Manipulating User Passwords Without Mimikatz
ID: 37b71215-551e-5cee-833b-df49d3d05cb6
STIX ID: report--37b71215-551e-5cee-833b-df49d3d05cb6
Feed Name: TrustedSec blog
**Executive summary:** This technical post demonstrates multiple TTPs for abusing Active Directory account reset and credential recovery: how an account with reset/GenericWrite rights can be used to change a Domain Admin password, recover previous NT hashes (via Mimikatz, DSInternals, DRSUAPI/Impacket), restore hashes or bypass password history, and alternatively add Shadow Credentials (AddKeyCredentialLink) to obtain Kerberos TGTs and NT hashes; examples and commands are provided for both Windows and Linux tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
