From Zero to Full Domain Admin: The Real-World Story of a Ransomware Attack
Download resourcesAbout this session
Joseph Carson, Chief Security Scientist and Advisory CISO at Delinea, reconstructs a real CryLock ransomware incident from both sides, first as responder, then in a live attacker demo. The victim, mid cloud migration, had no rehearsed plan, no out-of-band comms, and a backup sharing production credentials on a flat online network, so attackers encrypted it too. With no cyber insurance, the firm weighed paying while data still exfiltrated, then unplugged its internet and rebuilt from a year-old server that had escaped decommissioning, losing a year of data. Reconstructing five years of logs with Plaso, Carson traced patient zero: attackers had two weeks of hands-on-keyboard access, with initial access bought from access brokers seven months earlier. The demo walks the full kill chain: cracking NTLM hashes with Hashcat, Responder poisoning, RDP brute force via a shadow-IT accountant, an 'important stuff' credential file and browser-stored passwords, local-admin abuse, security-disabling scripts, Mimikatz dumping, NetScan lateral movement to a domain controller, sticky-keys persistence, and Cyrillic scripts hinting at Russian-speaking operators. He closes on defences: ransomware-tailored tested backups, least privilege, just-in-time PAM, internal MFA, application control, log correlation, and translating techniques into business risk.
Following in the footsteps of a cyber-criminal and uncovering their digital footprint. This is a journey inside the mind of an ethical hacker's response to a ransomware incident that brought a business to a full stop, and discovering the evidence left behind to uncover their attack path and the techniques used. In this session I will cover a real-world incident response to the CryLock ransomware showing the techniques used by the attackers. The footprints left behind and uncovering the techniques used. Joe Carson, Chief Security Scientist & Advisory CISO at Delinea, who will take you through the mind of a hacker and follow the footsteps that led to a damaging Crylock ransomware attack. Joe will look at tools and techniques cyber criminals use to hack endpoints, such as the WannaCry vulnerability, RDP Brute Force, Mimikatz, and Responder, and the paths they can take toward your enterprise infrastructure and data. Joe will walkthrough the attack, step-by-step, showing: • How attackers gained access to system • Established staging • What tools were used • What commands were executed • How the ransomware was delivered • How AD elevation was achieved Joe will then cover some of the needed incident response steps, utilizing the same use case but from the viewpoint of defender, including: • Detection, what triggered alert • Finding what Cryptor was used • Cleaning up systems • Finding patient zero
Key takeaways
- Design and rehearse a backup strategy specifically for ransomware: keep an offline, credential-isolated copy, keep the incident-response plan itself offline, and test the restore speed, not just that backups exist.
- Remove local administrator rights; the demo shows local admin is only two steps from full domain admin through credential luring and Mimikatz.
- Adopt just-in-time privileged access, system-generated passwords, MFA on internal system-to-system access, and application control so legitimate tools cannot be abused unnoticed.
- Hunt proactively for persistence and attacker behaviour, security-disabling scripts, registry changes for cleartext credentials, sticky-keys backdoors, rather than discovering them only after the ransomware fires.
- Correlate and actually review logs, and flag legitimate admin tools running at odd hours (2 a.m. on a weekend) as suspicious even when the software itself is allowed.
Speakers

Joseph is Chief Security Scientist and Advisory CISO at Delinea. A Cyber Security Professional with 25+ years’ experience in Enterprise Security & Infrastructure, Joseph is a Certified Information Systems Security Professional (CISSP). An active… Read moreRead less
Joseph is Chief Security Scientist and Advisory CISO at Delinea. A Cyber Security Professional with 25+ years’ experience in Enterprise Security & Infrastructure, Joseph is a Certified Information Systems Security Professional (CISSP). An active member of the Cyber Security community and a frequent speaker at Cyber Security events globally Joseph is also an adviser to several governments and cyber security conferences. (ISC)² Information Security Leadership Award (ISLA®) Americas Winner 2018. Joseph is also host of the award-winning podcast 401 Access Denied.
