Windows WDigest Authentication

๐Ÿ”’ย Secure Bits ๐Ÿ’ก
๐—ฃ๐—น๐—ฎ๐—ถ๐—ป๐˜๐—ฒ๐˜…๐˜ ๐—ฃ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ๐˜€ ๐—ถ๐—ป ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐Ÿญ๐Ÿญ? ๐—ฆ๐˜๐—ถ๐—น๐—น ๐—ฝ๐—ผ๐˜€๐˜€๐—ถ๐—ฏ๐—น๐—ฒ.

Modern Windows versions like Windows 11 and Windows Server 2025 are ๐—ณ๐—ฎ๐—ฟ ๐—บ๐—ผ๐—ฟ๐—ฒ ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—ฏ๐˜† ๐—ฑ๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜. But ๐—น๐—ฒ๐—ด๐—ฎ๐—ฐ๐˜† ๐—ฐ๐—ผ๐—บ๐—ฝ๐—ผ๐—ป๐—ฒ๐—ป๐˜๐˜€ ๐—ฐ๐—ฎ๐—ป ๐˜€๐˜๐—ถ๐—น๐—น ๐—ถ๐—ป๐˜๐—ฟ๐—ผ๐—ฑ๐˜‚๐—ฐ๐—ฒ ๐˜€๐˜‚๐—ฟ๐—ฝ๐—ฟ๐—ถ๐˜€๐—ถ๐—ป๐—ด ๐—ฟ๐—ถ๐˜€๐—ธ๐˜€ โ€” if you’re not careful.

๐—ข๐—ป๐—ฒ ๐—ฒ๐˜…๐—ฎ๐—บ๐—ฝ๐—น๐—ฒ: ๐—ช๐——๐—ถ๐—ด๐—ฒ๐˜€๐˜ ๐—ฎ๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป.
Disabled by default for years โ€” but with one registry tweak, you canย re-enable it, and Windows will startย caching plaintext credentialsย again.

๐Ÿ›  ๐—ฅ๐—ฒ๐—ด๐—ถ๐˜€๐˜๐—ฟ๐˜† ๐—ฝ๐—ฎ๐˜๐—ต:
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest\UseLogonCredential=1
๐—ก๐—ผ ๐—ฟ๐—ฒ๐—ฏ๐—ผ๐—ผ๐˜ ๐—ป๐—ฒ๐—ฒ๐—ฑ๐—ฒ๐—ฑ โ€” just a logon, and the password is in memory.

๐Ÿ‘€ ๐—ช๐—ต๐˜† ๐˜„๐—ผ๐˜‚๐—น๐—ฑ ๐˜๐—ต๐—ถ๐˜€ ๐—บ๐—ฎ๐˜๐˜๐—ฒ๐—ฟ?
For attackers,ย plaintext creds open more doorsย than hashes โ€” and this is a known technique used to bypass otherwise modern protections.

โš ๏ธย ๐—Ÿ๐—ฆ๐—”๐—ฆ๐—ฆ ๐—ฝ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—ถ๐˜€ ๐—ด๐—ผ๐—ผ๐—ฑ, ๐—ฏ๐˜‚๐˜ ๐—ป๐—ผ๐˜ ๐—ฝ๐—ฒ๐—ฟ๐—ณ๐—ฒ๐—ฐ๐˜:
โœ… Windows 11 protects LSASS by default
โ— Butย Credential Guard requires Enterprise editionย โ€” and ๐—บ๐—ฎ๐—ป๐˜† ๐—ผ๐—ฟ๐—ด๐˜€ ๐˜€๐˜๐—ถ๐—น๐—น ๐—ฟ๐˜‚๐—ป ๐—ฃ๐—ฟ๐—ผ
โœ…ย Protected Users groupย is free and effective โ€” and often underused. It blocks several forms of credential caching, including WDigest.

๐Ÿ” If you’re not using Protected Users for your privileged accounts โ€” you’re leaving them exposed.

I am not even mentioning ๐˜๐—ต๐—ฒ ๐—บ๐—ฒ๐—บ๐—ผ๐—ฟ๐˜† ๐—ผ๐—ณ ๐— ๐—ฆ๐—ง๐—ฆ๐—– ๐—ฝ๐—ฟ๐—ผ๐—ฐ๐—ฒ๐˜€๐˜€, which I discuss in another post….

๐Ÿ’ฌ How areย youย defending against credential theft in your org?