๐ ๏ธ ๐ฃ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฎ๐น ๐๐ถ๐๐
๐๐ผ ๐๐ผ๐ ๐ต๐ฎ๐๐ฒ ๐ฎ๐ป๐ ๐ต๐ถ๐๐๐ผ๐ฟ๐ถ๐ฐ ๐ฝ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ๐ ๐ถ๐ป ๐๐ผ๐๐ฟ ๐๐?
I am sure nobody uses passwords anymore, right?
๐น Everything is passwordless.
๐น Everybody has MFA.
๐น No old accounts.
๐น No forgotten service accounts.
๐น Nothing to worry about.
Wellโฆ in Active Directory, that is usually ๐ป๐ผ๐ ๐๐ต๐ฒ ๐ฟ๐ฒ๐ฎ๐น๐ถ๐๐. It is worth checking from time to time what still resides in your AD, because it often hides quite a history.
โก๏ธ And this is exactly the kind of low-hanging fruit attackers are going to use.
They will not spend time trying to break into a well-protected account with MFA if there is a ๐ฎ๐ฌ-๐๐ฒ๐ฎ๐ฟ-๐ผ๐น๐ฑ enabled account sitting next to it. Maybe even a service account with a password that has not changed for years and with a path leading somewhere important โ ๏ธ.
That is why the ๐ฒ๐ ๐ฎ๐ด๐ด๐ฒ๐ฟ๐ฎ๐๐ถ๐ผ๐ป at the start. We often hear that passwords are gone, everyone uses MFA, everything is modern nowโฆ But in Active Directory, there are almost ๐ฎ๐น๐๐ฎ๐๐ ๐ฒ๐ ๐ฐ๐ฒ๐ฝ๐๐ถ๐ผ๐ป๐.
โก๏ธ And exceptions are where attackers strike.
๐๐ต๐ฒ๐ฐ๐ธ๐ถ๐ป๐ด ๐ณ๐ผ๐ฟ ๐๐ต๐ฒ๐๐ฒ ๐ผ๐น๐ฑ ๐ฝ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ๐ ๐ถ๐ ๐๐ฒ๐ฟ๐ ๐๐ถ๐บ๐ฝ๐น๐ฒ ๐๐ถ๐๐ต ๐ฃ๐ผ๐๐ฒ๐ฟ๐ฆ๐ต๐ฒ๐น๐น:
Get-ADUser -Filter ‘enabled -eq $true’ -Properties Name, PwdLastSet,lastlogonTimestamp |ย select name, @{N=’pwdlastset’ ; E={[DateTime]::FromFileTime($_.PwdLastSet)}}, @{N=’LastLogonTimestamp’ ; E={[DateTime]::FromFileTime($_.lastlogonTimestamp)}} | Where-Object {$_.PwdLastSet -le $(Get-Date -date $(get-date).AddDays(-365))} |ย Sort-Object -Property PwdLastSet
This gives you enabled accounts with passwords older than 365 days.
๐ง๐ต๐ฒ๐ป ๐๐ต๐ฒ ๐ฟ๐ฒ๐ฎ๐น ๐๐ผ๐ฟ๐ธ ๐๐๐ฎ๐ฟ๐๐:
๐ธ Is the account still needed?
๐ธ Who owns it?
๐ธ Is it a user or service account?
๐ธ Where is it used?
๐ธ What can it access?
You can also use my free and transparent tool ๐๐๐ฃ๐ฟ๐ผ๐ฏ๐ฒ for this. It is a simple PowerShell-based tool that scans Active Directory for vulnerabilities and persistence methods.
Do you check for historic passwords in your AD?
