logo

A LAPS(e) in Judgement

ID: c9432bf5-0f42-5cec-b276-18e0571cc41d

STIX ID: report--c9432bf5-0f42-5cec-b276-18e0571cc41d

Feed Name: TrustedSec blog

Threat Score
60/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This blog explains how Microsoft LAPS can be abused to retrieve local Administrator passwords and provides step-by-step defensive guidance: enabling and enhancing Windows/LDAP logging, translating schema GUIDs for ms-Mcs-AdmPwd, and constructing Splunk SPL detections (using Event IDs 4662 and 4624, thresholding, and optional LDAP Event ID 1644) to identify LAPSDumper and CrackMapExec-based attacks; it also documents registry and GPO settings, example commands, and trade-offs for production tuning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.