452-48a0-a809-d2f58c4f68b7&ali=1 Follow Azure ATP on Microsoft Tech Community https://techcommunity.microsoft.com/t5/Azure-Advanced-Threat-Protection/bd- p/AzureAdvancedThreatProtection Join the Azure ATP Yammer community https://www.yammer.com/azureadvisors/#/threads/inGroup?type=in_group&feedId=9386893 Visit the Azure ATP product page https://azure.microsoft.com/features/azure-advanced-threat-protection/ Learn more about Azure ATP architecture Azure ATP Architecture Microsoft Ignite Microsoft Ignite 2018 featured multiple sessions focused on Azure Advanced Threat Protection. Sessions were recorded, so if you missed the event, we recommend you watch here: Azure ATP BRK3117 - SecOp and incident response with Azure ATP - watch the YouTube video Azure ATP and Azure AD IP (Active Directory Identity Protection) BRK3237 - Securing your hybrid cloud environment with Azure AD Identity Protection and Azure ATP - watch the YouTube video BRK2157 - Accelerate deployment and adoption of Microsoft Information Protection solutions - watch the YouTube video For a summary of Azure ATP announcements that were made at Ignite 2018, see the blog post - Azure Advanced Threat Protection Expands Integrations, Detections, and Forensic Capabilities. What's next? We recommend deploying Azure ATP in three phases: Phase 1 1. Set up Azure ATP to protect your primary environments. Azure ATP's fast deployment model enables you to start protecting your organization today. Install Azure ATP 2. Set sensitive accounts and honeytoken accounts. 3. Review reports and lateral movement paths. Phase 2 1. Protect all the domain controllers and forests in your organization. 2. Monitor all alerts – investigate lateral movement & domain dominance alerts. 3. Work with the Security Alert guide to understand threats and triage potential attacks. Phase 3 1. Integrate Azure ATP alerts into your SecOp workflows. See Also Azure ATP frequently asked questions Working with security alerts Check out the Azure ATP forum! Azure ATP Architecture 7/17/2019 • 3 minutes to read Azure ATP monitors your domain controllers by capturing and parsing network traffic and leveraging Windows events directly from your domain controllers, then analyzes the data for attacks and threats. Utilizing profiling, deterministic detection, machine learning, and behavioral algorithms Azure ATP learns about your network, enables detection of anomalies, and warns you of suspicious activities. Azure Advanced Threat Protection architecture: This section describes how the flow of Azure ATP's network and event capturing works, and drills down to describe the functionality of the main components: the Azure ATP portal, Azure ATP sensor, and Azure ATP cloud service. Installed directly on your domain controllers, the Azure ATP sensor accesses the event logs it requires directly from the domain controller. After the logs and network traffic are parsed by the sensor, Azure ATP sends only the parsed information to the Azure ATP cloud service (only a percentage of the logs are sent). Azure ATP Components Azure ATP consists of the following components: Azure ATP portal The Azure ATP portal allows creation of your Azure ATP instance, displays