Hawthorne, N.J., August 5, 2020

Stealthbits, Now Part of Netwrix, Extends Industrys Most Comprehensive Active Directory Security Portfolio

ActiveDirectory Attack Detections Such as “Pass the Ticket” and Group Managed Service Account (gMSA) Exploitation Pinpoint Attacks, andAuto-Response Playbooks Speed Threat Containment

Stealthbits, now part of Netwrix, today announced multiple enhancements to its Active Directory (AD) threat, policy enforcement, and auditing platforms.

Cyberattacks and data breaches are simply too common with nearly 4,000 confirmed data breaches reported in the latest 2020 Verizon Data Breach Investigations Report. Recent news demonstrates Active Directory is under heavy attack from adversaries of all types, including nation-state sponsored and organized cybercriminal groups alike.

In each of these recent breaches, Active Directory was noted as a key attack component. Now more than ever, organizations need to protect themselves, their customers, and their data, and it starts with Active Directory.

In the latest releases of StealthDEFEND, StealthINTERCEPT, and Stealthbits Activity Monitor, Stealthbits has added new and enhanced AD attack detections to its comprehensive library of detectable attacks.Additionally, Stealthbits has providednew tools to remove the signal-to-noise ratio within important datasets like Active Directory LDAP activity, allowing security practitioners tomore easily pinpoint attack behaviorsAuto-response playbooks provide immediate reaction and containment of detected attacks and new follow-up actions can be linked and auto-triggered based on the results of previously executed responses.

Reducing the dwell time of attackers has everything to do with accelerating detection of, and response to, cyber threats. The new and enhanced attack detection in this release strengthens an already extensive library of attacks we are tuned to detect. The ability to auto-respond the instant attacks are detected, vastly improves any organization’sability to contain and eradicate threats quickly and with confidence.
Rod Simmons, VP, Product Strategy at Stealthbits, now part of Netwrix

Even as the Active Directory Security market continues to expand with new offerings, Stealthbits continues to widen the innovation and capability gap with these and dozens of additional enhancements to its already industry-leading portfolio of solutions. From robust state-based and real-time auditing to password analysis and enforcement, purpose-built AD threat detection and response to rollback and recovery, AD privilege security, governance, clean-up, deception, change, authentication, and request prevention, and more, Stealthbits boasts the broadest and most complete set of AD security solutions developed over a 15-year history in the space

New and enhanced threat detection and response capabilities

  • Pass-the-Ticket (New)  Detect the theft of Kerberos Ticket Granting Tickets (TGT) and their use by a threat actor for lateral movement
  • Group Managed Service Account (GMSA) Exploitation (New)  Detect unauthorized retrieval of Group Managed Service Account passwords
  • Golden Ticket & Forged PAC (Enhanced) – Golden Ticket and Forged PAC threat analytics leverage a new Ticket Granting Tickets (TGT) cache for more accurate detection
  • User Behavior Analytics (Enhanced) – Detection speed and visualization of behavior anomalies over time have been improved
  • Threat Response: Follow-up Playbooks –Playbooks are a series of response actions automatically following the detection of a threat.Users now gain the ability to trigger follow-up playbooks based on whether the actions in the first playbook were successful or failed.
  • Enhanced LDAP Filtering – Remove LDAP query ‘noise’ and improve threat detection byfilteringbased on search scope, attributes requested and returned, and number of items returned
  • Active Directory Read Event Auditing – Gain the ability to enable surgical auditing of attribute read events that could indicate reconnaissance or other nefarious activitiessuch as unauthorized reading of LAPS passwords or BitLocker recovery passwords
  • FSMO Role Owner Changes – Detect when FSMO roles are moved or seized by a new system
  • Azure Active Directory MonitoringCheck for varying changes that could signal a threat (Stealthbits reports on over 800 events across different categories and services)

Organizations seeking ways to make substantial improvements in their ability to mitigate, detect, and even prevent advanced threats targeted at Active Directory or any of the resources Active Directory has been connected to are invited to evaluate Stealthbitsofferings in full.

We’ve made it our mission to provide the most innovative and useful approaches available for managing and securing Active Directory. We understand there is significant fatigue within organizations when it comes to dealing with AD, but the fact of the matter is that the problems with AD cannot be wished away and AD itself cannot be eradicated from existence overnight. In the interim, we’re committed to continual improvement and innovation in the space and believe we’re leading the charge toward a better future for Active Directory and the many thousands of organizations that rely on it every day.
Steve Cochran, CEO and Founder of Stealthbits, now part of Netwrix

StealthDEFEND 2.5 and StealthINTERCEPT 7.1 enhanced by Stealthbits Activity Monitor are available immediately.

about netwrix corporation

Netwrix makes data security easy. Since 2006, Netwrix solutions have been simplifying the lives of security professionals by enabling them to identify and protect sensitive data to reduce the risk of a breach, and to detect, respond to and recover from attacks, limiting their impact. More than 13,500 organizations worldwide rely on Netwrix solutions to strengthen their security and compliance posture across all three primary attack vectors: data, identity and infrastructure.

For more information, visit www.netwrix.com.

contact us

Your questions and feedback are always welcome. Please dial our toll-free number: 888 - 638 - 9749, or enter your question details here and we will reply as soon as possible.

Media contact

Erin Jones, Avista PR for Netwrix
Phone: 704 - 664 - 2170

Follow us