[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fWDOhzxIhCTv9roiFPXqslcDtPMErTA-aAxvbvuBBh2I":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":52,"_status":50},123,"What detection methods can defenders use to identify password brute-force attacks on domain users?","Query the user attributes `badPwdCount` (number of bad password attempts) and `lastbadpasswordattempt` (time of last failed login). On a domain controller, use PowerShell: `Get-ADUser -Filter * -Properties * | select name,lastbadpasswordattempt,badpwdcount`. On a domain-joined host, use PowerView's `Get-NetUser | select name,badpasswordtime,badpwdcount` or a custom C++ tool using the NetUserGetInfo API. For more detection approaches, see the detection section in [Penetration Basics - Obtaining Domain User Password Policies](\u002Fnews\u002Fpenetration-basics-obtaining-domain-user-password-policies) and [Penetration Basics - Bypassing SSH Logs](\u002Fnews\u002Fpenetration-basics-bypassing-ssh-logs) for log evasion techniques.","\u003Cp>Query the user attributes `badPwdCount` (number of bad password attempts) and `lastbadpasswordattempt` (time of last failed login). On a domain controller, use PowerShell: `Get-ADUser -Filter * -Properties * | select name,lastbadpasswordattempt,badpwdcount`. On a domain-joined host, use PowerView&#39;s `Get-NetUser | select name,badpasswordtime,badpwdcount` or a custom C++ tool using the NetUserGetInfo API. For more detection approaches, see the detection section in [Penetration Basics - Obtaining Domain User Password Policies](\u002Fnews\u002Fpenetration-basics-obtaining-domain-user-password-policies) and [Penetration Basics - Bypassing SSH Logs](\u002Fnews\u002Fpenetration-basics-bypassing-ssh-logs) for log evasion techniques.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-obtaining-domain-user-password-policies\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-detection-methods-can-defenders-use-to-identify-password-brute-force-attack-1777484999465","detection, badPwdCount, password brute-force, powerview, active directory audit",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},32,"Penetration Basics - Obtaining Domain User Password Policies","penetration-basics-obtaining-domain-user-password-policies","Learn how to obtain domain user password policies for penetration testing and detect brute-force attacks. Includes external and internal methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In domain penetration, we need to obtain the password policies of domain users before password brute-forcing to avoid locking out users during the attack.\u003C\u002Fp>\u003Cp>From a defensive perspective, it is necessary to identify password brute-forcing attacks and implement defensive measures.\u003C\u002Fp>\u003Cp>This article will introduce common methods for obtaining domain user password policies, along with detection methods for domain user password brute-forcing attacks.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for modifying domain user password policies\u003C\u002Fli>\u003Cli>Methods for obtaining domain user password policies from outside the domain\u003C\u002Fli>\u003Cli>Methods for obtaining domain user password policies from within the domain\u003C\u002Fli>\u003Cli>Detection methods\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basics\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>We need to focus on the following password policies:\u003C\u002Fp>\u003Cul>\u003Cli>Maximum password age, indicating the expiration time of passwords, default is 42\u003C\u002Fli>\u003Cli>Minimum password length, indicating the minimum length of passwords, default is 7\u003C\u002Fli>\u003Cli>Account lockout duration, indicating the number of minutes a locked account remains locked before being automatically unlocked, default is 30\u003C\u002Fli>\u003Cli>Account lockout threshold, indicating the number of failed login attempts that cause a user account to be locked, default is 5\u003C\u002Fli>\u003Cli>Reset account lockout counter after, indicating the number of minutes that must elapse after a failed login attempt before the failed login attempt counter is reset to 0, default is 30\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Method to modify domain user password policy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The domain user password policy is by default stored in the Default Domain Policy within the domain, with GUID {31B2F340-016D-11D2-945F-00C04FB984F9}\u003C\u002Fp>\u003Cp>Open Group Policy Management on the domain controller, locate the current domain, select Default Domain Policy, right-click and choose Edit, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019807633_0_7c652fe763.jpeg\">\u003C\u002Fp>\u003Cp>Navigate sequentially through Computer Configuration-&gt;Policies-&gt;Windows Settings-&gt;Security Settings-&gt;Account Policies, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019821338_1_983cb4b4c0.jpeg\">\u003C\u002Fp>\u003Cp>Modify the corresponding options as prompted\u003C\u002Fp>\u003Cp>After modification, you can choose to update the group policy immediately to make it effective, enter the command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gpupdate\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Methods for Obtaining Domain User Password Policies from Outside the Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using ldapsearch on Kali System to Obtain Domain User Password Policies\u003C\u002Fh3>\u003Cp>Test environment as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019831296_2_0f6f3f1c67.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 of the Domain Controller (DC) and have obtained the password of at least one ordinary domain user\u003C\u002Fp>\u003Cp>In this test environment, we have obtained the password for the ordinary domain user testa: DomainUser123!\u003C\u002Fp>\u003Cp>Connection command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" | grep replUpToDateVector -A 13\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cp>-x Perform simple authentication\u003C\u002Fp>\u003Cp>-H Server address\u003C\u002Fp>\u003Cp>-D DN used to bind to the server\u003C\u002Fp>\u003Cp>-w Password for binding DN\u003C\u002Fp>\u003Cp>-b specifies the root node to query\u003C\u002Fp>\u003Cp>Use the grep command to filter the output results; grep replUpToDateVector -A 13 is to display only items related to password policy\u003C\u002Fp>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019841832_3_6039e11ca8.jpeg\">\u003C\u002Fp>\u003Cp>Includes the following required information:\u003C\u002Fp>\u003Cul>\u003Cli>maxPwdAge: -36288000000000\u003C\u002Fli>\u003Cli>minPwdLength: 10\u003C\u002Fli>\u003Cli>lockoutDuration: -18600000000\u003C\u002Fli>\u003Cli>lockoutThreshold: 15\u003C\u002Fli>\u003Cli>lockOutObservationWindow: -18600000000\u003C\u002Fli>\u003C\u002Ful>\u003Cp>To convert to seconds, divide by 10000000\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cp>(1) maxPwdAge: -36288000000000\u003C\u002Fp>\u003Cp>36288000000000\u002F10000000=3628800s\u003C\u002Fp>\u003Cp>3628800\u002F86400=42d\u003C\u002Fp>\u003Cp>maxPwdAge=42d\u003C\u002Fp>\u003Cp>(2)lockoutDuration: -18600000000\u003C\u002Fp>\u003Cp>-18600000000\u002F10000000=1860s\u003C\u002Fp>\u003Cp>1860\u002F60=31m\u003C\u002Fp>\u003Cp>lockoutDuration=31m\u003C\u002Fp>\u003Ch3>2. Retrieving Domain User Password Policy via PowerShell on Windows System\u003C\u002Fh3>\u003Cp>Test environment is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019861911_4_2f758f7e24.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 of the domain controller (DC), and we have obtained at least one regular domain user's password\u003C\u002Fp>\u003Cp>In this test environment, we obtained the password for the regular domain user testa as DomainUser123!\u003C\u002Fp>\u003Cp>The PowerShell module Active Directory is required here\u003C\u002Fp>\u003Cp>There is no need to specifically install the PowerShell module Active Directory; it can be resolved by calling Microsoft.ActiveDirectory.Management.dll\u003C\u002Fp>\u003Cp>Microsoft.ActiveDirectory.Management.dll is generated after installing the PowerShell module Active Directory. I have extracted it and uploaded it to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Additionally, credential information is required, so the complete PowerShell command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>Get-ADDefaultDomainPasswordPolicy -Server 192.168.1.1 -Credential $cred -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019867115_5_b74fd614b5.jpeg\">\u003C\u002Fp>\u003Ch3>3. Windows system obtains domain user password policy via domain shared files\u003C\u002Fh3>\u003Cp>The test environment is the same as above\u003C\u002Fp>\u003Cp>The domain user's password policy is stored in the default domain policy (Default Domain Policy) within the domain, with the guid {31B2F340-016D-11D2-945F-00C04FB984F9}\u003C\u002Fp>\u003Cp>It can be viewed by accessing the domain shared folder \\\\SYSVOL\u003C\u002Fp>\u003Cp>Prerequisite: Domain user credentials need to be provided\u003C\u002Fp>\u003Cp>In this test environment, we obtained the password for the domain ordinary user testa as DomainUser123!\u003C\u002Fp>\u003Cp>The general location is: \\\\\u003Cdomain controller=\"\" ip=\"\">\\SYSVOL\\\u003Cdomain>\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>The location in the test environment is: \\\\192.168.1.1\\SYSVOL\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fp>\u003Cp>The output result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019870628_6_06bb4407e5.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Methods for Obtaining Domain User Password Policies within a Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Prerequisite: Access to a host within the domain has been obtained\u003C\u002Fp>\u003Cp>The test environment is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019874887_7_3e8b5ad364.jpeg\">\u003C\u002Fp>\u003Ch3>1. Obtaining Domain User Password Policies via PowerShell\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>Get-ADDefaultDomainPasswordPolicy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtaining Domain User Password Policies via C++\u003C\u002Fh3>\u003Cp>Using the API NetUserModalsGet to retrieve domain user password policies\u003C\u002Fp>\u003Cp>Structure USER_MODALS_INFO_0 stores global password information\u003C\u002Fp>\u003Cp>Structure USER_MODALS_INFO_3 stores lockout information\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Flmaccess\u002Fnf-lmaccess-netusermodalsget?redirectedfrom=MSDN\u003C\u002Fp>\u003Cp>Based on the code in the reference materials, added functionality to query user lockout information. The code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code uses the structures USER_MODALS_INFO_0 and USER_MODALS_INFO_3 respectively to query user password policies\u003C\u002Fp>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019878349_8_69c5c60caa.jpeg\">\u003C\u002Fp>\u003Ch3>3. Obtain domain user password policies through domain shared files\u003C\u002Fh3>\u003Cp>The general location is: \\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>The test environment location is: \\\\test.com\\SYSVOL\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fp>\u003Ch2>0x06 Detection Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Domain user attributes include two useful pieces of information:\u003C\u002Fp>\u003Cul>\u003Cli>badPwdCount, which records the number of incorrect password attempts for the user\u003C\u002Fli>\u003Cli>lastbadpasswordattempt, which records the last login time when an incorrect password was entered\u003C\u002Fli>\u003C\u002Ful>\u003Cp>During detection, we can query these two attributes to identify whether a password brute-force attack has occurred. The specific method is as follows:\u003C\u002Fp>\u003Ch3>1. Query directly on the domain controller\u003C\u002Fh3>\u003Cp>Powershell code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-ADUser -Filter * -Properties *| select name,lastbadpasswordattempt,badpwdcount|fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019882020_9_6baa856eb5.jpeg\">\u003C\u002Fp>\u003Ch3>2. On a host logged in by a regular domain user\u003C\u002Fh3>\u003Ch4>(1) Using powerview\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-NetUser | select name,badpasswordtime,badpwdcount\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019885711_10_4e997ca8e1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Using C++\u003C\u002Fh4>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019888187_11_2675408436.jpeg\">\u003C\u002Fp>\u003Ch3>3. On a Kali system outside the domain\u003C\u002Fh3>\u003Ch4>(1) Using ldapsearch\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\"|grep -E \"cn:|badPwdCount|badPasswordTime\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019889716_12_56516cc380.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the password is entered correctly, then badPwdCount will be cleared\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article lists common methods for obtaining domain user password policies and describes how to identify password brute-force behavior in various environments.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In domain penetration, we need to obtain the password policies of domain users before password brute-forcing to avoid locking out users during the attack.\u003C\u002Fp>\u003Cp>From a defensive perspective, it is necessary to identify password brute-forcing attacks and implement defensive measures.\u003C\u002Fp>\u003Cp>This article will introduce common methods for obtaining domain user password policies, along with detection methods for domain user password brute-forcing attacks.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for modifying domain user password policies\u003C\u002Fli>\u003Cli>Methods for obtaining domain user password policies from outside the domain\u003C\u002Fli>\u003Cli>Methods for obtaining domain user password policies from within the domain\u003C\u002Fli>\u003Cli>Detection methods\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basics\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>We need to focus on the following password policies:\u003C\u002Fp>\u003Cul>\u003Cli>Maximum password age, indicating the expiration time of passwords, default is 42\u003C\u002Fli>\u003Cli>Minimum password length, indicating the minimum length of passwords, default is 7\u003C\u002Fli>\u003Cli>Account lockout duration, indicating the number of minutes a locked account remains locked before being automatically unlocked, default is 30\u003C\u002Fli>\u003Cli>Account lockout threshold, indicating the number of failed login attempts that cause a user account to be locked, default is 5\u003C\u002Fli>\u003Cli>Reset account lockout counter after, indicating the number of minutes that must elapse after a failed login attempt before the failed login attempt counter is reset to 0, default is 30\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Method to modify domain user password policy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The domain user password policy is by default stored in the Default Domain Policy within the domain, with GUID {31B2F340-016D-11D2-945F-00C04FB984F9}\u003C\u002Fp>\u003Cp>Open Group Policy Management on the domain controller, locate the current domain, select Default Domain Policy, right-click and choose Edit, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019807633_0_7c652fe763-1.jpeg\">\u003C\u002Fp>\u003Cp>Navigate sequentially through Computer Configuration-&gt;Policies-&gt;Windows Settings-&gt;Security Settings-&gt;Account Policies, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019821338_1_983cb4b4c0-1.jpeg\">\u003C\u002Fp>\u003Cp>Modify the corresponding options as prompted\u003C\u002Fp>\u003Cp>After modification, you can choose to update the group policy immediately to make it effective, enter the command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gpupdate\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Methods for Obtaining Domain User Password Policies from Outside the Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using ldapsearch on Kali System to Obtain Domain User Password Policies\u003C\u002Fh3>\u003Cp>Test environment as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019831296_2_0f6f3f1c67-1.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 of the Domain Controller (DC) and have obtained the password of at least one ordinary domain user\u003C\u002Fp>\u003Cp>In this test environment, we have obtained the password for the ordinary domain user testa: DomainUser123!\u003C\u002Fp>\u003Cp>Connection command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" | grep replUpToDateVector -A 13\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cp>-x Perform simple authentication\u003C\u002Fp>\u003Cp>-H Server address\u003C\u002Fp>\u003Cp>-D DN used to bind to the server\u003C\u002Fp>\u003Cp>-w Password for binding DN\u003C\u002Fp>\u003Cp>-b specifies the root node to query\u003C\u002Fp>\u003Cp>Use the grep command to filter the output results; grep replUpToDateVector -A 13 is to display only items related to password policy\u003C\u002Fp>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019841832_3_6039e11ca8-1.jpeg\">\u003C\u002Fp>\u003Cp>Includes the following required information:\u003C\u002Fp>\u003Cul>\u003Cli>maxPwdAge: -36288000000000\u003C\u002Fli>\u003Cli>minPwdLength: 10\u003C\u002Fli>\u003Cli>lockoutDuration: -18600000000\u003C\u002Fli>\u003Cli>lockoutThreshold: 15\u003C\u002Fli>\u003Cli>lockOutObservationWindow: -18600000000\u003C\u002Fli>\u003C\u002Ful>\u003Cp>To convert to seconds, divide by 10000000\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cp>(1) maxPwdAge: -36288000000000\u003C\u002Fp>\u003Cp>36288000000000\u002F10000000=3628800s\u003C\u002Fp>\u003Cp>3628800\u002F86400=42d\u003C\u002Fp>\u003Cp>maxPwdAge=42d\u003C\u002Fp>\u003Cp>(2)lockoutDuration: -18600000000\u003C\u002Fp>\u003Cp>-18600000000\u002F10000000=1860s\u003C\u002Fp>\u003Cp>1860\u002F60=31m\u003C\u002Fp>\u003Cp>lockoutDuration=31m\u003C\u002Fp>\u003Ch3>2. Retrieving Domain User Password Policy via PowerShell on Windows System\u003C\u002Fh3>\u003Cp>Test environment is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019861911_4_2f758f7e24-1.jpeg\">\u003C\u002Fp>\u003Cp>Prerequisite: We can access port 389 of the domain controller (DC), and we have obtained at least one regular domain user's password\u003C\u002Fp>\u003Cp>In this test environment, we obtained the password for the regular domain user testa as DomainUser123!\u003C\u002Fp>\u003Cp>The PowerShell module Active Directory is required here\u003C\u002Fp>\u003Cp>There is no need to specifically install the PowerShell module Active Directory; it can be resolved by calling Microsoft.ActiveDirectory.Management.dll\u003C\u002Fp>\u003Cp>Microsoft.ActiveDirectory.Management.dll is generated after installing the PowerShell module Active Directory. I have extracted it and uploaded it to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Additionally, credential information is required, so the complete PowerShell command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>Get-ADDefaultDomainPasswordPolicy -Server 192.168.1.1 -Credential $cred -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019867115_5_b74fd614b5-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Windows system obtains domain user password policy via domain shared files\u003C\u002Fh3>\u003Cp>The test environment is the same as above\u003C\u002Fp>\u003Cp>The domain user's password policy is stored in the default domain policy (Default Domain Policy) within the domain, with the guid {31B2F340-016D-11D2-945F-00C04FB984F9}\u003C\u002Fp>\u003Cp>It can be viewed by accessing the domain shared folder \\\\SYSVOL\u003C\u002Fp>\u003Cp>Prerequisite: Domain user credentials need to be provided\u003C\u002Fp>\u003Cp>In this test environment, we obtained the password for the domain ordinary user testa as DomainUser123!\u003C\u002Fp>\u003Cp>The general location is: \\\\\u003Cdomain controller=\"\" ip=\"\">\\SYSVOL\\\u003Cdomain>\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>The location in the test environment is: \\\\192.168.1.1\\SYSVOL\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fp>\u003Cp>The output result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019870628_6_06bb4407e5-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Methods for Obtaining Domain User Password Policies within a Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Prerequisite: Access to a host within the domain has been obtained\u003C\u002Fp>\u003Cp>The test environment is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019874887_7_3e8b5ad364-1.jpeg\">\u003C\u002Fp>\u003Ch3>1. Obtaining Domain User Password Policies via PowerShell\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>Get-ADDefaultDomainPasswordPolicy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtaining Domain User Password Policies via C++\u003C\u002Fh3>\u003Cp>Using the API NetUserModalsGet to retrieve domain user password policies\u003C\u002Fp>\u003Cp>Structure USER_MODALS_INFO_0 stores global password information\u003C\u002Fp>\u003Cp>Structure USER_MODALS_INFO_3 stores lockout information\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Flmaccess\u002Fnf-lmaccess-netusermodalsget?redirectedfrom=MSDN\u003C\u002Fp>\u003Cp>Based on the code in the reference materials, added functionality to query user lockout information. The code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code uses the structures USER_MODALS_INFO_0 and USER_MODALS_INFO_3 respectively to query user password policies\u003C\u002Fp>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019878349_8_69c5c60caa-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Obtain domain user password policies through domain shared files\u003C\u002Fh3>\u003Cp>The general location is: \\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>The test environment location is: \\\\test.com\\SYSVOL\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf\u003C\u002Fp>\u003Ch2>0x06 Detection Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Domain user attributes include two useful pieces of information:\u003C\u002Fp>\u003Cul>\u003Cli>badPwdCount, which records the number of incorrect password attempts for the user\u003C\u002Fli>\u003Cli>lastbadpasswordattempt, which records the last login time when an incorrect password was entered\u003C\u002Fli>\u003C\u002Ful>\u003Cp>During detection, we can query these two attributes to identify whether a password brute-force attack has occurred. The specific method is as follows:\u003C\u002Fp>\u003Ch3>1. Query directly on the domain controller\u003C\u002Fh3>\u003Cp>Powershell code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-ADUser -Filter * -Properties *| select name,lastbadpasswordattempt,badpwdcount|fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019882020_9_6baa856eb5-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. On a host logged in by a regular domain user\u003C\u002Fh3>\u003Ch4>(1) Using powerview\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-NetUser | select name,badpasswordtime,badpwdcount\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019885711_10_4e997ca8e1-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Using C++\u003C\u002Fh4>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019888187_11_2675408436-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. On a Kali system outside the domain\u003C\u002Fh3>\u003Ch4>(1) Using ldapsearch\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\"|grep -E \"cn:|badPwdCount|badPasswordTime\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019889716_12_56516cc380-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the password is entered correctly, then badPwdCount will be cleared\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article lists common methods for obtaining domain user password policies and describes how to identify password brute-force behavior in various environments.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1675,"Onedaysec",6,"published","2026-02-02T08:19:47.664Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Domain User Password Policies: Obtaining & Detection Methods","domain penetration, password policies, brute-force detection, Active Directory, ldapsearch, PowerShell",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],122,121,120,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.320Z","2026-07-23T16:01:02.118Z","draft","2026-07-23T16:03:49.822Z","2026-07-23T16:03:49.821Z"]