Password Policy Discovery

T1201

Technique.View on attack.mitre.org

About this technique

Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment. Password policies are a way to enforce complex passwords that are difficult to guess or crack through Brute Force. This information may help the adversary to create a list of common passwords and launch dictionary and/or brute force attacks which adheres to the policy (e.g. if the minimum password length should be 8, then not trying passwords such as 'pass123'; not checking for more than 3-4 passwords per account if the lockout is set to 6 as to not lock out accounts).

Password policies can be set and discovered on Windows, Linux, and macOS systems via various command shell utilities such as net accounts (/domain), Get-ADDefaultDomainPasswordPolicy, chage -l <username>, cat /etc/pam.d/common-password, and pwpolicy getaccountpolicies . Adversaries may also leverage a Network Device CLI on network devices to discover password policy information (e.g. show aaa, show aaa common-criteria policy all).

Password policies can be discovered in cloud environments using available APIs such as GetAccountPasswordPolicy in AWS .

Detection rules16

Rules on DetectionCode tagged with T1201.

Sigma5

RuleLevelLog source
HackTool - CrackMapExec Executionhighwindows / process_creation
Password Policy Enumeratedmediumwindows / NULL
Cisco Discoverylowcisco / NULL
Password Policy Discovery - Linuxlowlinux / NULL
Password Policy Discovery With Get-AdDefaultDomainPasswordPolicylowwindows / ps_script

Splunk11

RuleTypeRiskData source
ASL AWS Password Policy ChangesHuntingNULL
AWS High Number Of Failed Authentications For UserAnomalyNULLAWS CloudTrail ConsoleLogin
AWS Password Policy ChangesHuntingNULLAWS CloudTrail UpdateAccountPasswordPolicy, AWS CloudTrail GetAccountPasswordPolicy, AWS CloudTrail DeleteAccountPasswordPolicy
Get ADDefaultDomainPasswordPolicy with PowershellHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Get ADDefaultDomainPasswordPolicy with Powershell Script BlockHuntingNULLPowershell Script Block Logging 4104
Get ADUserResultantPasswordPolicy with PowershellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Get ADUserResultantPasswordPolicy with Powershell Script BlockTTPNULLPowershell Script Block Logging 4104
Get DomainPolicy with PowershellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Get DomainPolicy with Powershell Script BlockTTPNULLPowershell Script Block Logging 4104
Password Policy Discovery with NetHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Password Policy Discovery with NetHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups3

Software4

Campaigns1

Procedure examples8

Groups3

Used byProcedure example
GroupChimera

Chimera has used the NtdsAudit utility to collect information related to accounts and passwords.

GroupOilRig

OilRig has used net.exe in a script with net accounts /domain to find the password policy of a domain.

GroupTurla

Turla has used net accounts and net accounts /domain to acquire password policy information.

Software4

Used byProcedure example
ToolCrackMapExec

CrackMapExec can discover the password policies applied to the target system.

MalwareKwampirs

Kwampirs collects password policy information with the command net accounts.

ToolNet

The net accounts and net accounts /domain commands with Net can be used to obtain password policy information.

ToolPoshC2

PoshC2 can use Get-PassPol to enumerate the domain password policy.

Campaigns1

Used byProcedure example
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net accounts` command as part of their advanced reconnaissance.

References4

  1. AWS GetPasswordPolicy Open source
    Amazon Web Services. (n.d.). AWS API GetAccountPasswordPolicy. Retrieved June 8, 2021.
  2. Jamf User Password Policies Open source
    Holland, J. (2016, January 25). User password policies on non AD machines. Retrieved April 5, 2018.
  3. Superuser Linux Password Policies Open source
    Matutiae, M. (2014, August 6). How to display password policy information for a user (Ubuntu)?. Retrieved April 5, 2018.
  4. US-CERT-TA18-106A Open source
    US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.