---
title: "Zerologon: How Bitdefender Protects Customers from this No-Credential Post-Exploit Technique"
description: Bitdefender customers are protected from this post-exploit technique via our Network Attack Defense, Anti-Malware SDK and Indicator of Risk (IOR) technologies
image: https://businessinsights.bitdefender.com/hubfs/Banner-Blog.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

 By [**Ashish Chakrabortty**](https://businessinsights.bitdefender.com/author/ashish-chakrabortty) / Sep 21, 2020

# Zerologon: How Bitdefender Protects Customers from this No-Credential Post-Exploit Technique

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/zerologon-bitdefender-customers-protected-post-exploit-technique&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/zerologon-bitdefender-customers-protected-post-exploit-technique&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/zerologon-bitdefender-customers-protected-post-exploit-technique&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/zerologon-bitdefender-customers-protected-post-exploit-technique&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/zerologon-bitdefender-customers-protected-post-exploit-technique&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/zerologon-bitdefender-customers-protected-post-exploit-technique&utm_medium=social&utm_source=facebook)

- Zerologon is a zero-credential vulnerability that exploits Windows Netlogon to allow adversaries access to the Active Directory domain controllers, first reported in August 2020 
- “This attack has a huge impact” according to researchers, as attackers on the local network can launch this exploit to compromise the Windows domain controller with no authentication
-  Bitdefender customers are protected from this post-exploit technique via our Network Attack Defense, Anti-Malware SDK and Indicator of Risk (IOR) technologies

Termed as [Zerologon](https://arstechnica.com/information-technology/2020/09/new-windows-exploit-lets-you-instantly-become-admin-have-you-patched/) ([CVE-2020-1472](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472)), the attacker exploits endpoint native tools to elevate privileges using the Netlogon vulnerability. Developed by [researchers from Secura](https://www.secura.com/blog/zero-logon), it allows attackers to gain unauthenticated control of the Active Directory using [Netlogon Remote Protocol](https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-nrpc/2d776bfc-e81f-4c8f-9da8-4c2920f65413) (MS-NRPC) to connect to a domain controller and obtain domain administrator access. 

**Technical Overview** 

The Netlogon Remote Procedure Call is an RPC interface available on Windows Domain Controller. It is used for various tasks related to user and machine authentication using the NT (New Technology) LM (LAN Manager) protocol.  

This protocol does not use the same authentication scheme as other RPC services. Instead it uses a customized cryptographic protocol to allow a client (a domain-joined computer) and server (the domain controller) prove to each other that they both know a shared secret cipher. 

The [cryptographic protocol](https://www.secura.com/blog-cve-2019-1424) used is rather unorthodox and has not been put under much scrutiny ([CVE-2019-1424](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1424)). A study conducted last year showed that Netlogon calls were not being encrypted when a fallback SMB occurred while a session had already been established. 

In the technical overview diagram below: 

- The Netlogon message parameters in the protocol are filled with zeroes 
- Attacker retries the handshake a few times to set an empty password on the domain controller 
- Attacker changes the computer password of the domain controller stored in the Active Directory to obtain domain admin credentials and then restores the original domain controller password 

![blogpost-prtsc](https://businessinsights.bitdefender.com/hs-fs/hubfs/blogpost-prtsc.png?width=483&name=blogpost-prtsc.png)Image source: [Secura CVE-2020-1472](https://www.secura.com/pathtoimg.php?id=2055) 

**Protection during solutionrollout** 

Microsoft is [addressing the vulnerability](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472) in a phased two-part rollout, with a patch already available for part 1. These updates address the vulnerability by modifying how Netlogon handles the usage of secure channels. The second phase of the Windows updates will become available in Q1-2021. 

Bitdefender customers are already protected by our end-to-end GravityZone breach avoidance platform which deploys heuristic models to analyze the behavior of the message requests used to compromise the domain controller hosted on the Active Directory. It prevents the adversary from leveraging “living-off-the-land" tools to make system or environment level changes.  

The following Bitdefender technologies identify this vulnerability early in the attack kill-chain: 

**1. Identifying network exploits** 

Bitdefender Network Attack Defense quickly senses exploit attempts such as initial access, discovery, and credential access and prevents an array of attacks from lateral movement, web-service attacks, and traffic-level attacks to privacy breaches performed via phishing attacks to exfiltrate data.  

**2. Advanced Anti-Malware Security** 

Patented [machine learning](https://download.bitdefender.com/resources/files/News/CaseStudies/study/212/Bitdefender-2017-TechnicalBrief-MachineLearning-crea2103-A4-en-EN-2-GenericUse.pdf?adobe_mc=MCMID%3D00140555670055345834605320005372784273%7CMCORGID%3D0E920C0F53DA9E9B0A490D45%2540AdobeOrg%7CTS%3D1600413120) combines security capabilities required to protect against both legacy and modern attacks using technologies including: 

- [HyperDetect](https://download.bitdefender.com/resources/files/News/CaseStudies/study/206/Bitdefender-2017-TechnicalBrief-HyperDetect-crea2103-A4-en-EN-2-GenericUse.pdf?adobe_mc=MCMID%3D00140555670055345834605320005372784273%7CMCORGID%3D0E920C0F53DA9E9B0A490D45%2540AdobeOrg%7CTS%3D1600413120), a tunable machine learning technology, extracts meanings and instructions from command line and scripts 
- [Process Inspector](https://explore.bitdefender.com/business-security-documentation/process-inspector-technical-brief) operates on a zero-trust basis, monitoring running processes and system events 

Behavior analytics coupled with event correlation allows for effective remediation actions including terminating the process and rolling back changes. 

**3. Indicators of Risk**  

Bitdefender provides an Integrated, Centralized [Endpoint Risk Analytics](https://businessresources.bitdefender.com/endpoint-risk-analytics-endpoint-security-whitepaper?hsLang=en-us) (ERA) module that provides comprehensive identification and remediation of many network and operating system risks at the endpoint level. 

The indicators of risk are grouped into three major categories: 

- Misconfigurations 
- Vulnerable applications 
- Human-based risks 

[Patch Management](https://www.bitdefender.com/business/patch-management/) creates a flexible and simplified workflow to support both automatic and manual patching for vulnerable applications. 

[Human Risk Analytics](https://www.bitdefender.com/news/bitdefender-gravityzoneadds-human-risk-analytics-to-bolster-defense-against-user-error-malice-3866.html) provides details about user behavior while preserving user autonomy to perform their jobs and retaining a measure of privacy for their actions.  

If you are looking to secure your infrastructure, get a [free, 90-day](https://www.bitdefender.com/business/enterprise-products/ultra-plus/90-days-free-trial.html) full product evaluation for GravityZone with our unique, limited time offer.  

If you are a service provider, get a [free full-featured trial](https://www.bitdefender.com/business/service-providers-products/cloud-security-msp.html) of the multitenant security suite, Bitdefender [Cloud Security for MSP](https://www.bitdefender.com/business/service-providers-products/cloud-security-msp.html) 

Bitdefender is a technology provider of choice, with 38% of cybersecurity vendors worldwide using one or more Bitdefender technologies. To maintain our high quality and accuracy of detection, Bitdefender remains committed to developing technologies in house, and to maintaining over 50% of its workforce in R&D teams.  

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/famoussparrow-apt-targets-azerbaijani-oil-gas-industry?hsLang=en-us>

### [FamousSparrow APT Targets Azerbaijani Oil and Gas Industry](https://businessinsights.bitdefender.com/famoussparrow-apt-targets-azerbaijani-oil-gas-industry?hsLang=en-us)

<https://businessinsights.bitdefender.com/akira-ransomware-a-shifting-force-in-the-raas-domain?hsLang=en-us>

### [Akira Ransomware: A Shifting Force in the RaaS Domain](https://businessinsights.bitdefender.com/akira-ransomware-a-shifting-force-in-the-raas-domain?hsLang=en-us)

<https://businessinsights.bitdefender.com/unpacking-bellaciao-a-closer-look-at-irans-latest-malware?hsLang=en-us>

### [Unpacking BellaCiao: A Closer Look at Iran’s Latest Malware](https://businessinsights.bitdefender.com/unpacking-bellaciao-a-closer-look-at-irans-latest-malware?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Ashish Chakrabortty",
    "url" : "https://businessinsights.bitdefender.com/author/ashish-chakrabortty"
  },
  "dateModified" : "2020-09-21T15:00:00.378Z",
  "datePublished" : "2020-09-21T15:00:00.000Z",
  "headline" : "Zerologon: How Bitdefender Protects Customers from this No-Credential Post-Exploit Technique",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/Banner-Blog.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/zerologon-bitdefender-customers-protected-post-exploit-technique",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```