Info Security Memo
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org

Build Confidence

Focusing on Information Security 

Info Security Notes

Enable Azure ATP (Microsoft Defender for Identity) and Install ATP Sensor

10/19/2020

1 Comment

 
Enable Azure ATP (Microsoft Defender for Identity) and Install ATP Sensor
Azure ATP (Microsoft Defender for Identity),   is a cloud-based security solution that leverages your on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization.


You can enter the Azure ATP portal either by logging in to the portal https://portal.atp.azure.com and selecting your instance, or browsing to the instance URL: https://<instancename>.atp.azure.com, such as https://51sec.atp.azure.com




After logged in, there are a couple of steps to follow to get your instance up and running. You will need to activate your ATP with a sensor installation.


1  Click Sensors menu on the left side


2  Download Azure ATP Sensor setup file, either on Domain controller or one of domain member servers. If it is not on Domain controller, you will need to set up mirroring traffic from DC to your member server. 


3  Double click exe file to start installation. 


4  Since we are not installing it on DC, the option we have is standalone server. It requires configuration of port-mirroring from the domain controllers to receive network traffic. 

5  Enter the access key to link the standalone sensor installation to your Azure ATP instance. 



6  Once installation completed, there are two services showing in the Services MMC. 


7  Configure your sensor.


8  Modify and change your configuration of sensor, making sure it can reach out to your DC.
















via Blogger https://ift.tt/31mHhFo
October 19, 2020 at 02:20PM Cloud
1 Comment

Security Controls Based on NIST 800-53 Low Medium High Impact

10/19/2020

0 Comments

 
Security Controls Based on NIST 800-53 Low, Medium, High Impact

Since NIST 800-53 was first introduced, the number of controls has greatly expanded; the initial version of 800-53 contained approximately 300 controls and NIST 800-53 rev 4 contains 965 controls. 

Despite the complexity, each NIST 800-53 revision makes the controls set increasingly valuable. As things like mobile, IoT, and cloud evolve, NIST continuously enhances 800-53 to make migration an ongoing requirement.

800-53 (Rev. 4) Security Control Catalog

Low-Impact

Moderate-Impact

High-Impact

 


Security Objectives / Impact / Required Security Controls

 

Confidentiality

Integrity

Availability

Low

Login Audit
Encryption in transit
Patch Management
Centralized Authentication

Antivirus

Onsite Backup
Change Control
Patch Management
Vulnerability Management
SLAs

Moderate

Login Audit
System Health Monitoring
Encryption at rest
Encryption in transit
MFA
Secure Delete
DLP
Patch Management
Centralized Authentication
Machine Authentication
Role Based Authentication
Network IDS
Cloud Isolation

Antivirus
File Integrity Monitoring

High Availability
Onsite Backup
Change Control
Patch Management
Vulnerability Management
SLAs

High

Login Audit
System Health Monitoring
Encryption at rest
Encryption in transit
MFA
Priviledged Access Management
Patch Management
Machine authentication
Host IDS
Network IDS
SSL Decryption
Secure Delete
DLP
Penetration Testing
Centralized Authentication
Role Based Authentication
Cloud Isolation

Antivirus
File Integrity Monitoring

High Availability
Onsite/Offsite Backup
Scalability
DR Site
Change Control
Patch Management
Vulnerability Management
DDoS Protection
SLAs


The following list is showing those most common controls align with the impact level in 800-53. 

Impact / Required Security Controls (Based on 800-53))


 

Low

Moderate

High

Access Control / Firewall

 

 

 

Account Management

 

 

 

Security Awareness Training

 

 

 

Security Assessment / Categorization

 

 

 

System Inventory

 

 

 

Key Protection / Management

 

 

 

DoS Protection

 

 

 

Remote Access from External Network 

Monitoring, Managed,

Privileged Commands Controlled and Documents,

 Information Protected, Disabled non-secure network protocols

Wireless Access

Authentication, Encryption, Monitoring,

(Restrict Users)

 

Physical Access Control

 

 

 

System Maintenance

 

 

 

Patch Management

 

 

 

System / Login Audit / Response

 

 

 

System Health, Usage Monitoring

 

 

 

Encryption in transit

 

 

 

System Hardening

 

 

 

Software Usage Restrictions

 

 

 

Antivirus/Antimalware

 

 

 

Vulnerability Scanning

 

 

 

Onsite Backup / Recovery

 

 

 

Alternate Storage Site & Backup / Recovery

 

 

 

Access / Configuration Change Control

 

 

 

Least Privilege

 

 

 

PKI Certificates

 

 

 

Anti-SPAM

 

 

 

Endpoints Advanced Threat Protection

 

 

 

Encryption at Rest

 

 

 

Device Identification &  Authentication

 

 

 

Network IDS

 

 

 

File Integrity Monitoring

 

 

 

Role-based Authentication

 

 

 

Centralized Authentication

 

 

 

Separation of Duties

 

 

 

DLP

 

 

 

Application Partitioning

 

 

 

Multi Factor Authentication

 

 

 

Secure Delete

 

 

 

Penetration Testing

 

 

 

Vulnerability Management

 

 

 

Supply Chain Protection

 

 

 

Network Segregation (DMZ, Subnets, Mgmt Interface)

 

 

 

DR Site

 

 

 

Privileged Access Management

 

 

 

SIEM

 

 

 

Host IDS

 

 

 

 















via Blogger https://ift.tt/35dcbRJ
October 19, 2020 at 11:02AM Architecture
0 Comments

Security Portals for Microsoft Azure Windows and Office 365

10/18/2020

1 Comment

 
Security Portals for Microsoft, Azure, Windows and Office 365
Here is a list for Security Related Portals of Microsoft, Azure, Windows and Office 365.
  • Azure ATP - https://portal.atp.azure.com/
  • Microsoft Cloud App Security - https://portal.cloudappsecurity.com
  • Windows Defender ATP - https://securitycenter.windows.com/
  • O365 ATP - https://protection.office.com/
  • Microsoft 365 Compliance - https://compliance.microsoft.com/
  • Microsoft Service Trust Portal https://ift.tt/2qkdgRX
  • Microsoft Azure Identity Protection - https://portal.azure.com/#blade/Microsoft_AAD_IAM/IdentityProtectionMenuBlade/
  • Microsoft Azure Security https://portal.azure.com/#blade/Microsoft_AAD_IAM/SecurityMenuBlade/


Azure ATP

https://portal.atp.azure.com/

It will auto redirect to your signed in account url , such as https://51sec.atp.azure.com/timeline


Microsoft Cloud App Security

https://portal.cloudappsecurity.com

It will auto redirect to your signed in account url , such as https://51sec.portal.cloudappsecurity.com/




Windows Defender ATP

https://securitycenter.windows.com/






O365 ATP

https://protection.office.com/







Microsoft 365 Compliance

https://compliance.microsoft.com/





Microsoft Service Trust Portal

https://servicetrust.microsoft.com/






Microsoft Azure Identity Protection

https://portal.azure.com/#blade/Microsoft_AAD_IAM/IdentityProtectionMenuBlade/Overview






Microsoft Azure Security

https://portal.azure.com/#blade/Microsoft_AAD_IAM/SecurityMenuBlade/GettingStarted

  • Azure AD Conditional Access
  • Azure AD Identity Protection
  • Azure Security Center
  • Identity Secure Score
  • Named locations
  • Authentication methods
  • Multi Factor Authentication (MFA)







via Blogger https://ift.tt/37k4Br8
October 18, 2020 at 01:54PM Cloud
1 Comment

Microsoft Azure Identity Protection Respond Procedures and Action Explaination

10/13/2020

0 Comments

 
Microsoft Azure Identity Protection Respond Procedures and Action Explaination

 Identity Protection is a tool that allows organizations to accomplish three key tasks:

  • Automate the detection and remediation of identity-based risks.
  • Investigate risks using data in the portal.
  • Export risk detection data to third-party utilities for further analysis.
Automation will help to block three top attacks:
  • Breach replay: 
  • Password spray: 
  • Phishing: 

Identity Protection identifies risks in the following classifications:

RISK DETECTION AND REMEDIATION
Risk detection type Description
Atypical travel Sign in from an atypical location based on the user's recent sign-ins.
Anonymous IP address Sign in from an anonymous IP address (for example: Tor browser, anonymizer VPNs).
Unfamiliar sign-in properties Sign in with properties we've not seen recently for the given user.
Malware linked IP address Sign in from a malware linked IP address.
Leaked Credentials Indicates that the user's valid credentials have been leaked.
Password spray Indicates that multiple usernames are being attacked using common passwords in a unified, brute-force manner.
Azure AD threat intelligence Microsoft's internal and external threat intelligence sources have identified a known attack pattern.


Policy Enable (User Risk and Sign-In Risk Policy)








Investigate


Risky users

With the information provided by the risky users report, administrators can find:

  • Which users are at risk, have had risk remediated, or have had risk dismissed?
  • Details about detections
  • History of all risky sign-ins
  • Risk history

Administrators can then choose to take action on these events. Administrators can choose to:

  • Reset the user password (Not Security Administrator)
  • Confirm user compromise
  • Dismiss user risk
  • Block user from signing in (Not Security Administrator)
  • Investigate further using Azure ATP

Risky sign-ins

The risky sign-ins report contains filterable data for up to the past 30 days (1 month).

With the information provided by the risky sign-ins report, administrators can find:

  • Which sign-ins are classified as at risk, confirmed compromised, confirmed safe, dismissed, or remediated.
  • Real-time and aggregate risk levels associated with sign-in attempts.
  • Detection types triggered
  • Conditional Access policies applied
  • MFA details
  • Device information
  • Application information
  • Location information

Administrators can then choose to take action on these events. Administrators can choose to:

  • Confirm sign-in compromise
  • Confirm sign-in safe







Best Practice - Self-Remediation with Risk Policy

By allowing users to self-remediate, with Azure Multi-Factor Authentication (MFA) and self-service password reset (SSPR) in the risk policies, they can unblock themselves when risk is detected. These detections are then considered closed. Users must have previously registered for Azure MFA and SSPR in order to use when risk is detected.

  • Enable Azure AD self-service password reset

  • Enable Azure Multi-Factor Authentication

  • Enable Azure Multi-Factor Authentication registration policy

  • Enable sign-in and user risk policies


How to manually remediate risks and unblock users

There is an option to enable automated remediation using risk policies, such as MFA or Change password (SSPR - Self-Service Password Reset) to remediate risks. For some reasons, if MFA and Require Change Password options are not available for your organization, but Risk policy has been enabled to block user's access. Here are some manual process :


1. User blocked by User Risk Policy

step 1. Since user wont be able to log in using blocked AD account , user has to call into helpdesk to request unblock. After unblock, helpdesk will execute a manually password reset and pass password to user by phone. 

Step 2. Security admin contacted by helpdesk will need to investigate and take further action, such as dismiss user risk, which confirms to Azure AD that the user is not compromised. User Risk will be reset to none. All risk on this user and past sign-in will be closed. 

Step 3. User should be able to sign in now. 

Step 3 option: Exclude user from policy or disable policy. 


2. user blocked by Sign-in Risk Policy

Step1. User will not be able to sign in certain o365 apps.          

Step2. User contact helpdesk by phone or email to report issue and get support

Step3 Security admin confirm sign-in safe, which will set Risk level to none and reverse its impact on the user risk. 

Step4. User should be able to sign -in again . 

Optional step 3, exclude user from sign-in policy or disable sign-in policy. How long should we wait once add user into exclusion policy or disabled policy?




References

  • Remediate Risks and Unblock  Users








via Blogger https://ift.tt/3nQyGnQ
October 13, 2020 at 04:41PM Cloud
0 Comments

Azure Security Best Practices

10/5/2020

0 Comments

 
Azure Security Best Practices

This post summarizes some collected best practices from online for Microsoft Azure Security. 

Shared Responsibility model for cloud security


1  AWS - Shared Responsibility Model


2  Azure: - Shared Responsibilities for Cloud Computing

- 



3  CIS: Shared Responsibility for Cloud Security: What You Need to Know


Sources:
1. Microsoft Azure, https://docs.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility
2. Amazon Web Services, https://aws.amazon.com/compliance/shared-responsibility-model/



Azure Security Reference Model



1  Reference Design - Azure Administration Model




2  Best practices and tips to secure your hybrid cloud environment



2  Best practices - Identity & Access Management

  • Centralize Identity management. Designate a single Azure AD directory as the authoritative source.
  • Enforce SSO and Multi Factor Authentication.
  • Leverage Azure RBAC with Privileged Identity Management.
  • Actively monitor for suspicious activities using AAD anomaly reports.
  • Use Azure AD for storage authentication.






3  Best Practice - for Azure Storage

Advanced Threat Protection for Azure Storage
Alerts on anomalous access & potential data exfiltration
Investigation & remediation guidance
Alerts in Azure Security Centor

Note: Advanced Threat Protection for Storage Alerts


4  Best practices — Apps and Data security
Leverage Key Vault to store cryptographic keys and secrets. Control access through RBAC
Manage Azure Key Vault access at Management plane and Data plane
Encrypt data and rest and dbta in transit. Use client-side encryption for high value data
Leverage Advance Data Security (ADS) for Azure SQL
Leverage Azure Security Center to identify assets that do not have encryption at rest enabled


5  Best practices — Network Security
Adopt a Zero Trust approach
Control routing behavior and avoid implications of default routes
Disable RDP/SSH Access to virtual machines over internet
Choose whether to use Native Azure Controls or 3rd party Network Virtual Appliances (NVAs) for
internet edge security (North-South)
Simplify NSG rule management by defining application security groups (ASGs)







6  Protect Linux and Windows Servers from Threats

Best practices:
  • Reduce open network ports
    • Use Just-in-Time VM to control access to commonly attacked management ports
    • Limit open ports with adaptive network hardening
  • Block malware with adaptive application controls
  • Protect Windows servers and clients with the integration of Microsoft  Defender ATP and Linux servers




7  Protect your workloads from Threats - Use industry's most extensive threat intelligence to gain deep insights
Best Practices:
  • Detect & block advanced malware and threats for Linux and Windows Servers on any cloud
  • Protect cloud-native services from threats 
  • Protect data services against malicious attacks
  • Protect your Azure IOT solutions with near real time monitoring
  • Service layer detections: Azure network layer and Azure management layer (ARM)




Modern security operations and threat protection

Modern security operations and threat protection with Azure security center and Azure sentinel

Security Posture management with Secure Score

  • Gain instant insight into the security state of your cloud workloads
  • Address security vulnerabilities with prioritized recommendations
  • Improve your Secure Score and overall security posture in minutes
  • Speed up regulatory compliance










References

  • Portable Document Format File
    Premier Services - WorkshopPLUS - Microsoft Azure Security Best Practices
  • Website Link
    Azure security documentation
  • Website Link
    Azure security best practices and patterns
  • Website Link
    Security best practices for Azure solutions
  • Website Link
    Security best practices for IaaS workloads in Azure
  • Website Link
    Securing PaaS deployments
  • Website Link
    Exam AZ-500: Microsoft Azure Security Technologies

  • Website LinkAzure Design Best Practices: Azure Design & architecture Best practices on-demand: https://aka.ms/AzureDesignSG

    Website LinkAzure Operations & Governance Best Practices - Azure Ops & Governance Best practices on-demand: https://aka.ms/AzureOpsSG







via Blogger https://ift.tt/2GEs2A6
October 05, 2020 at 03:28PM Cloud
0 Comments

    Categories

    All
    Architecture
    Blog
    Checkpoint
    Cisco
    Cloud
    CyberArk
    F5
    Fortigate
    Guardium
    Juniper
    Linux
    Network
    Others
    Palo Alto
    Qualys
    Raspberry Pi
    Security
    SIEM
    Software
    Vmware
    VPN
    Wireless

    Archives

    March 2024
    February 2024
    January 2024
    December 2023
    November 2023
    October 2023
    September 2023
    August 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    February 2023
    January 2023
    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    October 2019
    September 2019
    June 2019
    July 2018
    May 2018
    December 2017
    August 2017
    April 2017
    March 2017
    January 2017
    December 2016
    November 2016
    October 2016
    September 2016
    August 2016
    July 2016
    June 2016
    May 2016
    April 2016
    March 2016
    February 2016
    January 2016
    December 2015
    November 2015
    October 2015
    September 2015
    August 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015

    Print Page:

    RSS Feed

    Email Subscribe
Powered by Create your own unique website with customizable templates.
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org