CTD-000152

Active Directory detect dormant accounts for computers and users

Medium
Active Directory
Credential Access
v9

Signature Identity

CTD-000152
Threat ID
9
Version
IOE
Indicator Type

Threat Description

This rule detects inactive and never used user and computer accounts in Active Directory (AD) based on the LastLogonTimestamp attribute. This attribute records the latest time an account successfully logged into the domain. However, it only replicates across domain controllers about every 9 to 14 days, making it a more performance-friendly option for identifying dormant accounts.

By identifying these accounts, administrators can prevent the unauthorized use of stale credentials or deactivate accounts that are no longer needed.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

D3-CRO (Credential Rotation) D3-DAM (Domain Account Monitoring)

Remediation

  1. For inactive accounts, confirm their necessity by checking with department heads or verifying whether associated assets, especially computers, are still in use.
  2. For never-used accounts, confirm whether these accounts were provisioned for specific use cases or created by mistake.
  3. Right-click on the accounts within ADUC and select Disable Account to prevent further use of these accounts without immediate deletion, allowing time for re-evaluation.
  4. Move disabled accounts into an Inactive Accounts Organizational Unit (OU) for future tracking, archiving, or deletion.
  5. Notify relevant stakeholders, such as managers or system owners, about disabled accounts, particularly for high-privilege accounts.
  6. Establish regular monitoring to detect any unexpected reactivation of disabled accounts. Use audit logs to verify these reactivation events.
  7. Exclude critical service accounts that may have infrequent logon activity but are necessary for system functionality.
  8. Pay extra attention to dormant admin or privileged accounts, as they pose a higher security risk if compromised.

Frequently Asked Questions

What does Active Directory detect dormant accounts for computers and users mean?

Active Directory detects inactive and never used user and computer accounts based on the LastLogonTimestamp attribute, allowing administrators to identify and manage stale credentials.

This feature is rated medium severity because it helps prevent unauthorized access using stale credentials. Compromised inactive accounts can still pose a security risk due to their potential privilege level, which an attacker could exploit if not properly managed.

Attackers can use compromised inactive user or computer accounts to gain unauthorized access to the domain, potentially escalating privileges or performing malicious activities. This is because these accounts often retain their original permissions and access rights, making them a potential entry point for attackers.

Cayosoft Guardian continuously monitors the LastLogonTimestamp attribute across the Active Directory environment domain to identify inactive or never used accounts, flagging them as security issues for administrator review.

Cayosoft Guardian alerts administrators to disable or delete inactive user and computer accounts, preventing unauthorized access using stale credentials and reducing the security risk posed by these accounts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access
Defend Tactics
D3-CRO (Credential Rotation) D3-DAM (Domain Account Monitoring)
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical