Active Directory Collection
The ability to collect the AD information for a specific AD environment requires the Shield installation of a Shield Service to collect the users, groups, and computers objects and associated attributes. Shield has a standalone PowerShell script within the Deployment (Identity-Security) page that users can access.
Deployment
To deploy the Shield Active Directory (AD) service, navigate to the Deployment (Identity-Security) page and the Shield platform has a pre-generated deployment PowerShell script that can be executed on a single domain-joined Windows server or workstation.
Once at the Deployment page, to generate the deployment PowerShell script, enter a Location, and the script will be displayed in the text box.
Troubleshooting
If there are errors when launching the PowerShell script, users can troubleshoot further by downloading the Shield Cyber MSI to the domain-joined Windows host, and perform the following commands one-by-one or together creating a PowerShell (.ps1) file and executing them together.
- Download the Shield Cyber Services MSI here: Shield Cyber Services MSI
- Run the commands below or save them to a PowerShell (.ps1) file to execute on the target hosts:
If there are additional issues, please send the errors received from these commands to support@shieldcyber.io.
Independent Service Installation
Alternatively, all Shield services can be installed by downloading the Shield Microsoft Installer (MSI) and launched directly on the
Download the guided Shield MSI here and run as Administrator on a Windows host within the desired internal network. Once the MSI is downloaded and executed, you will be prompted to begin the installation:
Click next to decide where to install the files for the services:
On the next screen, you will need to select the services to install. The following services are available:
- Active Directory: Active Directory collection module
- Nessus: Nessus Professional integration service installation
- Shield: Shield network scanner module
Select next to install all dependencies and proceed to the service configuration for the choices that were selected.
Insert the following in the Active Directory service configuration:
- Location Name: Name a location for the specific network where you will be deploying. This can be any value, however, it will need to be distinct for within each subscription. This should be the same value as the Shield scanner configuration within the next step.
- Subscription ID: Insert the Subscription ID for where the scanner location should be created.
- API Key: Enter the designated API key for the subscription. This value can be copied directly from the platform on the Subscriptions page.
Click next to proceed to input the credentials that the Active Directory service will run under the context of:
The credentials will need to be entered in the following format:
- User Name: DOMAIN\Username
- Domain: domain.local
- Password: Password (If you are using a GMSA/MSA, this can be left empty)
Click next to proceed to install all the Shield AD service and finalize the installation:
To verify that the Active Directory service installed correctly, you can open the services pane (Windows Key + run.exe
and enter services.msc
), and the Shield Cyber AD Agent should be running:
Results
Once the service is installed, the AD objects and risks associated with the objects should start to populate within the Identity Security module within the Shield platform.