A LAPS(e) in Judgement
ID: c9432bf5-0f42-5cec-b276-18e0571cc41d
STIX ID: report--c9432bf5-0f42-5cec-b276-18e0571cc41d
Feed Name: TrustedSec blog
This blog explains how Microsoft LAPS can be abused to retrieve local Administrator passwords and provides step-by-step defensive guidance: enabling and enhancing Windows/LDAP logging, translating schema GUIDs for ms-Mcs-AdmPwd, and constructing Splunk SPL detections (using Event IDs 4662 and 4624, thresholding, and optional LDAP Event ID 1644) to identify LAPSDumper and CrackMapExec-based attacks; it also documents registry and GPO settings, example commands, and trade-offs for production tuning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
