Punti di forza
- L’ingegneria sociale nei servizi di assistenza è ormai diventata uno dei principali punti di accesso, con gli attacchi di vishing (phishing vocale) in rapido aumento che portano alla compromissione delle credenziali.
- Le identità non umane, come gli account di servizio e i token, rappresentano un grave punto cieco in termini di sicurezza: spesso non vengono gestite e sono oggetto di gravi abusi finalizzati al movimento laterale.
- Active Directory (AD) rappresenta un obiettivo di grande valore a causa del suo controllo centralizzato e delle potenziali configurazioni errate.
- La prevenzione da sola non basta; le organizzazioni hanno bisogno di solide capacità di rilevamento e di ripristino rapido per limitare i danni.
- Immediate operational actions – like auditing accounts and correlating help desk activity with identity changes – can significantly reduce risk.
AD rimane uno degli obiettivi principali degli hacker poiché è il fulcro della gestione delle identità aziendali.Ricerche recenti dimostrano cheil 67% degli incidenti comporta ormai una compromissione legata alle identità, with attackers going after critical systems like AD within hours of initial access.Once compromised, recovery can take days or weeks – causing significant business disruption.
The question worth asking isn’t whether AD is a target.It’s how attackers get tqui – and why the path is so much shorter than security teams might expect.
3 passi verso un compromesso completo
Gruppi di malintenzionati come ShinyHunters e Scattered Spider hanno trasformato l’ingegneria sociale in un’operazione su larga scala.Voice phishing – vishing – jumped 449% in 2025.I chiamanti vengono reclutati, istruiti su copioni prestabiliti epagati fino a 1.000 dollari depending on success and hit rate.
That means, it’s possible to start an attack with one step: Get a password reset or multi-factor authentication (MFA) change.That’s it.
From that single credential, the attacker moves laterally into cloud and virtualized environments.They harvest OAuth tokens, create new administrative service accounts, and embed access in machine-layer credentials.These non-human identities – service accounts, API keys, tokens – now outnumber human users 144 to 1.La proliferazione e i costi operativi rendono difficili la rotazione e l’audit. Quel movimento laterale ha una destinazione: Active Directory.
La pubblicità è l’obiettivo
AD is the central nervous system of enterprise identity.Control it and you control everything – user accounts, group policies, and access to every domain-joined system in the network.The reason it’s so attractive to attackers – and so difficult to defend – is structural.Any authenticated user can read the entire directory.Every domain-joined system inherits trust from it.
Group Policy Objects linked at the domain head can be weaponized to disable security controls outright.Legacy protocols left enabled for application compatibility provide straightforward access.Microsoft’s own documentation says that “most identity attacks utilize common misconfigurations in Active Directory.”
When an attacker reaches the AD, they don’t need to force entry.The door is usually open.
La prevenzione è necessaria ma non sufficiente
The standard security stack – MFA, endpoint detection, email filtering – is built around human behavior.It wasn’t designed to govern the machine identity layer or to detect the kind of slow, legitimate-looking privilege escalation that characterizes modern AD attacks.An attacker that moves from a compromised human account to a service account to a domain administrator over 72 hours may never trigger a single alert.
This is why the conversation must shift from prevention-first to recovery-first.
Prevention still matters.Least-privilege access, auditing AD changes, hardening default configurations, disabling inactive accounts – these can help reduce the attack surface.But given that half of organizations have already experienced an AD attack, designing only for prevention means designing to fail.
True identity resilience requires the ability to detect unauthorized privilege escalations in near real time, roll back malicious changes before they propagate, and restore the identity environment to a known-trusted state quickly – not in days or weeks, but fast enough to contain the blast radius.That means treating AD and the non-human identity layer as Tier 0 assets, with the same governance and recovery investment you’d apply to any other mission-critical system.
Cosa fare subito per rafforzare la resilienza dell’identità
The gap between wqui most organizations are and wqui they need to be on identity resilience is real.But it’s closeable.The immediate priorities are unglamorous and operational:
- Audit what’s in your AD.
- Find the accounts that shouldn’t still exist.
- Rotate the credentials that haven’t been touched in years.
- Correlare l’attività dell’help desk con gli eventi relativi alla creazione di token e account.
A help desk interaction followed by an MFA reset followed by a new service account is a high-confidence attack signal – and it’s detectable if you’re looking for it.
The longer-term work is architectural: Build recovery capability into your identity program so that when an attack succeeds – and it’s usually when, not if – you can contain it, reverse it, and try to restore trust faster than the attacker can consolidate their position.
Attackers are counting on your AD being ungoverned, your machine identities being invisible, and your recovery plan being theoretical.Close one of those gaps this quarter.Close all three and you’ve fundamentally changed the math.
: dalla valutazione delle vulnerabilità al rollback con un solo clic, fino al ripristino completo della foresta.
Recentemente ho partecipato al podcast STRIVE insieme a Vidya Shankaran per parlare del divario di governance relativo alle identità non umane. Ascolta la nostra puntata – from vulnerability assessment to one-click rollback and full forest recovery.
I recently joined Vidya Shankaran on the STRIVE podcast to talk about the governance gap for non-human identities.Check out our episode qui.And be sure to read Vidya’s blog, Il punto cieco dell’identità delle macchine è ormai diventato una delle principali superfici di attacco.
Domande frequenti
Q: Why are help desks becoming a major security risk?
A: Help desks are often trusted to reset passwords and modify MFA settings, making them attractive targets for social engineering.Attackers exploit this trust to gain initial access with minimal resistance.
Q: What role do non-human identities play in attacks?
A: Sprawl and operational overhead make rotation and audit of non-human identities, such as service accounts and API keys, difficult.Attackers use them to maintain persistence and move undetected across systems.
Q: Why is AD such a critical target?
A: AD controls authentication and access across the network.Gaining control of it allows attackers to manage users, policies, and systems at scale.
Q: Isn’t MFA and endpoint security enough to stop these attacks?
A: These tools focus on human behavior and may not detect slow, legitimate-looking privilege escalation.Attackers can operate within normal patterns and avoid triggering alerts.
Q: What does a recovery-first security approach mean?
A: It means preparing for the reality that breaches will happen and prioritizing the ability to detect, contain, and reverse them quickly.This approach helps reduce downtime and can help limit overall impact.
Q: What are the most important steps to take immediately?
A: Start by auditing your AD, removing unnecessary accounts, rotating old credentials, and monitoring for suspicious sequences of help desk and identity-related activities.
Dan Conrad is Principal Technologist and Field CTO at Commvault.
Automated discovery protects new reports and folders are included as environments evolve, while centralized management provides a single place to monitor, manage, and recover data at scale.

Data Activate può aiutarti a: