CTD-000178

AD user with compromised password

Critical
Active Directory
Credential Access Initial Access
v6

Signature Identity

CTD-000178
Threat ID
6
Version
IOA-IOC-IOE
Indicator Type

Threat Description

Passwords that appear in known data breaches are considered compromised and are highly vulnerable to exploitation. Attackers often use these leaked credentials in automated attacks across multiple environments.

To help detect such risks, Cayosoft Guardian compares password hashes against a curated database of breached credentials sourced from Have I Been Pwned. This database is downloaded to the Cayosoft cloud server, where it is filtered to retain only the most frequently used passwords. Your Cayosoft Guardian server then downloads this filtered list and performs local hash comparisons directly on your domain controllers.

Cayosoft Guardian is designed with strict security principles to protect sensitive credential data within customer environments.

Cayosoft Guardian does not store or transmit password hashes. All password-related comparison operations are executed locally on your domain controllers, ensuring that password hashes remain within your secure environment and are never sent to the internet or external systems.

This architecture ensures that password hashes are not collected, exported, or exposed outside your Active Directory domain controllers during backup, recovery, or change monitoring operations.

MITRE ATT&CK: Attack Tactics

Credential Access Initial Access

D3FEND: Defend Tactics

D3-PR (Password Rotation)

Remediation

  1. Enforce complexity requirements, length, and expiration settings through Group Policy to enhance security.
  2. Use Active Directory Users and Computers to locate active and inactive accounts.
  3. Reset passwords for compromised or inactive accounts and disable or remove unnecessary accounts to reduce security risks.

Frequently Asked Questions

What does AD user with compromised password mean?

An Active Directory user account has a compromised password when its credentials have been leaked in a known data breach, allowing attackers to use the exposed password hashes in automated attacks.

Attackers can authenticate and access resources using leaked passwords, leading to unauthorized access and potential privilege escalation. This is because password hashes are often used in brute-force attacks or password cracking tools.

Attackers can use exposed password hashes to gain unauthorized access to the affected account, potentially moving laterally within the network. This allows them to escalate privileges and expand their attack scope.

Cayosoft Guardian detects AD user with compromised password by comparing password hashes against a curated database of breached credentials sourced from Have I Been Pwned, ensuring that sensitive credential data remains within the secure environment.

Cayosoft Guardian helps reduce the risk by alerting administrators to reset passwords for compromised or inactive accounts and disable or remove unnecessary accounts, limiting the exposure of vulnerable credentials. This provides visibility into potential attack paths and supports investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access Initial Access
Defend Tactics
D3-PR (Password Rotation)
Indicator Types
IOA IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical