This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Password Audit Cracking in AD: The Fun Part of Compliance

Download resources

About this session

Mathieu Saulnier, a longtime Active Directory specialist who describes himself as an independent security researcher, uses a running story about three fictional organizations to contrast compliance frameworks with real password-cracking practice. YoloCorp follows only PCI and GDPR; CoolSec adds NIST 800-63B; EvilCats is the attacker. A LinkedIn-scraped password-spray attack instantly compromises YoloCorp but fails against CoolSec once MFA blocks it, and he cites Microsoft's figure that MFA stops 99.9% of credential-based attacks. He contrasts PCI's 12-character and GDPR's 8-character minimums, both crackable in minutes to hours, with NIST's 15-character, non-expiring rule, which only holds up because CoolSec pairs it with weekly self-cracking audits using DSInternals and hashcat against a copy of ntds.dit, forcing a reset on any password that cracks. He extends the same technique to Entra ID via AADInternals, then closes with concrete guidance: generated 64-character passwords in a password manager for anything never typed, and long passphrases 'dressed' with special characters front and back for anything that must be typed.

Key takeaways

  • Enable MFA on every internet-facing login; Microsoft attributes a 99.9% reduction in credential-based compromise to MFA versus password alone.
  • Treat compliance minimums (PCI's 12 characters, GDPR's 8) as a floor, not a target; both crack in minutes to hours against a standard wordlist and rule set.
  • Regularly audit your own Active Directory (and Entra ID) password hashes with tools like DSInternals and hashcat against a copy of ntds.dit, and force a reset on any password that cracks.
  • Build a company-specific banned-password list (brand names, local sports teams, city names) instead of relying only on generic denylists, which miss local and organizational context.
  • For passwords you must type, use a long passphrase 'dressed' with special characters at the start and end rather than predictable substitutions like changing O to 0, which crack instantly.

Speakers

Mathieu Saulnier
Mathieu Saulnier
Staff Program Manager · SpecterOps
Mathieu Saulnier is a cybersecurity leader with 20+ years in Threat Research, Detection Engineering, Threat Hunting, and Incident Response. He has led diverse, global teams to success and shared his expertise on stages at Derbycon, SANS Summits… Read moreRead less

Mathieu Saulnier is a cybersecurity leader with 20+ years in Threat Research, Detection Engineering, Threat Hunting, and Incident Response. He has led diverse, global teams to success and shared his expertise on stages at Derbycon, SANS Summits, RSAC, SecTor, and BSides worldwide. A dedicated community mentor with DEF CON’s Blue Team Village and co-organizer of NorthSec, DEATHcon and SkiCon, Mathieu now serves as Product Manager for BloodHound Community Edition, empowering attackers and defenders to audit and secure complex environments.

Resources

Tags

More from GoSec 2023

Also from Mathieu Saulnier

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.