1200KM / simulation
T1201 Password Policy Discovery — Attack Simulation
Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment. Password policies are a way to enforce complex passwords that are difficult to guess or crack through Brute Force. This information may help the adversary to create a list of common passwords and launch dictionary and/or brute force attacks which adheres to the policy (e.g. if the minimum password length should…
Technique description
Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment. Password policies are a way to enforce complex passwords that are difficult to guess or crack through Brute Force. This information may help the adversary to create a list of common passwords and launch dictionary and/or brute force attacks which adheres to the policy (e.g. if the minimum password length should…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Examine password complexity policy - Ubuntu
Procedure 085fe567-ac84-47c7-ac4c-2688ce28265b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Examine AWS Password Policy
Procedure 15330820-d405-450b-bd08-16b5be5be9f4; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Get-DomainPolicy with PowerView
Procedure 3177f4da-3d4b-4592-8bdc-aa23d0b2e843; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Examine local password policy - Windows
Procedure 4588d243-f24e-4549-b2e3-e627acc089f6; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Examine domain password policy - Windows
Procedure 46c2c362-2679-4ef5-aec9-0e958e135be4; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Examine password policy - macOS
Procedure 4b7fa042-9482-45e1-b348-4b756b2a0742; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Use of SecEdit.exe to export the local security policy (including the password policy)
Procedure 510cc97f-56ac-4cd3-a198-d3218c23d889; elevation required; cleanup not declared. Not executed or individually validated.
- Examine password complexity policy - CentOS/RHEL 6.x
Procedure 6ce12552-0adb-4f56-89ff-95ce268f6358; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Examine password complexity policy - CentOS/RHEL 7.x
Procedure 78a12e65-efff-4617-bc01-88f17d71315d; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Examine password expiration policy - All Linux
Procedure 7c86c55c-70fa-4a05-83c9-3aa19b145d1a; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Examine password complexity policy - FreeBSD
Procedure a7893624-a3d7-4aed-9676-80498f31820f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Enumerate Active Directory Password Policy with get-addefaultdomainpasswordpolicy
Procedure b2698b33-984c-4a1c-93bb-e4ba72a0babb; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.