@lkarlslund In Trimarc tools, we don't expand virtual groups like Authenticated Users or very large groups like Domain Users/Computers. Instead we use those groups only when simulating access tokens or determining the severity of misconfiguration. Otherwise, results are unusable!
Conversation
Notices
-
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Tuesday, 28-Nov-2023 19:49:50 JST Jake Hildreth (acorn) :blacker_heart_outline: -
Embed this notice
Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Tuesday, 28-Nov-2023 19:49:51 JST Lars Karlslund :verified: For Adalanche users:
I'm very unsure whether adding every account in an AD to the "Authenticated Users" group was a good decision or not. It does show the massive impact this group has, but it also clutters large graphs.
Any input?
-
Embed this notice