CTD-000054

AD user account with DES encryption type enabled

Medium
Active Directory
Credential Access
v21

Signature Identity

CTD-000054
Threat ID
21
Version
IOC
Indicator Type

Threat Description

DES encryption uses a 56-bit key to encrypt the content and is now considered to be highly insecure. Accounts that can use DES to authenticate to services are at significantly greater risk of having that account’s logon sequence decrypted and the account compromised.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

To enable pre-authentication for a user account:

  1. Click Start.
  2. Point to Control Panel.
  3. Point to Administrative Tools.
  4. Click Active Directory Users and Computers.
  5. Find the user with pre-authentication disabled.
  6. In the account options, clear the checkbox Use only Kerberos DES encryption types for this account.
  7. Press OK.

Frequently Asked Questions

What does AD user account with DES encryption type enabled mean?

An Active Directory user account has the DES encryption type enabled, which uses a 56-bit key for authentication. This outdated encryption method is susceptible to brute-force attacks due to its weak cryptographic properties.

AD user accounts using DES encryption are rated medium severity because they can be compromised, allowing attackers to decrypt the logon sequence and gain unauthorized access. The relatively low computational effort required for a brute-force attack amplifies this risk.

Attackers can exploit accounts using DES encryption by performing a brute-force attack on the 56-bit key, allowing them to decrypt the logon sequence and gain unauthorized access. This weak authentication method provides an entry point for malicious activity, enabling attackers to escalate privileges or conduct lateral movement.

Cayosoft Guardian detects AD user accounts using outdated DES encryption by continuously monitoring Active Directory settings, specifically checking the encryption type used for authentication. When an account is found to be using this weak encryption, Guardian flags it as a security issue and provides visibility into the affected account.

Cayosoft Guardian helps reduce the risk by alerting administrators to disable pre-authentication for affected accounts, ensuring they use more secure authentication methods. This proactive approach limits the blast radius and prevents attackers from exploiting weak encryption, ultimately supporting investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access
Defend Tactics
Domain Account Monitoring
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical