Your Password Is… wait for it… NOT Always Encrypted
ID: e69d8d1c-f3ef-5080-bb5b-bde0e45c95e4
STIX ID: report--e69d8d1c-f3ef-5080-bb5b-bde0e45c95e4
Feed Name: Black Hills Infosec Blog
**Executive Summary:** This blog post provides a practical overview of credential-harvesting techniques used during penetration tests, demonstrating tools (Mimikatz, LaZagne, WCE), methods (memory/lsass dumps, Meterpreter migration, in-memory PowerShell), and legacy weaknesses (Group Policy Preferences) that can expose plaintext passwords or hashes, and emphasizes simple mitigations such as enabling two-factor authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
