Password Policy Discovery T1201

Tactic: Discovery

Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment. Password policies are a way to enforce complex passwords that are difficult to guess or crack through Brute Force. This information may help the adversary to create a list of common passwords and launch dictionary and/or brute force attacks which adheres to the policy (e.g. if the minimum password length should be 8, then not trying passwords such as 'pass123'; not checking for more than 3-4 passwords per account if the lockout is set to 6 as to not lock out accounts).

Events covered

11 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 32 rules share fields, values, and exclusions.

Fields filtered most (45 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine8contains 7, regex_match 1accounts, --local-auth, -d , -h , accounts
ScriptBlockText7contains 4, in 3, eq 2get-addefaultdomainpasswordpolicy, .getgporeport(), .maxpasswordage, .minlengthpassword, .minpasswordage
EventID6eq 64104, 4799, DeleteAccountPasswordPolicy, UpdateAccountPasswordPolicy
process_name6eq 5, starts_with 2, ends_with 1cmd.exe, powershell, \lsass.exe, dsget.exe, dsquery.exe
Image4ends_with 3, eq 1\net.exe, \net1.exe, \crackmapexec.exe, c:\windows\adws\microsoft.activedirectory.webservices.exe
OriginalFileName4eq 4net1.exe, net.exe, cmd.exe, powershell.exe, powershell_ise.exe
event.category4eq 4process, LOGIN
aws::eventName3in 2, eq 1GetAccountPasswordPolicy, PutAccountPasswordPolicy, UpdateAccountPasswordPolicy, consolelogin, deleteaccountpasswordpolicy
ObjectServer2eq 2security account manager
aws::userAgent2eq 1, regex_match 1(azure|sharp|blood)(hound)/.*, mozilla/5.0 (windows nt 10.0; win64; x64)...
data_stream.dataset2eq 1, in 1azure.activitylogs, azure.auditlogs, azure.graphactivitylogs, azure.signinlogs, o365.audit
process.Ext.api.name2eq 2ldap_search
process.Ext.api.parameters.search_filter2wildcard 2, contains 1(&(objectCategory=Computer)(!userAccountControl:1.2.840.1..., (&(objectCategory=person)(objectClass=user)(!(userAccount..., (&(objectCategory=person)(objectClass=user)(directReports..., *(pwdlastset>=*(operatingSystem=*windows*)), msds-passwordsettings
sourcetype2eq 2aws:cloudtrail
user.id2ne 2S-1-5-18

Top indicator values (312 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventIDeq
4104
4269
process_nameeq
cmd.exe
4121
process_nameeq
net1.exe
239
OriginalFileNameeq
net1.exe
344
OriginalFileNameeq
net.exe
231
event.categoryeq
process
3142
CommandLinecontains
accounts
22
CommandLinecontains
--local-auth
1
CommandLinecontains
-d
18
CommandLinecontains
-h
1
CommandLinecontains
-h 'nthash'
1
CommandLinecontains
-m
1
CommandLinecontains
-m pe_inject
1
CommandLinecontains
-o
13
CommandLinecontains
-p
111
CommandLinecontains
-u
18
CommandLinecontains
-x
12
CommandLinecontains
10.
13
CommandLinecontains
192.168.
13
Imageends_with
\net.exe
249
Imageends_with
\net1.exe
247
ObjectServereq
security account manager
27
ScriptBlockTextcontains
get-addefaultdomainpasswordpolicy
22
ScriptBlockTextin
get-addefaultdomainpasswordpolicy
22
process.Ext.api.nameeq
ldap_search
214
process_namestarts_with
powershell
25
sourcetypeeq
aws:cloudtrail
259
user.idne
S-1-5-18
236
AccessListcontains
%%5392
12
ActionTypene
ListeningConnectionCreated
14

Exclusions (39 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imagewildcard
?:\program files\azure advanced threat protection sensor\*\microsoft.tri.sensor.exe
2
Imagewildcard
?:\windows\adfs\microsoft.identityserver.servicehost.exe
2
Imagewildcard
?:\windows\adws\microsoft.activedirectory.webservices.exe
2
Imagewildcard
?:\program files (x86)\trend micro\security agent\pccntmon.exe
1
Imagewildcard
?:\program files\microsoft sql server\mssql??.mssqlserver\mssql\binn\sqlservr.exe
1
user.ideq
s-1-5-18
2
CommandLinein
*/forcelogoff*
1
CommandLinein
*/maxpwage*
1
CommandLinein
*/minpwage*
1
CommandLinein
*/minpwlen*
1
CommandLinein
*/uniquepw*
1
ScriptBlockTexteq
# copyright: (c) 2018, ansible project
1
ScriptBlockTexteq
#ansiblerequires -csharputil ansible.basic
1
ScriptBlockTexteq
#requires -module ansible.moduleutils.addtype
1
ScriptBlockTexteq
43c15630-959c-49e4-a977-758c5cc93408
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 8 rules

Elastic 8 rules

Splunk 11 rules

Kusto 2 rules

YARA-L 1 rule

Panther 2 rules