转载:零信任安全产品的变与不变
抓住零信任的金线,是理解和落地零信任的第一步,本文作者基于多年甲方实践,带着对零信任深刻的理解和认知,深入洞悉身份和权限对于零信任的灵魂所在,预祝创业成功,为市场和客户带来更好的零信任产品。
On a network and need credentials? Try password spraying the domain controller directly.
A few years ago, I wrote this password spray tool called gospray that was used succesfully in a couple of engagements since. It does an LDAP bind directly against the domain controller to validate credentials. This doesn’t require an SMB server (or other servers) as target. So, it’s pretty quiet and number of concurrent Go routines is configurable. :)