Diving into Pre-Created Computer Accounts
ID: a312a9d1-5fd3-5942-a962-9526a215dbcc
STIX ID: report--a312a9d1-5fd3-5942-a962-9526a215dbcc
Feed Name: TrustedSec blog
This post demonstrates a post-exploitation/privilege-escalation technique in Active Directory: enumerating pre-created (PASSWD_NOTREQD) computer accounts (UserAccountControl=4128), leveraging the predictable password behavior of pre-Windows-2000 accounts (computername in lowercase or blank), changing the account password via Kerberos or RPC, and abusing a vulnerable certificate template to gain further access. The author also describes tooling (Impacket scripts, kpasswd), practical detection gaps (BloodHound/SharpHound not graphing certain AllExtendedRights delegations), and cautions about resetting live computer account passwords.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
