Hawthorne, N.J., August 5, 2020

Stealthbits, Now Part of Netwrix, Extends Industrys Most Comprehensive Active Directory Security Portfolio

ActiveDirectory Attack Detections Such as “Pass the Ticket” and Group Managed Service Account (gMSA) Exploitation Pinpoint Attacks, andAuto-Response Playbooks Speed Threat Containment

Stealthbits, now part of Netwrix, today announced multiple enhancements to its Active Directory (AD) threat, policy enforcement, and auditing platforms.

Cyberattacks and data breaches are simply too common with nearly 4,000 confirmed data breaches reported in the latest 2020 Verizon Data Breach Investigations Report. Recent news demonstrates Active Directory is under heavy attack from adversaries of all types, including nation-state sponsored and organized cybercriminal groups alike.

In each of these recent breaches, Active Directory was noted as a key attack component. Now more than ever, organizations need to protect themselves, their customers, and their data, and it starts with Active Directory.

In the latest releases of StealthDEFEND, StealthINTERCEPT, and Stealthbits Activity Monitor, Stealthbits has added new and enhanced AD attack detections to its comprehensive library of detectable attacks.Additionally, Stealthbits has providednew tools to remove the signal-to-noise ratio within important datasets like Active Directory LDAP activity, allowing security practitioners tomore easily pinpoint attack behaviorsAuto-response playbooks provide immediate reaction and containment of detected attacks and new follow-up actions can be linked and auto-triggered based on the results of previously executed responses.

Reducing the dwell time of attackers has everything to do with accelerating detection of, and response to, cyber threats. The new and enhanced attack detection in this release strengthens an already extensive library of attacks we are tuned to detect. The ability to auto-respond the instant attacks are detected, vastly improves any organization’sability to contain and eradicate threats quickly and with confidence.
Rod Simmons, VP, Product Strategy at Stealthbits, now part of Netwrix

Even as the Active Directory Security market continues to expand with new offerings, Stealthbits continues to widen the innovation and capability gap with these and dozens of additional enhancements to its already industry-leading portfolio of solutions. From robust state-based and real-time auditing to password analysis and enforcement, purpose-built AD threat detection and response to rollback and recovery, AD privilege security, governance, clean-up, deception, change, authentication, and request prevention, and more, Stealthbits boasts the broadest and most complete set of AD security solutions developed over a 15-year history in the space

New and enhanced threat detection and response capabilities

  • Pass-the-Ticket (New)  Detect the theft of Kerberos Ticket Granting Tickets (TGT) and their use by a threat actor for lateral movement
  • Group Managed Service Account (GMSA) Exploitation (New)  Detect unauthorized retrieval of Group Managed Service Account passwords
  • Golden Ticket & Forged PAC (Enhanced) – Golden Ticket and Forged PAC threat analytics leverage a new Ticket Granting Tickets (TGT) cache for more accurate detection
  • User Behavior Analytics (Enhanced) – Detection speed and visualization of behavior anomalies over time have been improved
  • Threat Response: Follow-up Playbooks –Playbooks are a series of response actions automatically following the detection of a threat.Users now gain the ability to trigger follow-up playbooks based on whether the actions in the first playbook were successful or failed.
  • Enhanced LDAP Filtering – Remove LDAP query ‘noise’ and improve threat detection byfilteringbased on search scope, attributes requested and returned, and number of items returned
  • Active Directory Read Event Auditing – Gain the ability to enable surgical auditing of attribute read events that could indicate reconnaissance or other nefarious activitiessuch as unauthorized reading of LAPS passwords or BitLocker recovery passwords
  • FSMO Role Owner Changes – Detect when FSMO roles are moved or seized by a new system
  • Azure Active Directory MonitoringCheck for varying changes that could signal a threat (Stealthbits reports on over 800 events across different categories and services)

Organizations seeking ways to make substantial improvements in their ability to mitigate, detect, and even prevent advanced threats targeted at Active Directory or any of the resources Active Directory has been connected to are invited to evaluate Stealthbitsofferings in full.

We’ve made it our mission to provide the most innovative and useful approaches available for managing and securing Active Directory. We understand there is significant fatigue within organizations when it comes to dealing with AD, but the fact of the matter is that the problems with AD cannot be wished away and AD itself cannot be eradicated from existence overnight. In the interim, we’re committed to continual improvement and innovation in the space and believe we’re leading the charge toward a better future for Active Directory and the many thousands of organizations that rely on it every day.
Steve Cochran, CEO and Founder of Stealthbits, now part of Netwrix

StealthDEFEND 2.5 and StealthINTERCEPT 7.1 enhanced by Stealthbits Activity Monitor are available immediately.

about netwrix corporation

Netwrix champions cybersecurity to ensure a brighter digital future for any organization. Netwrix's innovative solutions safeguard data, identities, and infrastructure reducing both the risk and impact of a breach for more than 13,500 organizations across 100+ countries. Netwrix empowers security professionals to face digital threats with confidence by enabling them to identify and protect sensitive data as well as to detect, respond to, and recover from attacks.

For more information, visit www.netwrix.com.

contact us

Your questions and feedback are always welcome. Please dial our toll-free number: 888 - 638 - 9749, or enter your question details here and we will reply as soon as possible.

Media contact

Erin Jones, Avista PR for Netwrix
Phone: 704 - 664 - 2170

Follow us