logo

Manipulating User Passwords Without Mimikatz

ID: 37b71215-551e-5cee-833b-df49d3d05cb6

STIX ID: report--37b71215-551e-5cee-833b-df49d3d05cb6

Feed Name: TrustedSec blog

Threat Score
75/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

**Executive summary:** This technical post demonstrates multiple TTPs for abusing Active Directory account reset and credential recovery: how an account with reset/GenericWrite rights can be used to change a Domain Admin password, recover previous NT hashes (via Mimikatz, DSInternals, DRSUAPI/Impacket), restore hashes or bypass password history, and alternatively add Shadow Credentials (AddKeyCredentialLink) to obtain Kerberos TGTs and NT hashes; examples and commands are provided for both Windows and Linux tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.