Bottom line: Organizations must implement security controls to prevent 12 of the 17 identified techniques.
What's happening: The guidance, published on the CISA website, outlines strategies to detect and mitigate the 17 most common Active Directory compromise techniques, including techniques used by APT10 and Lazarus Group. The guidance is based on information from the NSA, the FBI, and the ICS-CERT. The techniques are used by attackers to gain unauthorized access to sensitive data.
What to do: Security leaders should review the guidance and develop a comprehensive security plan to address the identified techniques, including implementing security controls to prevent 12 of the 17 identified techniques and conducting regular vulnerability assessments to identify and remediate vulnerabilities. END: [optional] No additional information beyond the executive briefing.