Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
filiaks1
Contributor II

Is there an option FortiNDR be configured with the IP address of the AD server to detect AD attacks?

Hey Everyone,

 

 

Is there an option FortiNDR be configured with the IP address of the AD server to detect AD attacks?

 

I did see Device Enrichment | FortiNDR 7.6.2 | Fortinet Document Library but I was wondering not about enriching the other hosts but for FortiNDR to monitor the AD server IP address or FortiNDR to autodiscover it, so to detect Pass-the-Hash / Pass-the-Ticket, Kerberoasting, DC Shadow, DCSync or Golden/Silver Ticket attacks Active Directory Attacks ?

 

For example by FortiNDR knowing that there are two AD servers on ip addresses 1.1.1.1 and 1.1.1.2 then if another host sends DCSync requests using MS-DRSR protocol to 1.1.1.1 or 1.1.1.2 this will suggest AD attack as only AD servers should use DCSync between them.

 

 

3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello,

We are still looking for someone to help you.

We will come back to you ASAP.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Did you already have a look at our FortiNDR Knowledge Base?:

https://community.fortinet.com/t5/FortiNDR-on-premise/tkb-p/TKB49

 

You have some interesting KB article and it could help you.

 

Regards,

Anthony-Fortinet Community Team.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors