Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: Openurmind

Active Directory professional here. The passwords are stored in AD in a hash, yes, but tools like Mimikatz allow threat actors to get the hash out of the LSASS process on your machine and literally present the hash to login. It’s far and away the most common method to move laterally in a compromised corporate environment.


30 posted on 05/03/2025 12:35:05 PM PDT by rarestia (“A nation which can prefer disgrace to danger is prepared for a master, and deserves one.” -Hamilton)
[ Post Reply | Private Reply | To 21 | View Replies ]


To: rarestia

I understand hashing is not foolproof. And there are applications such as Corporate where this might be handy and needed. But this new MS feature should be an opt in feature. They are going to mandate it default across the board with no choice. In other words, they own your machine and you have no choice.


31 posted on 05/03/2025 12:39:19 PM PDT by Openurmind
[ Post Reply | Private Reply | To 30 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson