Do you have any historic passwords in your AD?

๐Ÿ› ๏ธ ๐—ฃ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—•๐—ถ๐˜๐˜€

๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐—ต๐—ฎ๐˜ƒ๐—ฒ ๐—ฎ๐—ป๐˜† ๐—ต๐—ถ๐˜€๐˜๐—ผ๐—ฟ๐—ถ๐—ฐ ๐—ฝ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ๐˜€ ๐—ถ๐—ป ๐˜†๐—ผ๐˜‚๐—ฟ ๐—”๐——?

I am sure nobody uses passwords anymore, right?

๐Ÿ”น Everything is passwordless.

๐Ÿ”น Everybody has MFA.

๐Ÿ”น No old accounts.

๐Ÿ”น No forgotten service accounts.

๐Ÿ”น Nothing to worry about.

Wellโ€ฆ in Active Directory, that is usually ๐—ป๐—ผ๐˜ ๐˜๐—ต๐—ฒ ๐—ฟ๐—ฒ๐—ฎ๐—น๐—ถ๐˜๐˜†. It is worth checking from time to time what still resides in your AD, because it often hides quite a history.

โžก๏ธ And this is exactly the kind of low-hanging fruit attackers are going to use.

They will not spend time trying to break into a well-protected account with MFA if there is a ๐Ÿฎ๐Ÿฌ-๐˜†๐—ฒ๐—ฎ๐—ฟ-๐—ผ๐—น๐—ฑ enabled account sitting next to it. Maybe even a service account with a password that has not changed for years and with a path leading somewhere important โš ๏ธ.

That is why the ๐—ฒ๐˜…๐—ฎ๐—ด๐—ด๐—ฒ๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป at the start. We often hear that passwords are gone, everyone uses MFA, everything is modern nowโ€ฆ But in Active Directory, there are almost ๐—ฎ๐—น๐˜„๐—ฎ๐˜†๐˜€ ๐—ฒ๐˜…๐—ฐ๐—ฒ๐—ฝ๐˜๐—ถ๐—ผ๐—ป๐˜€.

โžก๏ธ And exceptions are where attackers strike.

๐—–๐—ต๐—ฒ๐—ฐ๐—ธ๐—ถ๐—ป๐—ด ๐—ณ๐—ผ๐—ฟ ๐˜๐—ต๐—ฒ๐˜€๐—ฒ ๐—ผ๐—น๐—ฑ ๐—ฝ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ๐˜€ ๐—ถ๐˜€ ๐˜ƒ๐—ฒ๐—ฟ๐˜† ๐˜€๐—ถ๐—บ๐—ฝ๐—น๐—ฒ ๐˜„๐—ถ๐˜๐—ต ๐—ฃ๐—ผ๐˜„๐—ฒ๐—ฟ๐—ฆ๐—ต๐—ฒ๐—น๐—น:

Get-ADUser -Filter ‘enabled -eq $true’ -Properties Name, PwdLastSet,lastlogonTimestamp |ย select name, @{N=’pwdlastset’ ; E={[DateTime]::FromFileTime($_.PwdLastSet)}}, @{N=’LastLogonTimestamp’ ; E={[DateTime]::FromFileTime($_.lastlogonTimestamp)}} | Where-Object {$_.PwdLastSet -le $(Get-Date -date $(get-date).AddDays(-365))} |ย Sort-Object -Property PwdLastSet

This gives you enabled accounts with passwords older than 365 days.

๐—ง๐—ต๐—ฒ๐—ป ๐˜๐—ต๐—ฒ ๐—ฟ๐—ฒ๐—ฎ๐—น ๐˜„๐—ผ๐—ฟ๐—ธ ๐˜€๐˜๐—ฎ๐—ฟ๐˜๐˜€:

๐Ÿ”ธ Is the account still needed?

๐Ÿ”ธ Who owns it?

๐Ÿ”ธ Is it a user or service account?

๐Ÿ”ธ Where is it used?

๐Ÿ”ธ What can it access?

You can also use my free and transparent tool ๐—”๐——๐—ฃ๐—ฟ๐—ผ๐—ฏ๐—ฒ for this. It is a simple PowerShell-based tool that scans Active Directory for vulnerabilities and persistence methods.

Do you check for historic passwords in your AD?