CTD-000028

Computer not resetting its password periodically

Low
Active Directory
Credential Access
v81

Signature Identity

CTD-000028
Threat ID
81
Version
IOC
Indicator Type

Threat Description

A computer account that has not automatically changed its password might be an indication of threat activities. Computer accounts should automatically change their passwords every 30 days. If a threat actor obtains a password, she can potentially perform pass-through authentication to the domain controller.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

  1. Investigate the computer account.
  2. Remove unnecessary computer accounts from AD. Learn more about passwords of computer accounts.

Frequently Asked Questions

What does Computer not resetting its password periodically mean?

Computer not resetting its password periodically means the account's password has not been updated as expected, typically due to a misconfigured password policy or unauthorized access.

This issue is rated low severity because it does not directly grant attackers administrative privileges. However, if an attacker obtains the static password, they can use pass-through authentication to access the domain controller, making this finding a meaningful exposure that requires further investigation.

Attackers can exploit a computer account with a static password by using it for pass-through authentication. This allows them to bypass normal login requirements and access the domain controller, potentially leading to more serious compromise or lateral movement within the network.

Cayosoft Guardian continuously monitors Active Directory for accounts with non-expiring passwords. When such an account is found, Guardian flags it as a security issue, providing administrators with visibility into potential threats.

Cayosoft Guardian helps reduce the risk by alerting administrators to investigate computer accounts with static passwords. This proactive approach supports ongoing monitoring and change history review, ensuring that unnecessary access points are closed and limiting opportunities for attackers to exploit static passwords.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Infrastructure
Attack Tactics
Credential Access
Defend Tactics
Domain Account Monitoring
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical