Points clés à retenir
- L’ingénierie sociale visant les services d’assistance est désormais l’un des principaux points d’entrée, les attaques de « vishing » (hameçonnage vocal) se multipliant rapidement et entraînant la compromission des identifiants.
- Les identités non humaines, telles que les comptes de service et les jetons, constituent un angle mort majeur en matière de sécurité ; elles sont souvent laissées sans surveillance et largement exploitées à des fins de déplacement latéral.
- Active Directory (AD) constitue une cible de choix en raison de son contrôle centralisé et des risques de mauvaise configuration.
- La prévention à elle seule ne suffit pas ; les organisations doivent disposer de solides capacités de détection et de reprise rapide afin de limiter les dégâts.
- Immediate operational actions – like auditing accounts and correlating help desk activity with identity changes – can significantly reduce risk.
Active Directory (AD) reste une cible privilégiée des pirates, car il est au cœur de la gestion des identités en entreprise.Des études récentes montrent que67 % des incidents impliquent désormais une compromission liée aux identités, with attackers going after critical systems like AD within hours of initial access.Once compromised, recovery can take days or weeks – causing significant business disruption.
The question worth asking isn’t whether AD is a target.It’s how attackers get tici – and why the path is so much shorter than security teams might expect.
3 étapes pour parvenir à un compromis global
Des groupes malveillants tels que ShinyHunters et Scattered Spider ont fait de l’ingénierie sociale une opération à grande échelle.Voice phishing – vishing – jumped 449% in 2025.Les appelants sont recrutés, reçoivent un script à suivre etsont rémunérés jusqu’à 1 000 dollars depending on success and hit rate.
That means, it’s possible to start an attack with one step: Get a password reset or multi-factor authentication (MFA) change.That’s it.
From that single credential, the attacker moves laterally into cloud and virtualized environments.They harvest OAuth tokens, create new administrative service accounts, and embed access in machine-layer credentials.These non-human identities – service accounts, API keys, tokens – now outnumber human users 144 to 1.La prolifération et la charge opérationnelle rendent la rotation des identifiants et les audits difficiles. Ce déplacement latéral a une destination : Active Directory.
La publicité est la cible
AD is the central nervous system of enterprise identity.Control it and you control everything – user accounts, group policies, and access to every domain-joined system in the network.The reason it’s so attractive to attackers – and so difficult to defend – is structural.Any authenticated user can read the entire directory.Every domain-joined system inherits trust from it.
Group Policy Objects linked at the domain head can be weaponized to disable security controls outright.Legacy protocols left enabled for application compatibility provide straightforward access.Microsoft’s own documentation says that “most identity attacks utilize common misconfigurations in Active Directory.”
When an attacker reaches the AD, they don’t need to force entry.The door is usually open.
La prévention est nécessaire, mais pas suffisante
The standard security stack – MFA, endpoint detection, email filtering – is built around human behavior.It wasn’t designed to govern the machine identity layer or to detect the kind of slow, legitimate-looking privilege escalation that characterizes modern AD attacks.An attacker that moves from a compromised human account to a service account to a domain administrator over 72 hours may never trigger a single alert.
This is why the conversation must shift from prevention-first to recovery-first.
Prevention still matters.Least-privilege access, auditing AD changes, hardening default configurations, disabling inactive accounts – these can help reduce the attack surface.But given that half of organizations have already experienced an AD attack, designing only for prevention means designing to fail.
True identity resilience requires the ability to detect unauthorized privilege escalations in near real time, roll back malicious changes before they propagate, and restore the identity environment to a known-trusted state quickly – not in days or weeks, but fast enough to contain the blast radius.That means treating AD and the non-human identity layer as Tier 0 assets, with the same governance and recovery investment you’d apply to any other mission-critical system.
Que faire dès maintenant pour renforcer la résilience identitaire ?
The gap between wici most organizations are and wici they need to be on identity resilience is real.But it’s closeable.The immediate priorities are unglamorous and operational:
- Audit what’s in your AD.
- Find the accounts that shouldn’t still exist.
- Rotate the credentials that haven’t been touched in years.
- Établir une corrélation entre l’activité du service d’assistance et les événements liés à la création de jetons et de comptes.
A help desk interaction followed by an MFA reset followed by a new service account is a high-confidence attack signal – and it’s detectable if you’re looking for it.
The longer-term work is architectural: Build recovery capability into your identity program so that when an attack succeeds – and it’s usually when, not if – you can contain it, reverse it, and try to restore trust faster than the attacker can consolidate their position.
Attackers are counting on your AD being ungoverned, your machine identities being invisible, and your recovery plan being theoretical.Close one of those gaps this quarter.Close all three and you’ve fundamentally changed the math.
Découvrez comment Commvault Cloud une protection complète de l’Active Directory – from vulnerability assessment to one-click rollback and full forest recovery.
I recently joined Vidya Shankaran on the STRIVE podcast to talk about the governance gap for non-human identities.Check out our episode ici.And be sure to read Vidya’s blog, Le « point aveugle » lié à l’identité des machines constitue désormais une surface d’attaque majeure.
FAQ
Q: Why are help desks becoming a major security risk?
A: Help desks are often trusted to reset passwords and modify MFA settings, making them attractive targets for social engineering.Attackers exploit this trust to gain initial access with minimal resistance.
Q: What role do non-human identities play in attacks?
A: Sprawl and operational overhead make rotation and audit of non-human identities, such as service accounts and API keys, difficult.Attackers use them to maintain persistence and move undetected across systems.
Q: Why is AD such a critical target?
A: AD controls authentication and access across the network.Gaining control of it allows attackers to manage users, policies, and systems at scale.
Q: Isn’t MFA and endpoint security enough to stop these attacks?
A: These tools focus on human behavior and may not detect slow, legitimate-looking privilege escalation.Attackers can operate within normal patterns and avoid triggering alerts.
Q: What does a recovery-first security approach mean?
A: It means preparing for the reality that breaches will happen and prioritizing the ability to detect, contain, and reverse them quickly.This approach helps reduce downtime and can help limit overall impact.
Q: What are the most important steps to take immediately?
A: Start by auditing your AD, removing unnecessary accounts, rotating old credentials, and monitoring for suspicious sequences of help desk and identity-related activities.
Dan Conrad is Principal Technologist and Field CTO at Commvault.
Automated discovery protects new reports and folders are included as environments evolve, while centralized management provides a single place to monitor, manage, and recover data at scale.

Data Activate peut vous aider à :