Technique.View on attack.mitre.org
Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment. Password policies are a way to enforce complex passwords that are difficult to guess or crack through Brute Force. This information may help the adversary to create a list of common passwords and launch dictionary and/or brute force attacks which adheres to the policy (e.g. if the minimum password length should be 8, then not trying passwords such as 'pass123'; not checking for more than 3-4 passwords per account if the lockout is set to 6 as to not lock out accounts).
Password policies can be set and discovered on Windows, Linux, and macOS systems via various command shell utilities such as net accounts (/domain), Get-ADDefaultDomainPasswordPolicy, chage -l <username>, cat /etc/pam.d/common-password, and pwpolicy getaccountpolicies . Adversaries may also leverage a Network Device CLI on network devices to discover password policy information (e.g. show aaa, show aaa common-criteria policy all).
Password policies can be discovered in cloud environments using available APIs such as GetAccountPasswordPolicy in AWS .
Rules on DetectionCode tagged with T1201.
| Rule | Level | Log source |
|---|---|---|
| HackTool - CrackMapExec Execution | high | windows / process_creation |
| Password Policy Enumerated | medium | windows / NULL |
| Cisco Discovery | low | cisco / NULL |
| Password Policy Discovery - Linux | low | linux / NULL |
| Password Policy Discovery With Get-AdDefaultDomainPasswordPolicy | low | windows / ps_script |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| ASL AWS Password Policy Changes | Hunting | NULL | |
| AWS High Number Of Failed Authentications For User | Anomaly | NULL | AWS CloudTrail ConsoleLogin |
| AWS Password Policy Changes | Hunting | NULL | AWS CloudTrail UpdateAccountPasswordPolicy, AWS CloudTrail GetAccountPasswordPolicy, AWS CloudTrail DeleteAccountPasswordPolicy |
| Get ADDefaultDomainPasswordPolicy with Powershell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Get ADDefaultDomainPasswordPolicy with Powershell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 |
| Get ADUserResultantPasswordPolicy with Powershell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Get ADUserResultantPasswordPolicy with Powershell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| Get DomainPolicy with Powershell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Get DomainPolicy with Powershell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| Password Policy Discovery with Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Password Policy Discovery with Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupChimera | Chimera has used the NtdsAudit utility to collect information related to accounts and passwords. |
| GroupOilRig | OilRig has used net.exe in a script with |
| GroupTurla | Turla has used |
| Used by | Procedure example |
|---|---|
| ToolCrackMapExec | CrackMapExec can discover the password policies applied to the target system. |
| MalwareKwampirs | Kwampirs collects password policy information with the command |
| ToolNet | The |
| ToolPoshC2 | PoshC2 can use |
| Used by | Procedure example |
|---|---|
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net accounts` command as part of their advanced reconnaissance. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.