logo

Wide-Spread Local Admin Testing

ID: 1c22fca6-2104-57ff-b07a-bbb38a600caf

STIX ID: report--1c22fca6-2104-57ff-b07a-bbb38a600caf

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2016-06-13

Date Updated: 2026-04-27

Author: BHIS

...
...

The report demonstrates a practical post-compromise technique for detecting wide-spread reuse of the local Windows Administrator password: enumerating hosts (net view) and attempting C$ access with a known Administrator credential to identify machines where that credential is valid. The author describes discovering a shared Administrator password documented on an internal SharePoint and using a modified password-spraying/net use loop to find nearly 200 machines where the credential worked, facilitating rapid lateral movement toward Domain Administrator access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.