CTD-000072

User account with old passwords

Low
Active Directory
Credential Access Persistence
v25

Signature Identity

CTD-000072
Threat ID
25
Version
IOE
Indicator Type

Threat Description

An Active Directory user account whose password is not changed periodically can be easily compromised. A malicious attacker might obtain an account’s password and use it to get into the environment and escalate privileges. Regular password rotation reduces the risk and effectiveness of password-based attacks by shortening the timeframe during which a compromised password may be valid.

NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.

According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.

MITRE ATT&CK: Attack Tactics

Credential Access Persistence

D3FEND: Defend Tactics

Credential Rotation

Remediation

Change the password of the account. Implement regular password rotation.

Frequently Asked Questions

What does User account with old passwords mean?

User account with old passwords refers to one or more user accounts in the Active Directory environment that have not had their passwords changed within a specified timeframe, potentially allowing an attacker to obtain the password and use it for unauthorized access.

This condition creates exposure, but typically requires additional attacker steps or context to become serious. An attacker would need to obtain the password and use it for access, which can be detected through monitoring and alerting.

An attacker may attempt to obtain the password through various means, such as brute-force attacks or phishing. If successful, they can use the password for unauthorized access and potentially escalate privileges by leveraging the compromised credentials.

Cayosoft Guardian continuously monitors password policies to identify accounts that have not had their passwords changed within a specified timeframe, providing visibility into potential security issues and supporting investigation and response efforts.

Cayosoft Guardian helps reduce the risk by alerting administrators when user accounts have old passwords, enabling them to change the password and implement regular password rotation. This limits the timeframe during which a compromised password may be valid.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access Persistence
Defend Tactics
Credential Rotation
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical