Password Policy Discovery T1201
Tactic: Discovery
Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment. Password policies are a way to enforce complex passwords that are difficult to guess or crack through Brute Force. This information may help the adversary to create a list of common passwords and launch dictionary and/or brute force attacks which adheres to the policy (e.g. if the minimum password length should be 8, then not trying passwords such as 'pass123'; not checking for more than 3-4 passwords per account if the lockout is set to 6 as to not lock out accounts).
Events covered
11 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4661 | A handle to an object was requested. |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| Security-Auditing | Event ID 4799 | A security-enabled local group membership was enumerated. |
| Defender-DeviceEvents | LdapSearch | LDAP search |
| Defender-DeviceInfo | any | Device information |
| Defender-DeviceNetworkEvents | any | Network activity |
| Defender-DeviceNetworkInfo | any | Device network configuration |
| Linux-Auditd | Event ID 1302 | PATH |
| Linux-Auditd | Event ID 1309 | EXECVE |
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
Authoring guide
These 32 rules share fields, values, and exclusions.
Fields filtered most (45 distinct)
These fields appear most often in rule filters.
Top indicator values (312 distinct)
These values appear most often in rule predicates.
Exclusions (39 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 8 rules
- Cisco Discovery
- Domain password policy enumeration
- HackTool - CrackMapExec Execution
- Net.EXE Execution
- Password Policy Discovery - Linux
- Password policy discovery via commandline
- Password Policy Discovery With Get-AdDefaultDomainPasswordPolicy
- Password Policy Enumerated
Elastic 8 rules
- Deprecated - PowerShell Script with Discovery Capabilities
- Domain Password Policy Enumeration via LDAP
- Entra ID Sign-in BloodHound Suite User-Agent Detected
- Entra ID Sign-in TeamFiltration User-Agent Detected
- Password Spraying Enumeration via LDAP
- PowerShell Script with Password Policy Discovery Capabilities
- PowerShell Suspicious Discovery Related Windows API Functions
- Windows Account or Group Discovery
Splunk 11 rules
- AWS High Number Of Failed Authentications For User
- AWS Password Policy Changes
- Get ADDefaultDomainPasswordPolicy with Powershell
- Get ADDefaultDomainPasswordPolicy with Powershell Script Block
- Get ADUserResultantPasswordPolicy with Powershell
- Get ADUserResultantPasswordPolicy with Powershell Script Block
- Get DomainPolicy with Powershell
- Get DomainPolicy with Powershell Script Block
- SharpHound Enumeration (Windows Event Log)
- SharpHound Keywords (PowerShell)
- Windows Password Policy Discovery with Net