Microsoft Defender for Identity can now detect Zerologon exploits

The update will help SecOps teams find and mitigate attacks using the authentication bypass flaw

A security flaw depicted by a padlock with bullet holes on a circuit board

Microsoft has updated its Microsoft Defender for Identity programme to detect Zerologon exploits, enabling SecOps teams to detect attacks using this vulnerability.

The Zerologon flaw is authentication bypass flaw in the Netlogon Remote Protocol (MS-NRPC) that allows an attack against Microsoft Active Directory domain controllers, making it possible for a hacker to impersonate any computer, including the root domain controller.

"Microsoft Defender for Identity can detect this vulnerability early on," said Microsoft program manager Daniel Naim in a blog post. "It covers both the aspects of exploitation and traffic inspection of the Netlogon channel."

Alerts will be displayed to enable admins to identify the device that attempted the impersonation, the domain controller, the targeted asset, and whether the impersonation attempts were successful. "Finally, customers using Microsoft 365 Defender can take full advantage of the power of the signals and alerts from Microsoft Defender for Identity, combined with behavioral events and detections from Microsoft Defender for Endpoint," Naim added.

"This coordinated protection enables you not just to observe Netlogon exploitation attempts over network protocols, but also to see device process and file activity associated with the exploitation."

Microsoft has known about the Netlogon flaw since August when it released an update for domain controllers.

MSRC VP of Engineering Aanchal Gupta said in a blog post that the company “strongly encourage anyone who has not applied the update to take this step now. Customers need to both apply the update and follow the original guidance as described in KB4557222 to ensure they are fully protected from this vulnerability.”

In an advisory, the US Cybersecurity and Infrastructure Security Agency (CISA) advised agencies in the country to “immediately apply the Windows Server August 2020 security update to all domain controllers”.

Featured Resources

Choosing a collaboration platform

Eight questions every IT leader should ask

Download now

Performance benchmark: PostgreSQL/ MongoDB

Helping developers choose a database

Download now

Customer service vs. customer experience

Three-step guide to modern customer experience

Download now

Taking a proactive approach to cyber security

A complete guide to penetration testing

Download now

Recommended

HackBoss malware is using Telegram to steal cryptocurrency from other hackers
cryptocurrencies

HackBoss malware is using Telegram to steal cryptocurrency from other hackers

16 Apr 2021
Geico data breach leads to stolen driver’s license numbers
data breaches

Geico data breach leads to stolen driver’s license numbers

21 Apr 2021
UK gov agrees new three-year cloud deal with Microsoft
public cloud

UK gov agrees new three-year cloud deal with Microsoft

21 Apr 2021
UK’s IoT security regulation will also include smartphones
Internet of Things (IoT)

UK’s IoT security regulation will also include smartphones

21 Apr 2021

Most Popular

How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

8 Apr 2021
Microsoft is submerging servers in boiling liquid to prevent Teams outages
data centres

Microsoft is submerging servers in boiling liquid to prevent Teams outages

7 Apr 2021
REvil threatens to release Apple’s hardware schematics
ransomware

REvil threatens to release Apple’s hardware schematics

21 Apr 2021