logo

Your Password Is… wait for it… NOT Always Encrypted

ID: e69d8d1c-f3ef-5080-bb5b-bde0e45c95e4

STIX ID: report--e69d8d1c-f3ef-5080-bb5b-bde0e45c95e4

Feed Name: Black Hills Infosec Blog

Date Published: 2016-01-15

Date Updated: 2026-04-27

Author: BHIS

...
...

**Executive Summary:** This blog post provides a practical overview of credential-harvesting techniques used during penetration tests, demonstrating tools (Mimikatz, LaZagne, WCE), methods (memory/lsass dumps, Meterpreter migration, in-memory PowerShell), and legacy weaknesses (Group Policy Preferences) that can expose plaintext passwords or hashes, and emphasizes simple mitigations such as enabling two-factor authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.