We're preparing for a scenario quand one of le accounts in a domain gets compromised—what to do next?
Disabling le account would be mon premier go-to answer, mais we had pentesters here a peu de weeks ago et they were able to use hashed logins of an admin user who left a couple of months ago.
Our two answers so far are:
- Supprimez le account et recreate it (creates nouveau SID mais aussi more drama for le user et work for us)
- Changez le password at least 3 times et désactivez le account
What would votre method be, ou what would you recommend?
Que faire après la compromission d'un compte de domaine Windows ?
Re: Que faire après la compromission d'un compte de domaine Windows ?
>
they were able to use hashed logins of an admin user who left a couple of months ago.
Stolen credential hashes ne work for accounts that are disabled, sauf si it is on a computer that is pas connected to le network. The process encore needs to request a ticket ou authenticate avec a domain controller. Can't do that si le account is disabled.
Vous devez to disable administrative accounts for ex-employees quand they leave.
they were able to use hashed logins of an admin user who left a couple of months ago.
Stolen credential hashes ne work for accounts that are disabled, sauf si it is on a computer that is pas connected to le network. The process encore needs to request a ticket ou authenticate avec a domain controller. Can't do that si le account is disabled.
Vous devez to disable administrative accounts for ex-employees quand they leave.