Shapefin

Horizon3.ai Enhances NodeZero Platform with Active Directory Tripwires for Proactive Threat Detection

Share It:

Horizon3.ai has announced the availability of Active Directory (AD) Tripwires, a new enhancement to its NodeZero® Offensive Security Platform, designed to provide early detection of identity-driven privilege escalation attempts.

Active Directory is a critical component for identity access management, with an estimated 90% of Global 1000 organizations relying on it. While initial compromises may exploit Common Vulnerabilities and Exposures (CVEs), privilege escalation often occurs through identity-centric techniques such as cached tokens, Kerberos ticket reuse, weak trust relationships, or misconfigurations. Traditional security tools frequently miss these subtle actions, leaving organizations vulnerable to undetected threats.

“With today’s news, our customers now have an attacker-informed early warning system – the equivalent of installing security cameras while breaking into your own house,” stated Snehal Antani, CEO and Co-founder, Horizon3.ai. “We’re proud to be empowering more global defenders to go on the offensive, and, armed with an attacker’s-eye view of their security posture, stop more breaches before they happen.” AD Tripwires aims to provide a clear understanding of where to place decoys to effectively intercept attackers attempting privilege escalation.

This development aligns with recent guidance from the NSA on mitigating Active Directory compromises, which emphasizes the importance of securing AD to protect sensitive data and prevent reputational and financial damage. With AD Tripwires, organizations can reduce attacker dwell time from weeks to minutes, detect attempts to steal credentials or escalate privileges at the identity layer before domain administrator access is achieved, identify stealthy identity attacks that bypass traditional monitoring, and verify the efficacy of identity defenses in production environments.

Research indicates that nearly half of organizations have experienced AD attacks, with over 40% resulting in a compromise. A common tactic involves Kerberos ticket abuse, where attackers silently request tickets to crack and escalate privileges. NodeZero has demonstrated its ability to compromise AD in minutes in benchmarks like Game of Active Directory (GOAD), and AD Tripwires is designed to detect such identity attacks as they occur in production.

Furthermore, AD Tripwires integrates into existing Security Operations Center (SOC) workflows, feeding directly into current detection and alerting tools. Each alert includes details on the compromised identity, the attack path leading to it, and how the adversary attempted its exploitation, facilitating faster and more precise incident response. AD Tripwires is currently available to all NodeZero Tripwires™ customers worldwide.

Horizon3.ai specializes in empowering organizations to continuously verify their security posture using NodeZero®, an autonomous pentesting platform. Built to simulate attacker behavior safely in production, NodeZero identifies exploitable weaknesses, prioritizes fixes based on real-world impact, and verifies remediation at scale. Its clientele spans manufacturing, healthcare, finance, and national security sectors.

Latest Posts