DrochaidHorizon3.ai
NodeZero/AD password audit
Autonomous pentesting

AD password audit

Attackers don't hack in, they log in.

Credential-based attacks have cost businesses an estimated US$10 billion over the past five years, and compromised credentials are behind most intrusions — CISA's FY2022 Risk and Vulnerability Assessment analysis found valid accounts were used to gain initial access 54.3% of the time. NodeZero AD Password Audit offers a fast and effective method for uncovering gaps in your password policy and streamlining your remediation. Reveal user passwords in your Active Directory environment that are likely targets for credential stuffing, password spray, credential reuse, and password cracking attacks.

54.3%
of the time, valid accounts were used to gain initial access
CISA FY2022 Risk and Vulnerability Assessment
NodeZero audited credentials and exposure summary
01

Why are password audits important?

Cyber threat actors commonly use valid accounts for initial access, lateral movement, and privilege escalation. CISA's Fiscal Year 2022 Risk and Vulnerability Assessment analysis finds valid accounts can be used to gain initial access 54.3% of the time, maintain persistence 56.1% of the time, and escalate privileges 42.9% of the time. CISA's conclusion is direct: to guard against the valid-accounts technique, organisations must implement strong password policies, such as phishing-resistant multi-factor authentication (MFA), and monitor access and network communication logs to detect abnormal access — swift identification of abnormalities can reduce the damage caused by a cyber intrusion. Poor password policies and lack of best-practice enforcement remain an issue in most organisations. In real-world tests, it is not uncommon for NodeZero to crack more than 50% of the passwords it tests as part of an initial audit, and to find hundreds of accounts sharing the same password. With NodeZero you can easily and regularly audit your organisation and receive prioritised guidance for your riskiest accounts; it rates accounts with easily guessable passwords as critical — the accounts most at risk from online attacks such as password spray and credential stuffing.

NodeZero AD password audit detail
In this example, NodeZero identified 30 users with cracked passwords and 18 users with similar passwords that should be updated, then prioritised the risk levels of the passwords examined.
02

What Australian frameworks expect

That prescription maps directly onto Australian obligations: the Essential Eight maturity level 2–3 multi-factor authentication (MFA) controls and the credential-control obligations DISP suppliers carry. A password audit produces the evidence record needed to demonstrate them.

03

Blast radius impact

Credential reuse is a simple and common technique that attackers use to gain access to more valid accounts. NodeZero AD Password Audit compares all account passwords to see how similar they are to each other. It then determines the number of additional accounts that can be accessed from a particular compromised credential in a novel metric known as "blast radius." NodeZero assumes an attacker can simply take a compromised password, or a simple variation of it, and try it against other accounts. With the blast radius metric, you can defend against credential reuse attack techniques.

NodeZero proof of the blast radius of audited credentials
This AD Password Audit proof shows a worst-case blast radius of 5 if this account is compromised.
04

Remediation

A Fix Action Report is delivered with the results of your AD Password Audit. NodeZero provides risky accounts that require immediate attention in a prioritised list, guidance on how to improve your password policy in accordance with NIST standards, and output you can feed into other tools (like Splunk) to investigate attacker use of risky accounts in the past. You can also use your audit results to build a remediation workflow that takes specific actions — for example, increased monitoring of risky accounts or a phased reset of risky passwords.

05

Easy to get started

When setting up your AD Password Audit, you enter a single IP address, add a credential, and basic information about your company such as its name and domain name. With that information, NodeZero uses OSINT to add more context about your company — context that an attacker may be able to leverage to guess weak passwords. NodeZero uses your company domains to look up dark web data associated with your company. You can also supply any well-known weak terms used at your organisation in the "Weak Password Terms" input, and NodeZero will test those terms and their variations while cracking.

What NodeZero reveals

How the audit works

A

Breach-based cracking

Cracks passwords based on public breach data, open-source intelligence (OSINT) tied to your company, and any weak password terms that you provide. Crack methods include Worst 10,000, Breach Terms, Credential Stuffing, Credential Tweaking, Contextual Terms, Username Mutation, and Breached Password.

B

Risk ranking

Ranks all users audited by their risk level, which is a function of guessability, how the password was cracked, and password similarity. Accounts with easily guessable passwords are rated as critical.

C

Blast radius metric

Determines the number of additional accounts that can be accessed from a particular compromised credential — showing the true scope of credential reuse risk.

D

Prioritised remediation guidance

Provides a prioritised list of risky accounts along with detailed remediation guidance, including NIST standards for improving your password policy.

Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Audit your password exposure

Continually verify the effectiveness of your credential policies with NodeZero AD Password Audit, and run a fresh audit each time staff join or leave. Set up in minutes with a single IP address and credential.