AD password audit
Attackers don't hack in, they log in.
Credential-based attacks have cost businesses an estimated US$10 billion over the past five years, and compromised credentials are behind most intrusions — CISA's FY2022 Risk and Vulnerability Assessment analysis found valid accounts were used to gain initial access 54.3% of the time. NodeZero AD Password Audit offers a fast and effective method for uncovering gaps in your password policy and streamlining your remediation. Reveal user passwords in your Active Directory environment that are likely targets for credential stuffing, password spray, credential reuse, and password cracking attacks.

Why are password audits important?
Cyber threat actors commonly use valid accounts for initial access, lateral movement, and privilege escalation. CISA's Fiscal Year 2022 Risk and Vulnerability Assessment analysis finds valid accounts can be used to gain initial access 54.3% of the time, maintain persistence 56.1% of the time, and escalate privileges 42.9% of the time. CISA's conclusion is direct: to guard against the valid-accounts technique, organisations must implement strong password policies, such as phishing-resistant multi-factor authentication (MFA), and monitor access and network communication logs to detect abnormal access — swift identification of abnormalities can reduce the damage caused by a cyber intrusion. Poor password policies and lack of best-practice enforcement remain an issue in most organisations. In real-world tests, it is not uncommon for NodeZero to crack more than 50% of the passwords it tests as part of an initial audit, and to find hundreds of accounts sharing the same password. With NodeZero you can easily and regularly audit your organisation and receive prioritised guidance for your riskiest accounts; it rates accounts with easily guessable passwords as critical — the accounts most at risk from online attacks such as password spray and credential stuffing.

What Australian frameworks expect
That prescription maps directly onto Australian obligations: the Essential Eight maturity level 2–3 multi-factor authentication (MFA) controls and the credential-control obligations DISP suppliers carry. A password audit produces the evidence record needed to demonstrate them.
Blast radius impact
Credential reuse is a simple and common technique that attackers use to gain access to more valid accounts. NodeZero AD Password Audit compares all account passwords to see how similar they are to each other. It then determines the number of additional accounts that can be accessed from a particular compromised credential in a novel metric known as "blast radius." NodeZero assumes an attacker can simply take a compromised password, or a simple variation of it, and try it against other accounts. With the blast radius metric, you can defend against credential reuse attack techniques.

Remediation
A Fix Action Report is delivered with the results of your AD Password Audit. NodeZero provides risky accounts that require immediate attention in a prioritised list, guidance on how to improve your password policy in accordance with NIST standards, and output you can feed into other tools (like Splunk) to investigate attacker use of risky accounts in the past. You can also use your audit results to build a remediation workflow that takes specific actions — for example, increased monitoring of risky accounts or a phased reset of risky passwords.
Easy to get started
When setting up your AD Password Audit, you enter a single IP address, add a credential, and basic information about your company such as its name and domain name. With that information, NodeZero uses OSINT to add more context about your company — context that an attacker may be able to leverage to guess weak passwords. NodeZero uses your company domains to look up dark web data associated with your company. You can also supply any well-known weak terms used at your organisation in the "Weak Password Terms" input, and NodeZero will test those terms and their variations while cracking.
How the audit works
Breach-based cracking
Cracks passwords based on public breach data, open-source intelligence (OSINT) tied to your company, and any weak password terms that you provide. Crack methods include Worst 10,000, Breach Terms, Credential Stuffing, Credential Tweaking, Contextual Terms, Username Mutation, and Breached Password.
Risk ranking
Ranks all users audited by their risk level, which is a function of guessability, how the password was cracked, and password similarity. Accounts with easily guessable passwords are rated as critical.
Blast radius metric
Determines the number of additional accounts that can be accessed from a particular compromised credential — showing the true scope of credential reuse risk.
Prioritised remediation guidance
Provides a prioritised list of risky accounts along with detailed remediation guidance, including NIST standards for improving your password policy.
Audit your password exposure
Continually verify the effectiveness of your credential policies with NodeZero AD Password Audit, and run a fresh audit each time staff join or leave. Set up in minutes with a single IP address and credential.