Puntos Clave
- La ingeniería social a través del servicio de asistencia técnica se ha convertido en uno de los principales puntos de entrada, ya que los ataques de «vishing» (phishing por voz) están aumentando rápidamente y provocan el robo de credenciales.
- Las identidades no humanas, como las cuentas de servicio y los tokens, son un importante punto ciego en materia de seguridad; a menudo no se gestionan y se aprovechan mucho para el movimiento lateral.
- Active Directory (AD) es un objetivo muy atractivo debido a su control centralizado y a las posibles configuraciones erróneas.
- La prevención por sí sola no basta; las organizaciones necesitan sistemas sólidos de detección y una capacidad de recuperación rápida para limitar los daños.
- Immediate operational actions – like auditing accounts and correlating help desk activity with identity changes – can significantly reduce risk.
AD sigue siendo uno de los principales objetivos de los atacantes porque es el núcleo de la identidad corporativa.Estudios recientes muestran queel 67 % de los incidentes implican ahora una violación de la identidad, with attackers going after critical systems like AD within hours of initial access.Once compromised, recovery can take days or weeks – causing significant business disruption.
The question worth asking isn’t whether AD is a target.It’s how attackers get taquí – and why the path is so much shorter than security teams might expect.
3 pasos para llegar a un acuerdo total
Grupos de ciberdelincuentes como ShinyHunters y Scattered Spider han convertido la ingeniería social en una operación a gran escala.Voice phishing – vishing – jumped 449% in 2025.Se recluta a personas para realizar las llamadas, se les proporciona un guion yse les paga hasta 1 000 dólares depending on success and hit rate.
That means, it’s possible to start an attack with one step: Get a password reset or multi-factor authentication (MFA) change.That’s it.
From that single credential, the attacker moves laterally into cloud and virtualized environments.They harvest OAuth tokens, create new administrative service accounts, and embed access in machine-layer credentials.These non-human identities – service accounts, API keys, tokens – now outnumber human users 144 to 1.La expansión y la sobrecarga operativa dificultan la rotación y la auditoría. Ese movimiento lateral tiene un destino: Active Directory.
La publicidad es el objetivo
AD is the central nervous system of enterprise identity.Control it and you control everything – user accounts, group policies, and access to every domain-joined system in the network.The reason it’s so attractive to attackers – and so difficult to defend – is structural.Any authenticated user can read the entire directory.Every domain-joined system inherits trust from it.
Group Policy Objects linked at the domain head can be weaponized to disable security controls outright.Legacy protocols left enabled for application compatibility provide straightforward access.Microsoft’s own documentation says that “most identity attacks utilize common misconfigurations in Active Directory.”
When an attacker reaches the AD, they don’t need to force entry.The door is usually open.
La prevención es necesaria, pero no suficiente
The standard security stack – MFA, endpoint detection, email filtering – is built around human behavior.It wasn’t designed to govern the machine identity layer or to detect the kind of slow, legitimate-looking privilege escalation that characterizes modern AD attacks.An attacker that moves from a compromised human account to a service account to a domain administrator over 72 hours may never trigger a single alert.
This is why the conversation must shift from prevention-first to recovery-first.
Prevention still matters.Least-privilege access, auditing AD changes, hardening default configurations, disabling inactive accounts – these can help reduce the attack surface.But given that half of organizations have already experienced an AD attack, designing only for prevention means designing to fail.
True identity resilience requires the ability to detect unauthorized privilege escalations in near real time, roll back malicious changes before they propagate, and restore the identity environment to a known-trusted state quickly – not in days or weeks, but fast enough to contain the blast radius.That means treating AD and the non-human identity layer as Tier 0 assets, with the same governance and recovery investment you’d apply to any other mission-critical system.
Qué hacer ahora mismo para reforzar tu identidad
The gap between waquí most organizations are and waquí they need to be on identity resilience is real.But it’s closeable.The immediate priorities are unglamorous and operational:
- Audit what’s in your AD.
- Find the accounts that shouldn’t still exist.
- Rotate the credentials that haven’t been touched in years.
- Relaciona la actividad del servicio de asistencia con los eventos de creación de tokens y cuentas.
A help desk interaction followed by an MFA reset followed by a new service account is a high-confidence attack signal – and it’s detectable if you’re looking for it.
The longer-term work is architectural: Build recovery capability into your identity program so that when an attack succeeds – and it’s usually when, not if – you can contain it, reverse it, and try to restore trust faster than the attacker can consolidate their position.
Attackers are counting on your AD being ungoverned, your machine identities being invisible, and your recovery plan being theoretical.Close one of those gaps this quarter.Close all three and you’ve fundamentally changed the math.
: desde la evaluación de vulnerabilidades hasta la reversión con un solo clic y la recuperación completa del bosque.
Hace poco participé junto a Vidya Shankaran en el podcast STRIVE para hablar sobre la brecha de gobernanza en las identidades no humanas. Echa un vistazo a nuestro episodio – from vulnerability assessment to one-click rollback and full forest recovery.
I recently joined Vidya Shankaran on the STRIVE podcast to talk about the governance gap for non-human identities.Check out our episode aquí.And be sure to read Vidya’s blog, El punto ciego de la identidad de las máquinas se ha convertido ahora en una superficie de ataque principal.
Preguntas frecuentes
Q: Why are help desks becoming a major security risk?
A: Help desks are often trusted to reset passwords and modify MFA settings, making them attractive targets for social engineering.Attackers exploit this trust to gain initial access with minimal resistance.
Q: What role do non-human identities play in attacks?
A: Sprawl and operational overhead make rotation and audit of non-human identities, such as service accounts and API keys, difficult.Attackers use them to maintain persistence and move undetected across systems.
Q: Why is AD such a critical target?
A: AD controls authentication and access across the network.Gaining control of it allows attackers to manage users, policies, and systems at scale.
Q: Isn’t MFA and endpoint security enough to stop these attacks?
A: These tools focus on human behavior and may not detect slow, legitimate-looking privilege escalation.Attackers can operate within normal patterns and avoid triggering alerts.
Q: What does a recovery-first security approach mean?
A: It means preparing for the reality that breaches will happen and prioritizing the ability to detect, contain, and reverse them quickly.This approach helps reduce downtime and can help limit overall impact.
Q: What are the most important steps to take immediately?
A: Start by auditing your AD, removing unnecessary accounts, rotating old credentials, and monitoring for suspicious sequences of help desk and identity-related activities.
Dan Conrad is Principal Technologist and Field CTO at Commvault.
Automated discovery protects new reports and folders are included as environments evolve, while centralized management provides a single place to monitor, manage, and recover data at scale.

Data Activate puede ayudarte a: