πPassword Policy Enumeration
π Overview
π― Why Password Policies Matter
π Assessment Value
β οΈ Key Policy Settings
π§ Linux-Based Enumeration
π Credentialed Enumeration
CrackMapExec - Password Policy
π SMB NULL Session Enumeration
rpcclient - NULL Session
enum4linux - Legacy Tool
enum4linux-ng - Modern Rewrite
Tool Port Usage
π LDAP Anonymous Bind
ldapsearch - LDAP Query
πͺ Windows-Based Enumeration
π NULL Session from Windows
net use Command
Common Error Messages
π Credentialed Windows Enumeration
net.exe - Built-in Tool
PowerView - PowerShell Module
π Password Policy Analysis
π INLANEFREIGHT.LOCAL Analysis
β οΈ Password Spraying Implications
π Default Domain Password Policy
π― HTB Academy Lab Walkthrough
π Lab Questions
Question 1: "What is the default Minimum password length when a new domain is created?"
Question 2: "What is the minPwdLength set to in the INLANEFREIGHT.LOCAL domain?"
π Step-by-Step Solution
1οΈβ£ Connect to Target
2οΈβ£ Method 1: enum4linux
3οΈβ£ Method 2: rpcclient NULL Session
4οΈβ£ Method 3: ldapsearch
5οΈβ£ Method 4: enum4linux-ng
β
Answers
π‘οΈ Password Policy Best Practices
β
Strong Policy Recommendations
π« Disable Legacy Features
π§ Group Policy Hardening
π Detection & Monitoring
π Event IDs to Monitor
π¨ Anomaly Detection
π Baseline Metrics
β‘ Quick Reference Commands
π§ Linux Enumeration
πͺ Windows Enumeration
π Key Takeaways
β
Enumeration Success Factors
β οΈ Critical Considerations
π― Next Steps
Last updated