[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwSwEm365vE9zBK6hIRPg7bn14d7wS9tMf8XBk1thrtg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},121,"What are the key password policy attributes obtained from Active Directory, and how are their raw values converted to human-readable time?","Key attributes include maxPwdAge (maximum password age), minPwdLength (minimum password length), lockoutDuration (account lockout duration), lockoutThreshold (failed attempts before lockout), and lockOutObservationWindow (reset counter time). The raw values are in 100-nanosecond intervals; to convert to seconds, divide by 10,000,000. For example, maxPwdAge of -36288000000000 equals 3628800 seconds, or 42 days. Full conversion details are in the article [Penetration Basics - Obtaining Domain User Password Policies](\u002Fnews\u002Fpenetration-basics-obtaining-domain-user-password-policies).","\u003Cp>Key attributes include maxPwdAge (maximum password age), minPwdLength (minimum password length), lockoutDuration (account lockout duration), lockoutThreshold (failed attempts before lockout), and lockOutObservationWindow (reset counter time). The raw values are in 100-nanosecond intervals; to convert to seconds, divide by 10,000,000. For example, maxPwdAge of -36288000000000 equals 3628800 seconds, or 42 days. Full conversion details are in the article [Penetration Basics - Obtaining Domain User Password Policies](\u002Fnews\u002Fpenetration-basics-obtaining-domain-user-password-policies).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-obtaining-domain-user-password-policies\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-key-password-policy-attributes-obtained-from-active-directory-and-h-1777484999182","maxPwdAge, lockoutDuration, lockoutThreshold, password policy conversion, active directory",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},32,"Penetration Basics - Obtaining Domain User Password Policies","penetration-basics-obtaining-domain-user-password-policies","Learn how to obtain domain user password policies for penetration testing and detect brute-force attacks. Includes external and internal methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In domain penetration, we need to obtain the password policies of domain users before password brute-forcing to avoid locking out users during the attack.\u003C\u002Fp>\u003Cp>From a defensive perspective, it is necessary to identify password brute-forcing attacks and implement defensive measures.\u003C\u002Fp>\u003Cp>This article will introduce common methods for obtaining domain user password policies, along with detection methods for domain user password brute-forcing attacks.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for modifying domain user password policies\u003C\u002Fli>\u003Cli>Methods for obtaining domain user password policies from outside the domain\u003C\u002Fli>\u003Cli>Methods for obtaining domain user password policies from within the domain\u003C\u002Fli>\u003Cli>Detection methods\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basics\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>We need to focus on the following password policies:\u003C\u002Fp>\u003Cul>\u003Cli>Maximum password age, indicating the expiration time of passwords, default is 42\u003C\u002Fli>\u003Cli>Minimum password length, indicating the minimum length of passwords, default is 7\u003C\u002Fli>\u003Cli>Account lockout duration, indicating the number of minutes a locked account remains locked before being automatically unlocked, default is 30\u003C\u002Fli>\u003Cli>Account lockout threshold, indicating the number of failed login attempts that cause a user account to be locked, default is 5\u003C\u002Fli>\u003Cli>Reset account lockout counter after, indicating the number of minutes that must elapse after a failed login attempt before the failed login attempt counter is reset to 0, default is 30\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Method to modify domain user password policy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The domain user password policy is by default stored in the Default Domain Policy within the domain, with GUID {31B2F340-016D-11D2-945F-00C04FB984F9}\u003C\u002Fp>\u003Cp>Open Group Policy Management on the domain controller, locate the current domain, select Default Domain Policy, right-click and choose Edit, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019807633_0_7c652fe763.jpeg\">\u003C\u002Fp>\u003Cp>Navigate sequentially through Computer Configuration-&gt;Policies-&gt;Windows Settings-&gt;Security Settings-&gt;Account Policies, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019821338_1_983cb4b4c0.jpeg\">\u003C\u002Fp>\u003Cp>Modify the corresponding options as prompted\u003C\u002Fp>\u003Cp>After modification, you can choose to update the group policy immediately to make it effective, enter the command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gpupdate\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Methods for Obtaining Domain User Password Policies from Outside the Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using ldapsearch on Kali System to Obtain Domain User Password Policies\u003C\u002Fh3>\u003Cp>Test environment as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019831296_2_0f6f3f1c67.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 of the Domain Controller (DC) and have obtained the password of at least one ordinary domain user\u003C\u002Fp>\u003Cp>In this test environment, we have obtained the password for the ordinary domain user testa: DomainUser123!\u003C\u002Fp>\u003Cp>Connection command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" | grep replUpToDateVector -A 13\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cp>-x Perform simple authentication\u003C\u002Fp>\u003Cp>-H Server address\u003C\u002Fp>\u003Cp>-D DN used to bind to the server\u003C\u002Fp>\u003Cp>-w Password for binding DN\u003C\u002Fp>\u003Cp>-b specifies the root node to query\u003C\u002Fp>\u003Cp>Use the grep command to filter the output results; grep replUpToDateVector -A 13 is to display only items related to password policy\u003C\u002Fp>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019841832_3_6039e11ca8.jpeg\">\u003C\u002Fp>\u003Cp>Includes the following required information:\u003C\u002Fp>\u003Cul>\u003Cli>maxPwdAge: -36288000000000\u003C\u002Fli>\u003Cli>minPwdLength: 10\u003C\u002Fli>\u003Cli>lockoutDuration: -18600000000\u003C\u002Fli>\u003Cli>lockoutThreshold: 15\u003C\u002Fli>\u003Cli>lockOutObservationWindow: -18600000000\u003C\u002Fli>\u003C\u002Ful>\u003Cp>To convert to seconds, divide by 10000000\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cp>(1) maxPwdAge: -36288000000000\u003C\u002Fp>\u003Cp>36288000000000\u002F10000000=3628800s\u003C\u002Fp>\u003Cp>3628800\u002F86400=42d\u003C\u002Fp>\u003Cp>maxPwdAge=42d\u003C\u002Fp>\u003Cp>(2)lockoutDuration: -18600000000\u003C\u002Fp>\u003Cp>-18600000000\u002F10000000=1860s\u003C\u002Fp>\u003Cp>1860\u002F60=31m\u003C\u002Fp>\u003Cp>lockoutDuration=31m\u003C\u002Fp>\u003Ch3>2. Retrieving Domain User Password Policy via PowerShell on Windows System\u003C\u002Fh3>\u003Cp>Test environment is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019861911_4_2f758f7e24.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 of the domain controller (DC), and we have obtained at least one regular domain user's password\u003C\u002Fp>\u003Cp>In this test environment, we obtained the password for the regular domain user testa as DomainUser123!\u003C\u002Fp>\u003Cp>The PowerShell module Active Directory is required here\u003C\u002Fp>\u003Cp>There is no need to specifically install the PowerShell module Active Directory; it can be resolved by calling Microsoft.ActiveDirectory.Management.dll\u003C\u002Fp>\u003Cp>Microsoft.ActiveDirectory.Management.dll is generated after installing the PowerShell module Active Directory. I have extracted it and uploaded it to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Additionally, credential information is required, so the complete PowerShell command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>Get-ADDefaultDomainPasswordPolicy -Server 192.168.1.1 -Credential $cred -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019867115_5_b74fd614b5.jpeg\">\u003C\u002Fp>\u003Ch3>3. Windows system obtains domain user password policy via domain shared files\u003C\u002Fh3>\u003Cp>The test environment is the same as above\u003C\u002Fp>\u003Cp>The domain user's password policy is stored in the default domain policy (Default Domain Policy) within the domain, with the guid {31B2F340-016D-11D2-945F-00C04FB984F9}\u003C\u002Fp>\u003Cp>It can be viewed by accessing the domain shared folder \\\\SYSVOL\u003C\u002Fp>\u003Cp>Prerequisite: Domain user credentials need to be provided\u003C\u002Fp>\u003Cp>In this test environment, we obtained the password for the domain ordinary user testa as DomainUser123!\u003C\u002Fp>\u003Cp>The general location is: \\\\\u003Cdomain controller=\"\" ip=\"\">\\SYSVOL\\\u003Cdomain>\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>The location in the test environment is: \\\\192.168.1.1\\SYSVOL\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fp>\u003Cp>The output result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019870628_6_06bb4407e5.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Methods for Obtaining Domain User Password Policies within a Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Prerequisite: Access to a host within the domain has been obtained\u003C\u002Fp>\u003Cp>The test environment is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019874887_7_3e8b5ad364.jpeg\">\u003C\u002Fp>\u003Ch3>1. Obtaining Domain User Password Policies via PowerShell\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>Get-ADDefaultDomainPasswordPolicy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtaining Domain User Password Policies via C++\u003C\u002Fh3>\u003Cp>Using the API NetUserModalsGet to retrieve domain user password policies\u003C\u002Fp>\u003Cp>Structure USER_MODALS_INFO_0 stores global password information\u003C\u002Fp>\u003Cp>Structure USER_MODALS_INFO_3 stores lockout information\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Flmaccess\u002Fnf-lmaccess-netusermodalsget?redirectedfrom=MSDN\u003C\u002Fp>\u003Cp>Based on the code in the reference materials, added functionality to query user lockout information. The code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code uses the structures USER_MODALS_INFO_0 and USER_MODALS_INFO_3 respectively to query user password policies\u003C\u002Fp>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019878349_8_69c5c60caa.jpeg\">\u003C\u002Fp>\u003Ch3>3. Obtain domain user password policies through domain shared files\u003C\u002Fh3>\u003Cp>The general location is: \\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>The test environment location is: \\\\test.com\\SYSVOL\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fp>\u003Ch2>0x06 Detection Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Domain user attributes include two useful pieces of information:\u003C\u002Fp>\u003Cul>\u003Cli>badPwdCount, which records the number of incorrect password attempts for the user\u003C\u002Fli>\u003Cli>lastbadpasswordattempt, which records the last login time when an incorrect password was entered\u003C\u002Fli>\u003C\u002Ful>\u003Cp>During detection, we can query these two attributes to identify whether a password brute-force attack has occurred. The specific method is as follows:\u003C\u002Fp>\u003Ch3>1. Query directly on the domain controller\u003C\u002Fh3>\u003Cp>Powershell code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-ADUser -Filter * -Properties *| select name,lastbadpasswordattempt,badpwdcount|fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019882020_9_6baa856eb5.jpeg\">\u003C\u002Fp>\u003Ch3>2. On a host logged in by a regular domain user\u003C\u002Fh3>\u003Ch4>(1) Using powerview\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-NetUser | select name,badpasswordtime,badpwdcount\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019885711_10_4e997ca8e1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Using C++\u003C\u002Fh4>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019888187_11_2675408436.jpeg\">\u003C\u002Fp>\u003Ch3>3. On a Kali system outside the domain\u003C\u002Fh3>\u003Ch4>(1) Using ldapsearch\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\"|grep -E \"cn:|badPwdCount|badPasswordTime\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019889716_12_56516cc380.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the password is entered correctly, then badPwdCount will be cleared\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article lists common methods for obtaining domain user password policies and describes how to identify password brute-force behavior in various environments.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In domain penetration, we need to obtain the password policies of domain users before password brute-forcing to avoid locking out users during the attack.\u003C\u002Fp>\u003Cp>From a defensive perspective, it is necessary to identify password brute-forcing attacks and implement defensive measures.\u003C\u002Fp>\u003Cp>This article will introduce common methods for obtaining domain user password policies, along with detection methods for domain user password brute-forcing attacks.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for modifying domain user password policies\u003C\u002Fli>\u003Cli>Methods for obtaining domain user password policies from outside the domain\u003C\u002Fli>\u003Cli>Methods for obtaining domain user password policies from within the domain\u003C\u002Fli>\u003Cli>Detection methods\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basics\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>We need to focus on the following password policies:\u003C\u002Fp>\u003Cul>\u003Cli>Maximum password age, indicating the expiration time of passwords, default is 42\u003C\u002Fli>\u003Cli>Minimum password length, indicating the minimum length of passwords, default is 7\u003C\u002Fli>\u003Cli>Account lockout duration, indicating the number of minutes a locked account remains locked before being automatically unlocked, default is 30\u003C\u002Fli>\u003Cli>Account lockout threshold, indicating the number of failed login attempts that cause a user account to be locked, default is 5\u003C\u002Fli>\u003Cli>Reset account lockout counter after, indicating the number of minutes that must elapse after a failed login attempt before the failed login attempt counter is reset to 0, default is 30\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Method to modify domain user password policy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The domain user password policy is by default stored in the Default Domain Policy within the domain, with GUID {31B2F340-016D-11D2-945F-00C04FB984F9}\u003C\u002Fp>\u003Cp>Open Group Policy Management on the domain controller, locate the current domain, select Default Domain Policy, right-click and choose Edit, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019807633_0_7c652fe763-1.jpeg\">\u003C\u002Fp>\u003Cp>Navigate sequentially through Computer Configuration-&gt;Policies-&gt;Windows Settings-&gt;Security Settings-&gt;Account Policies, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019821338_1_983cb4b4c0-1.jpeg\">\u003C\u002Fp>\u003Cp>Modify the corresponding options as prompted\u003C\u002Fp>\u003Cp>After modification, you can choose to update the group policy immediately to make it effective, enter the command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gpupdate\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Methods for Obtaining Domain User Password Policies from Outside the Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using ldapsearch on Kali System to Obtain Domain User Password Policies\u003C\u002Fh3>\u003Cp>Test environment as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019831296_2_0f6f3f1c67-1.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 of the Domain Controller (DC) and have obtained the password of at least one ordinary domain user\u003C\u002Fp>\u003Cp>In this test environment, we have obtained the password for the ordinary domain user testa: DomainUser123!\u003C\u002Fp>\u003Cp>Connection command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" | grep replUpToDateVector -A 13\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cp>-x Perform simple authentication\u003C\u002Fp>\u003Cp>-H Server address\u003C\u002Fp>\u003Cp>-D DN used to bind to the server\u003C\u002Fp>\u003Cp>-w Password for binding DN\u003C\u002Fp>\u003Cp>-b specifies the root node to query\u003C\u002Fp>\u003Cp>Use the grep command to filter the output results; grep replUpToDateVector -A 13 is to display only items related to password policy\u003C\u002Fp>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019841832_3_6039e11ca8-1.jpeg\">\u003C\u002Fp>\u003Cp>Includes the following required information:\u003C\u002Fp>\u003Cul>\u003Cli>maxPwdAge: -36288000000000\u003C\u002Fli>\u003Cli>minPwdLength: 10\u003C\u002Fli>\u003Cli>lockoutDuration: -18600000000\u003C\u002Fli>\u003Cli>lockoutThreshold: 15\u003C\u002Fli>\u003Cli>lockOutObservationWindow: -18600000000\u003C\u002Fli>\u003C\u002Ful>\u003Cp>To convert to seconds, divide by 10000000\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cp>(1) maxPwdAge: -36288000000000\u003C\u002Fp>\u003Cp>36288000000000\u002F10000000=3628800s\u003C\u002Fp>\u003Cp>3628800\u002F86400=42d\u003C\u002Fp>\u003Cp>maxPwdAge=42d\u003C\u002Fp>\u003Cp>(2)lockoutDuration: -18600000000\u003C\u002Fp>\u003Cp>-18600000000\u002F10000000=1860s\u003C\u002Fp>\u003Cp>1860\u002F60=31m\u003C\u002Fp>\u003Cp>lockoutDuration=31m\u003C\u002Fp>\u003Ch3>2. Retrieving Domain User Password Policy via PowerShell on Windows System\u003C\u002Fh3>\u003Cp>Test environment is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019861911_4_2f758f7e24-1.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 of the domain controller (DC), and we have obtained at least one regular domain user's password\u003C\u002Fp>\u003Cp>In this test environment, we obtained the password for the regular domain user testa as DomainUser123!\u003C\u002Fp>\u003Cp>The PowerShell module Active Directory is required here\u003C\u002Fp>\u003Cp>There is no need to specifically install the PowerShell module Active Directory; it can be resolved by calling Microsoft.ActiveDirectory.Management.dll\u003C\u002Fp>\u003Cp>Microsoft.ActiveDirectory.Management.dll is generated after installing the PowerShell module Active Directory. I have extracted it and uploaded it to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Additionally, credential information is required, so the complete PowerShell command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>Get-ADDefaultDomainPasswordPolicy -Server 192.168.1.1 -Credential $cred -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019867115_5_b74fd614b5-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Windows system obtains domain user password policy via domain shared files\u003C\u002Fh3>\u003Cp>The test environment is the same as above\u003C\u002Fp>\u003Cp>The domain user's password policy is stored in the default domain policy (Default Domain Policy) within the domain, with the guid {31B2F340-016D-11D2-945F-00C04FB984F9}\u003C\u002Fp>\u003Cp>It can be viewed by accessing the domain shared folder \\\\SYSVOL\u003C\u002Fp>\u003Cp>Prerequisite: Domain user credentials need to be provided\u003C\u002Fp>\u003Cp>In this test environment, we obtained the password for the domain ordinary user testa as DomainUser123!\u003C\u002Fp>\u003Cp>The general location is: \\\\\u003Cdomain controller=\"\" ip=\"\">\\SYSVOL\\\u003Cdomain>\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>The location in the test environment is: \\\\192.168.1.1\\SYSVOL\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fp>\u003Cp>The output result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019870628_6_06bb4407e5-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Methods for Obtaining Domain User Password Policies within a Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Prerequisite: Access to a host within the domain has been obtained\u003C\u002Fp>\u003Cp>The test environment is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019874887_7_3e8b5ad364-1.jpeg\">\u003C\u002Fp>\u003Ch3>1. Obtaining Domain User Password Policies via PowerShell\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>Get-ADDefaultDomainPasswordPolicy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtaining Domain User Password Policies via C++\u003C\u002Fh3>\u003Cp>Using the API NetUserModalsGet to retrieve domain user password policies\u003C\u002Fp>\u003Cp>Structure USER_MODALS_INFO_0 stores global password information\u003C\u002Fp>\u003Cp>Structure USER_MODALS_INFO_3 stores lockout information\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Flmaccess\u002Fnf-lmaccess-netusermodalsget?redirectedfrom=MSDN\u003C\u002Fp>\u003Cp>Based on the code in the reference materials, added functionality to query user lockout information. The code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code uses the structures USER_MODALS_INFO_0 and USER_MODALS_INFO_3 respectively to query user password policies\u003C\u002Fp>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019878349_8_69c5c60caa-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Obtain domain user password policies through domain shared files\u003C\u002Fh3>\u003Cp>The general location is: \\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>The test environment location is: \\\\test.com\\SYSVOL\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fp>\u003Ch2>0x06 Detection Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Domain user attributes include two useful pieces of information:\u003C\u002Fp>\u003Cul>\u003Cli>badPwdCount, which records the number of incorrect password attempts for the user\u003C\u002Fli>\u003Cli>lastbadpasswordattempt, which records the last login time when an incorrect password was entered\u003C\u002Fli>\u003C\u002Ful>\u003Cp>During detection, we can query these two attributes to identify whether a password brute-force attack has occurred. The specific method is as follows:\u003C\u002Fp>\u003Ch3>1. Query directly on the domain controller\u003C\u002Fh3>\u003Cp>Powershell code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-ADUser -Filter * -Properties *| select name,lastbadpasswordattempt,badpwdcount|fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019882020_9_6baa856eb5-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. On a host logged in by a regular domain user\u003C\u002Fh3>\u003Ch4>(1) Using powerview\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-NetUser | select name,badpasswordtime,badpwdcount\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019885711_10_4e997ca8e1-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Using C++\u003C\u002Fh4>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019888187_11_2675408436-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. On a Kali system outside the domain\u003C\u002Fh3>\u003Ch4>(1) Using ldapsearch\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\"|grep -E \"cn:|badPwdCount|badPasswordTime\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019889716_12_56516cc380-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the password is entered correctly, then badPwdCount will be cleared\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article lists common methods for obtaining domain user password policies and describes how to identify password brute-force behavior in various environments.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1675,"Onedaysec",6,"published","2026-02-02T08:19:47.664Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Domain User Password Policies: Obtaining & Detection Methods","domain penetration, password policies, brute-force detection, Active Directory, ldapsearch, PowerShell",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],123,122,120,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.320Z","2026-07-23T16:01:02.118Z","draft","2026-07-23T16:03:48.257Z"]