Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Level 4 with one computer (Privileged Access Workstation) #12

Open
C0FFEEC0FFEE opened this issue Jan 23, 2022 · 7 comments
Open

Level 4 with one computer (Privileged Access Workstation) #12

C0FFEEC0FFEE opened this issue Jan 23, 2022 · 7 comments
Assignees
Labels
good first issue Good for newcomers

Comments

@C0FFEEC0FFEE
Copy link

C0FFEEC0FFEE commented Jan 23, 2022

Level four can be achieved with only one physical computer on your desktop. One can use virtual machines and call it a Privileged Access Workstation: https://techcommunity.microsoft.com/t5/data-center-security/privileged-access-workstation-paw/ba-p/372274

It hurts a little less than two physical computers. ;)

@sergiomarotco
Copy link
Owner

@C0FFEEC0FFEE interesting.
I need time to analyze.

@sergiomarotco
Copy link
Owner

@C0FFEEC0FFEE Do you have experience using this technology if so?

@C0FFEEC0FFEE
Copy link
Author

Yes

@sergiomarotco
Copy link
Owner

@C0FFEEC0FFEE what if an attacker takes over the Guarded host after PAW was started, what prevents him from using the PAW virtual machine?

@C0FFEEC0FFEE
Copy link
Author

C0FFEEC0FFEE commented Feb 1, 2022

I did not have time to read the article you linked. In my case I put the untrusted workload (e-mail, browsing the web, office work) into a VM running on the PAW with a vNIC bridged onto the physical NIC. The PAW itself has an always-on VPN connection into the data centre. In this case the only attack vector would be to break out of the hypervisor, which is the tradeoff to using two physical devices. The OS on the PAW is hardened und watched closely by EDR.

@sergiomarotco sergiomarotco self-assigned this Feb 9, 2022
@sergiomarotco sergiomarotco added the good first issue Good for newcomers label Feb 9, 2022
@parlortrickss
Copy link

That would not pass Australia IRAP, you would need 2 physically separate hosts if you were to have separation

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
good first issue Good for newcomers
Projects
None yet
Development

No branches or pull requests

3 participants