skip to content

Identity and Credential Attacks

You will learn how one guessed or stolen credential becomes the whole estate, and what each step costs the operator who chose it. Interviewers make you walk that path end to end.

on this pageshow

explore

questions

page 2 of 2

An operator buys a valid CI pipeline token, pushes an image the cluster deploys, and reads production data. Which step escalated privilege?

level: seniorimportance: should knowfreq 45%

basics

~20 s

None of them. The token was entitled to push, the cluster was configured to pull and run whatever it finds, and the workload identity already held the database rights. The operator's only cost was acquiring one credential.

open as a page

Why is a single desktop-deployment credential a wider attack channel than a domain administrator account across 900 stores?

level: seniorimportance: should knowfreq 40%

basics

~20 s

The deployment path is built to push code to every host at once and its agent already listens on each one. Whoever holds its credential gets one-operation code execution estate-wide, while a domain admin must still reach each host through some channel.

open as a page

A credential-stuffing run converts 0.2% of pairs into logins — why is that profitable, and what kills it?

level: seniorimportance: should knowfreq 45%

basics

~20 s

Because the corpus is nearly free and each valid session resells. Two thousand hits from a million pairs clears the proxy and challenge-solving bill. Only shrinking how many of your accounts appear in that corpus changes the arithmetic.

open as a page

A sign-in was push-approved by the user — why doesn't that prove the user started it?

level: seniorimportance: should knowfreq 52%

basics

~20 s

It proves only that whoever holds the enrolled device pressed approve in response to some request. Without number matching there is nothing the approver must copy from the surface that made the request, so the approval is not bound to any particular attempt.

open as a page

How does a snapshot or backup of a virtualised domain controller yield every hash offline?

level: seniorimportance: should knowfreq 45%

basics

~20 s

The directory database file NTDS.dit and the SYSTEM registry hive both sit on a controller's disk. A VM snapshot or backup copies them without touching running processes; offline, the SYSTEM hive's boot key decrypts the hashes NTDS.dit stores. So backup or snapshot access equals replication rights.

open as a page

A departing contractor copies their laptop's credential stores — which artefacts are usable as-is?

level: seniorimportance: should knowfreq 52%

basics

~20 s

Rank by what each artefact still needs. Plaintext bearer material — a cloud credentials file, a passphrase-less private key, tokens in dotfiles — works immediately. Password-chained stores need the user's context. Cached domain verifiers only yield to offline guessing.

open as a page

Holding one student account in a domain with 400 service principal names, which accounts do you roast and which do you skip?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Skip machine-keyed accounts — computer accounts and group-managed service accounts — because their random keys will not crack. Target human-owned service accounts: old, role-named, ideally privileged. Pre-authentication left off is an account-age fingerprint that flags a legacy, likely-weak password worth taking first.

open as a page

A reviewer says the estate is fully patched, so NTLM relay is fixed. Why is that wrong?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Relay is a design property, not a defect. The exchange proves possession to whoever holds the challenge and never states which service it was meant for, so no patch retires it. Updates removed only particular variants and particular triggers.

open as a page

What does a valid signature on a federated identity assertion actually prove?

level: seniorimportance: should knowfreq 38%

basics

~10 s

Only that something holding the signing key produced it. It does not prove the issuer authenticated anyone, that the named person was present, or that the issuer would agree it issued this.

open as a page

Your provider says per-engagement admin grants break its 15-minute response SLA — do you keep standing access?

level: principalimportance: should knowfreq 34%

basics

~20 s

Usually no, because the SLA covers a small set of emergency paths, not all work. Split break-glass from routine: pre-approved self-activating emergency grants with a hard expiry meet the clock, while everything else waits for approval.

open as a page

If backup and snapshot access equal domain-secret theft, how should you scope the privileged tier?

level: principalimportance: should knowfreq 38%

basics

~20 s

Define the privileged tier by capability, not title: every principal that can replicate the directory, back up a domain controller, or snapshot its VM can reconstruct all password hashes and is therefore tier-zero. Counting named admins undercounts the real privileged set.

open as a page

If the adversary is 'just a kid with one laptop', are your roastable service accounts safe?

level: principalimportance: should knowfreq 28%

basics

~20 s

You cannot answer from the adversary's size alone. Safety is each service password's keyspace against the compute a realistic adversary can rent — a weekend of cloud GPUs clears far more than one laptop — weighted by blast radius. The only structural fix is machine-generated keys, not a patch.

open as a page

How can your own compromised tenant administrator reach a provider's other client estates?

level: middleimportance: nice to knowfreq 26%

basics

~20 s

Because the provider's privileged identity comes into your tenant to work. Whatever a compromised client can do to that identity while it is inside — capture it, lure it, get a consent or a role granted to it — travels back out to the other clients it serves.

open as a page

Can cached domain logon verifiers taken from a laptop's SECURITY hive be replayed to the domain?

level: middleimportance: nice to knowfreq 38%

basics

~10 s

No. Cached domain logon verifiers exist only so a laptop can validate a logon while no domain controller is reachable. No authentication protocol accepts them, so the only route is slow offline password guessing.

open as a page

After a merger adds a forest trust, why does the privilege graph change with no membership edits?

level: seniorimportance: nice to knowfreq 34%

basics

~20 s

A trust is an edge. Principals from the acquired forest become authenticated principals in yours when they authenticate across it, and any group or permission entry that references them joins the two graphs, so their weakest delegation now leads into your estate.

open as a page

Which control class actually stops NT hash and Kerberos ticket reuse?

level: seniorimportance: nice to knowfreq 36%

basics

~20 s

Only changing what the verifier accepts. Move to proof that cannot be replayed - a fresh signature over a challenge, checked against a public key, as in FIDO2/WebAuthn - then shorten and scope whatever static material remains.

open as a page

A reviewer wants a production-reach finding closed as low because no privilege was escalated. What do you argue?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Argue reach, class, cost and durability instead of boundaries. Concede honestly that nothing is unpatched, which changes who owns the fix rather than how serious it is — a route needing no defect has no vendor timeline slowing it down.

open as a page

Finance's scanner only speaks basic authentication — how do you decide what happens to that path?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

You cannot add a factor to a path that cannot prompt, so the decision is which control class replaces it and who pays. Scope the credential, restrict its source, or fund the device's replacement, with a named owner accepting what is left.

open as a page

Mandating signing and binding would end relay, but scanners on your segment cannot do it. How do you decide?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

Enforce at the destinations that accept identities, not at the devices. Legacy scanners are clients, so they rarely block enforcement. Where one genuinely cannot comply, shrink its account's authority to almost nothing and give the exception an owner and an end date.

open as a page

A federation signing key was held for a year; how do you re-establish trust with relying parties you cannot compel?

level: principalimportance: nice to knowfreq 24%

basics

~20 s

Replace the key and get every relying party onto the new one. You cannot compel third parties, enumerate them reliably, or say which identities were forged, so this is a negotiated programme with named owners and deadlines, not a change window.

open as a page

showing 31–50 of 50