CTD-000090

AD user with suspicious password refresh

Medium
Active Directory
Credential Access Defense Evasion
v18

Signature Identity

CTD-000090
Threat ID
18
Version
IOC
Indicator Type

Threat Description

If the option User must change password at next logon is turned on and then turned off again later, it could mean there might be a problem with a threat actor tried to break the organization’s password policy.

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

To reset an Active Directory user’s password with Active Directory Users and Computers (ADUC) console:

  1. Open the ADUC console.
  2. Search for the user account for which you want to change the password.
  3. Right-click on it and select Reset password.
  4. Enter a new password (twice).
  5. Enable the option User must change password at next logon. 

Frequently Asked Questions

What does AD user with suspicious password refresh mean?

An Active Directory user's password has been refreshed or reset in a way that may indicate an attacker attempted to modify the organization's password settings. This can be a sign of defense evasion tactics, where attackers manipulate password policies to avoid detection.

This finding indicates potential compromise of the organization's password policy, allowing attackers to manipulate password settings and potentially exploit weakened security exposure. However, it does not grant administrative control or enable serious compromise on its own.

Attackers may attempt to reset passwords for other users or exploit the compromised password policy by manipulating settings and policies to maintain persistence and access. This can also facilitate lateral movement within the organization.

Cayosoft Guardian detects AD user with suspicious password refresh by continuously monitoring Active Directory for changes in password settings and policies, providing visibility into potential security issues. When a suspicious password refresh is detected, Guardian alerts administrators to investigate and take corrective action.

Cayosoft Guardian helps reduce the risk of AD user with suspicious password refresh by providing real-time monitoring and alerting administrators to potential security issues. This enables teams to review and reset passwords, maintaining a strong password policy and preventing attackers from exploiting compromised credentials.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access Defense Evasion
Defend Tactics
Domain Account Monitoring
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical