Finding: Weak Password Policy
ID: a44c016e-5828-5245-9132-163ff38cd644
STIX ID: report--a44c016e-5828-5245-9132-163ff38cd644
Feed Name: Black Hills Infosec Blog
This guidance explains risks from weak passwords—both easily guessed and easily cracked—and recommends shifting to long passphrases (minimum ~15 characters, multiple dictionary words, allowing title case and digit substitution), reducing opportunities for hash collection, and deploying mitigations such as MFA, Credential Guard, admin-only admin workstations, and password managers to limit credential theft and lateral compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
