Wide-Spread Local Admin Testing
ID: 1c22fca6-2104-57ff-b07a-bbb38a600caf
STIX ID: report--1c22fca6-2104-57ff-b07a-bbb38a600caf
Feed Name: Black Hills Infosec Blog
The report demonstrates a practical post-compromise technique for detecting wide-spread reuse of the local Windows Administrator password: enumerating hosts (net view) and attempting C$ access with a known Administrator credential to identify machines where that credential is valid. The author describes discovering a shared Administrator password documented on an internal SharePoint and using a modified password-spraying/net use loop to find nearly 200 machines where the credential worked, facilitating rapid lateral movement toward Domain Administrator access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
