Windows Active Direct domain account weak password detection method based on offline analysis
Obtain password hash snapshot files of Windows Active Directory domain account through offline analysis mode, and batch comparisons are combined with multi-core CPU and high IOPS SSD storage, solving the problems of low online detection efficiency and high compliance pressure, and achieving efficient and secure weak password detection, which is suitable for security audits of large enterprises and industrial control systems.
Patent Information
- Application Number
- CN202510304511.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-07-08
AI Technical Summary
When detecting weak passwords for Windows Active Directory domain accounts, the existing technology has problems such as inefficient online verification, network congestion, high risk of account locking, high cost and high compliance pressure, and cannot conduct batch blasting tests, affecting normal business.
Using offline analysis mode, the password hash snapshot file is obtained through the volume shadow copy service management tool, batch comparison is performed in an independent or securely isolated management server, hash parallel computing is performed using multi-core CPU and high IOPS SSD storage, and a custom weak password list and multi-threaded operation is used to generate an audit report.
It improves detection speed and efficiency, reduces security alarm and compliance pressure, does not trigger account locking, protects user privacy, and is suitable for compliance security audits and security inspections of large enterprises and industrial control systems.
Smart Images

Figure CN120281507A_ABST
Abstract
Description
Technical Field:
[0001] The present invention relates to a method for detecting weak passwords of Windows Active Directory domain accounts based on offline analysis. Background Art:
[0002] With the deepening of informatization and the expansion of the scale of enterprise organizations, Windows Active Directory undertakes the core function of user authentication for most enterprises and industrial control systems. Enterprises usually uniformly manage a large number of employee accounts and passwords in a domain environment. The domain password policy provided by Windows mainly controls the password length and character complexity, but cannot build a more refined or dynamic "weak password blacklist" policy.
[0003] Traditional password detection methods often rely on online interfaces for batch attempts. It is necessary to conduct online verification for each possible weak password and a large number of user accounts, which is likely to cause network congestion or performance degradation. If the password failure count limit mechanism is triggered, it will cause the account to be locked and affect subsequent normal operations. At the same time, the efficiency of online batch verification is relatively low. For hundreds or thousands of user accounts and a large-scale custom weak password list, the overall detection cost is extremely high, and batch brute-force testing cannot be performed, easily resulting in relevant audit problems. Summary of the Invention:
[0004] The embodiment of the present invention provides a method for detecting weak passwords of Windows Active Directory domain accounts based on offline analysis. The method is reasonably designed, directly performs batch comparison on NTLM hashes in an offline mode, improves the overall calculation speed and efficiency, reduces security alarms and compliance pressure, does not trigger account locking, and does not cause actual interference to the production system. It can list the weak password user IDs or user names in the final summary report. Even if the report is leaked, it will not directly expose the password plaintext. At the same time, it has little impact on the domain controller and network load, does not affect the normal authentication process and the operation of the business system, and further provides functions such as custom weak password list, multi-threaded or distributed computing, integrates into the security operation platform, realizes regular or real-time auditing, and can be applied to the compliance security auditing, password policy inspection and routine security detection of large enterprises and industrial control systems, solving the problems existing in the prior art.
[0005] The technical solution adopted by the present invention to solve the above technical problems is:
[0006] A method for detecting weak passwords of Windows Active Directory domain accounts based on offline analysis, the detection method comprising the following steps:
[0007] S1. Obtain a snapshot copy of the password hash snapshot file using the Volume Shadow Copy Service management tool on the Windows domain controller;
[0008] S2. Conduct an offline analysis and comparison of the environment in an independent or securely isolated management server;
[0009] S3. Load the weak password list into the system configuration interface and text file according to the enterprise characteristics and common weak passwords in the industry, enabling flexible expansion of the weak password list in the system configuration interface and text file;
[0010] S4. Read and parse the user information in the system and ntds files, extract the domain user NTLM hash values, and map them to the corresponding user names or user IDs;
[0011] S5. Calculate the NTLM hash values one by one for the weak password list and perform a quick match with the extracted domain user NTLM hash values;
[0012] S6. Mark the corresponding weak password hash value records for the user accounts with successful matches and generate an audit report.
[0013] Obtaining a snapshot copy of the password hash snapshot file using the Volume Shadow Copy Service management tool on the Windows domain controller includes the following steps:
[0014] S1.1. The domain controller sets a specific startup period to execute an automatic scheduling script, trigger the volume shadow copy, and create a password hash snapshot file for all user accounts in the domain controller;
[0015] S1.2. Copy the password hash snapshot file to a specified secure directory, and use the hash verification algorithm for specific sectors to verify the key files to ensure that no tampering or damage occurs during the copying process;
[0016] S1.3. After the data collection is completed, automatically unmount the volume shadow mount point and destroy the temporarily generated VSS snapshot file to prevent external unauthorized access;
[0017] S1.4. Perform advanced encryption algorithm processing before packing the password hash snapshot file, and use a secure external hard drive or encrypted network tunnel for transmission, so that the receiving end can obtain the password hash snapshot file after verifying the digital signature and file integrity.
[0018] Conducting an offline analysis and comparison of the environment in an independent or securely isolated management server includes the following steps:
[0019] S2.1. Configure the hardware information, including multi-core CPUs, high-frequency memory, and high-IOPS SSD storage, to meet the throughput requirements of large-scale password dictionaries and hash comparisons and perform hash parallel computing to meet the acceleration detection requirements;
[0020] S2.2. Analyze the environment in isolation from the production network, implement a whitelist policy for all access paths, and strictly restrict the inbound and outbound traffic.
[0021] S2.3. Set up hierarchical access permissions for security administrators and auditors.
[0022] The weak password list includes a core basic library, an enterprise custom module, and a statistical extension module. The core basic library is used to integrate common weak passwords released by the National Internet Emergency Center and multiple types of security databases. The enterprise custom module is used to dynamically add passwords according to industry characteristics or common internal enterprise vocabulary. The statistical extension module is used to analyze using the N-gram model to mine high-frequency combinations.
[0023] Loading the weak password list into the system configuration interface and text file according to the enterprise characteristics and common weak passwords in the industry includes the following steps:
[0024] S3.1. Import the weak password list.
[0025] S3.2. Parse the password hash snapshot file exported from the domain controller.
[0026] S3.3. Calculate the password hash snapshot file of the weak password list and perform a comparison.
[0027] Reading and parsing the user information in the system and ntds files, extracting the domain user NTLM hash value and mapping it to the corresponding username or user ID includes the following steps:
[0028] S4.1. Import the password hash snapshot file, parse the domain user information, and extract the NTLM hash of each account.
[0029] S4.2. Establish a mapping table from user ID to NTLM hash and a mapping table from username to attribute information.
[0030] S4.3. Generate NTLM hashes in a loop for the weak password list, use block calculation or multi-threaded queue for fast matching; if the match is successful, record "username + weak password mark + user ID" to the memory log for summary when generating the report later.
[0031] S4.4. Display the username corresponding to the weak password account in the report and match the weak password strength level.
[0032] Build a secondary password verification mechanism on the domain controller. When the administrator starts the collection process, a one-time token needs to be verified; after the snapshot is completed, a security audit report is automatically triggered.
[0033] Symmetric encryption is performed before the password hash snapshot file is transmitted and signed using a hardware private key; after decryption at the transmission terminal, the signature is verified, and the administrator loads the detection process after verification.
[0034] The present invention adopts the above structure and method, and provides a technical solution for obtaining and offline analyzing Windows AD domain account password hashes in an authorized environment, ensuring that the impact on the production system is controllable and the risks are traceable; by loading a weak password dictionary in an independent or securely isolated management platform and matching it with the domain account password hashes for detection, potential weak password users can be efficiently discovered; by not storing the user's plaintext password during the offline analysis process and only outputting a list or identifier of weak password accounts, the user privacy is maximally protected and the security compliance requirements are met, having the advantages of high security, high efficiency, and strong scalability. Description of the Drawings:
[0035] Figure 1 It is a flow diagram of the present invention. Detailed Embodiments:
[0036] To clearly illustrate the technical features of the present solution, the present invention will be elaborated in detail below through specific embodiments and in conjunction with its accompanying drawings.
[0037] As Figure 1 shown in
[0038] S1. Use the Volume Shadow Copy Service management tool on the Windows domain controller to obtain a snapshot copy of the password hash snapshot file;
[0039] S2. Perform offline analysis and comparison of the environment in an independent or securely isolated management server;
[0040] S3. Load the weak password list into the system configuration interface and text file according to the enterprise characteristics and common weak passwords in the industry, so that the weak password list can be flexibly extended in the system configuration interface and text file;
[0041] S4. Read and parse the user information in the system and ntds files, extract the NTLM hash values of domain users and map them to the corresponding user names or user IDs;
[0042] S5. Calculate the NTLM hash values one by one for the weak password list and perform a quick match with the extracted NTLM hash values of domain users;
[0043] S6. Mark the corresponding weak password hash value records for the user accounts with successful matches and generate an audit report.
[0044] Taking a snapshot copy of the password hash snapshot file using the Volume Shadow Copy Service management tool on a Windows domain controller includes the following steps:
[0045] S1.1, The domain controller sets a specific startup period to execute an automatic scheduling script, triggers the volume shadow copy, and creates a password hash snapshot file for all user accounts in the domain controller;
[0046] S1.2, Copy the password hash snapshot file to a specified secure directory, and use a hash verification algorithm for specific sectors to verify critical files to ensure that no tampering or damage occurs during the copying process;
[0047] S1.3, After the data collection is completed, automatically unmount the volume shadow mount point and destroy the temporarily generated VSS snapshot file to prevent external unauthorized access;
[0048] S1.4, Before packing the password hash snapshot file, perform advanced encryption algorithm processing, and use a secure removable hard drive or an encrypted network tunnel for transmission, so that the receiving end obtains the password hash snapshot file after verifying the digital signature and file integrity.
[0049] Performing offline analysis and comparison of the environment in a standalone or securely isolated management server includes the following steps:
[0050] S2.1, Configure the hardware information, including a multi-core CPU, high-frequency memory, and an SSD storage with high IOPS, to meet the throughput requirements of large-scale password dictionaries and hash comparisons and perform hash parallel computing to meet the acceleration detection requirements;
[0051] S2.2, Isolate from the production network for environment analysis, implement a whitelist policy for all access paths, and strictly restrict the inbound and outbound traffic;
[0052] S2.3, Set hierarchical access permissions for security administrators and auditors.
[0053] The weak password list includes a core basic library, an enterprise custom module, and a statistical extension module; the core basic library is used to integrate common weak passwords and various types of security databases released by the National Internet Emergency Center; the enterprise custom module is used to dynamically add passwords according to industry characteristics or common internal enterprise vocabulary; the statistical extension module is used to perform analysis using the N-gram model to mine high-frequency combinations.
[0054] Loading the weak password list into the system configuration interface and text file according to the enterprise characteristics and industry common weak passwords includes the following steps:
[0055] S3.1, Import the weak password list;
[0056] S3.2, Parse the password hash snapshot file exported from the domain controller;
[0057] S3.3. Calculate the password hash snapshot file of the weak password list and perform comparison.
[0058] Reading and parsing user information in system and ntds files, extracting NTLM hashes of domain users and mapping them to corresponding usernames or user IDs includes the following steps:
[0059] S4.1. Import the password hash snapshot file, parse domain user information, and extract the NTLM hash of each account.
[0060] S4.2. Establish a mapping table from user ID to NTLM hash and a mapping table from username to attribute information.
[0061] S4.3. Generate NTLM hashes in a loop for the weak password list, and use block calculation or multithreaded queue for fast matching; if the match is successful, record "username + weak password flag + user ID" to the memory log for summary when generating the report later.
[0062] S4.4. Display the username corresponding to the weak password account in the report and match the weak password strength level.
[0063] Build a secondary password verification mechanism in the domain controller. When the administrator starts the collection process, a one-time token needs to be verified; after the snapshot is completed, a security audit report is automatically triggered.
[0064] Perform symmetric encryption on the password hash snapshot file before transmission and sign it with a hardware private key; verify the signature after decryption at the transmission terminal, and the administrator loads the detection process after passing the verification.
[0065] The working principle of the method for detecting weak passwords of Windows Active Directory domain accounts based on offline analysis in the embodiments of the present invention is as follows: directly perform batch comparison on NTLM hashes in offline mode to improve the overall calculation speed and efficiency, reduce security alarms and compliance pressure, will not trigger account locks, and will not cause actual interference to the production system. It can list weak password user IDs or usernames in the finally summarized report, and even if the report is leaked, it will not directly expose the password in plain text; at the same time, it has little impact on the domain controller and network load, will not affect the normal authentication process and the operation of the business system, and then provides functions such as customizing the weak password list, multithreaded or distributed operations, integrating into the security operation platform, realizing regular or real-time auditing, and can be applied to compliance security audits, password policy checks and routine security detections of large enterprises and industrial control systems.
[0066] Compared with the traditional weak password detection method that relies on online verification interfaces, this application can directly perform batch comparison on NTLM hashes in an offline manner, and its calculation speed is much higher than online brute-forcing one by one, especially obvious for a large number of accounts and ultra-large weak password dictionaries. At the same time, it does not use online login attempts, avoiding the failure count limit of Windows domain accounts, reducing security alarms and compliance pressure, and also not bringing actual interference to the production system.
[0067] For security and privacy protection measures, the entire process does not require an online connection to the domain controller for password brute-force requests, nor will it leave security logs of password attempt failures or trigger SSO warnings in Windows AD. Only an offline snapshot needs to be obtained once, and secondary password verification or hardware security module authorization management can be performed for secure access to system permissions to prevent abuse.
[0068] The reports output after detection are strictly restricted to be viewed on the authorized security management console. All weak passwords do not appear in plain text, only presenting user identifiers and possible weak password categories. Statistical reports can be further refined for improving security policies.
[0069] In the overall solution, the detection method includes the following steps: Use the Volume Shadow Copy Service management tool on the Windows domain controller to obtain a snapshot copy of the password hash snapshot file; perform offline analysis and comparison of the environment in an independent or securely isolated management server; load the weak password list into the system configuration interface and text file according to enterprise characteristics and common weak passwords in the industry, enabling flexible expansion of the weak password list in the system configuration interface and text file; read and parse user information in the system and ntds files, extract the NTLM hash values of domain users and map them to the corresponding user names or user IDs; calculate the NTLM hash values one by one for the weak password list and quickly match them with the extracted NTLM hash values of domain users; mark the corresponding weak password hash value records for the user accounts with successful matches and generate an audit report.
[0070] The NTLM hash principle of this application is a challenge or response type verification protocol based on algorithms such as MD4 / Md5. In an offline environment, the plain text passwords in the weak password list are converted to NTLM hashes and compared with the ciphertext hash fields obtained from ntds. If the two are exactly the same, it is determined as a weak password account.
[0071] Furthermore, the application for large enterprise industrial control systems often involves tens of thousands or even hundreds of thousands of users. To balance speed and accuracy, multi-threaded segmented comparison can be adopted. For distributed deployment, if the computing pressure on a single machine is too high, the NTLM calculation and comparison process can be distributed to multiple nodes for parallel operation, and finally the calculation results are summarized.
[0072] For the weak password list, it includes the core basic library, enterprise custom module, and statistical extension module; the core basic library is used to integrate common weak passwords released by the National Internet Emergency Center and various types of security databases; the enterprise custom module is used to dynamically add passwords according to industry characteristics or common internal words of the enterprise; the statistical extension module is used to analyze and mine high-frequency combinations using the N-gram model; in the management of the weak password list, it supports customization, dynamic update, or intelligent expansion; it can also build a more practical dictionary based on the unique password habits of the enterprise to further discover weak passwords with industry or organizational characteristics.
[0073] Generally speaking, the first layer consists of extremely common ones such as "123456", "admin@123", etc.; the second layer is fuzzy deformations, such as "P@ssw0rd", "Qaz!2345"; the third layer is combinations customized by enterprises (such as enterprise name + year + symbol); calculate the NTLM hash offline and compare it with the user hash in the domain. If there is a match, it is identified as a weak password account.
[0074] In this application, the core mainly includes an NTLM hash generation module, a user hash parsing module, a comparison module, and a result output module. SIMD instructions or GPU parallelism can be used to calculate the NTLM hash in batches.
[0075] Further, loading the weak password list into the system configuration interface and text file according to the enterprise characteristics and common weak passwords in the industry includes the following steps: importing the weak password list; parsing the password hash snapshot file exported from the domain controller; calculating the password hash snapshot file of the weak password list and making comparisons.
[0076] Reading and parsing the user information in the system, ntds files, extracting the NTLM hash values of domain users and mapping them to the corresponding user names or user IDs includes the following steps: importing the password hash snapshot file, parsing the domain user information, and extracting the NTLM hash of each account; establishing a mapping table from user ID to NTLM hash and a mapping table from user name to attribute information; generating the NTLM hash in a loop in the weak password list and using block calculation or multi-threaded queue for fast matching; if the match is successful, record "user name + weak password mark + user ID" in the memory log and summarize it when generating the report later; display the user name corresponding to the weak password account in the report and match the weak password strength level.
[0077] Preferably, obtaining a snapshot copy of the password hash snapshot file using the Volume Shadow Copy Service management tool on a Windows domain controller includes the following steps: The domain controller sets a specific startup period to execute an automatic scheduling script, trigger the volume shadow copy, and create a snapshot file of the password hashes of all user accounts in the domain controller; copy the password hash snapshot file to a specified secure directory, and use a hash verification algorithm for specific sectors to verify critical files to ensure that no tampering or damage occurs during the copying process; after data collection is completed, automatically unmount the volume shadow mount point and destroy the temporarily generated VSS snapshot file to prevent unauthorized external access; perform advanced encryption algorithm processing before packaging the password hash snapshot file, and use a secure external hard drive or encrypted network tunnel for transmission, so that the receiving end can obtain the password hash snapshot file after verifying the digital signature and file integrity.
[0078] Generally speaking, the formats of the password hash snapshot files are system.hive and ntds.dit. The program starts at a specific period, which can reduce the impact on the production system; at the same time, the collection process will retain the collection logs for subsequent auditing and tracing of the collection process.
[0079] Preferably, performing offline analysis and comparison of the environment in an independent or securely isolated management server includes the following steps: Configure the hardware information, including multi-core CPUs, high-frequency memory, and high-IOPS SSD storage, to meet the throughput requirements of large-scale password dictionaries and hash comparisons and perform hash parallel computing to meet the acceleration detection requirements; isolate the environment from the production network for analysis, implement a whitelist policy for all access channels, and strictly restrict the incoming and outgoing traffic; set hierarchical access permissions for security administrators and auditors.
[0080] For the large-scale industrial and mining lamp enterprise scenario, the offline analysis server can be configured with multi-core CPUs, and at the same time equipped with high-frequency memory and high-IOPS SSD storage to meet the throughput requirements of large-scale password dictionaries and hash comparisons; in some implementations, GPUs can be used for NTLM hash parallel computing to further accelerate the detection.
[0081] Regarding the verification and hardware authorization process of this application, a secondary password verification mechanism is executed on the domain controller, which can verify one-time tokens, such as Yubikey, Google Auth, SMS verification codes, etc.; after the snapshot is completed, a security audit record is automatically triggered, including information such as the operation time and the executor's account.
[0082] For scenarios with higher security requirements, HSM or USB Key can be used to store the private keys and signature certificates required by the collection program, and the snapshot collection can only be started after the device is inserted and the Pin code is verified; and data privacy and anti-tampering are protected throughout the transmission medium or encrypted tunnel.
[0083] In summary, the weak password detection method for Windows Active Directory domain accounts based on offline analysis in the embodiments of the present invention directly performs batch comparison on NTLM hashes in an offline mode, improving the overall calculation speed and efficiency, reducing security alarms and compliance pressure, not triggering account locks, and not causing actual interference to the production system. It can list the weak password user IDs or user names in the final summary report, and even if the report is leaked, it will not directly expose the clear text of the password. At the same time, it has little impact on the domain controller and network load, does not affect the normal authentication process and the operation of the business system, and further provides functions such as customizing the weak password list, multi-threaded or distributed computing, integrating into the security operation platform, and realizing regular or real-time auditing. It can be applied to the compliance security auditing, password policy inspection, and routine security detection of large enterprises and industrial control systems.
[0084] The above specific implementation manners cannot be used as a limitation on the protection scope of the present invention. For those skilled in the art of this technology, any alternative improvement or transformation made to the embodiments of the present invention falls within the protection scope of the present invention.
[0085] Where the present invention is not described in detail, it is all well-known technology to those skilled in the art of this technology.
Claims
1. A method for detecting weak passwords of Windows Active Directory domain accounts based on offline analysis, characterized in that, The detection method includes the following steps: S1. Obtain a snapshot copy of the password hash snapshot file using the Volume Shadow Copy Service management tool on the Windows domain controller; S2. Conduct an offline analysis and comparison of the environment in an independent or securely isolated management server; S3. Load the weak password list into the system configuration interface and text file according to the enterprise characteristics and common weak passwords in the industry, enabling flexible expansion of the weak password list in the system configuration interface and text file; S4. Read and parse the user information in the system and ntds files, extract the domain user NTLM hash values, and map them to the corresponding user names or user IDs; S5. Calculate the NTLM hash values one by one for the weak password list and perform a quick match with the extracted domain user NTLM hash values; S6. Mark the corresponding weak password hash value records for the user accounts with successful matches and generate an audit report.
2. The method for detecting weak passwords of Windows Active Directory domain accounts based on offline analysis according to claim 1, wherein Obtaining a snapshot copy of the password hash snapshot file using the Volume Shadow Copy Service management tool on the Windows domain controller includes the following steps: S1.
1. The domain controller sets a specific startup period to execute an automatic scheduling script, trigger the volume shadow copy, and create a snapshot file of all user account passwords hashes in the domain controller; S1.
2. Copy the password hash snapshot file to a specified secure directory, and use a hash verification algorithm for specific sectors to verify the key files to ensure that no tampering or damage occurs during the copying process; S1.
3. After the data collection is completed, automatically unmount the volume shadow mount point and destroy the temporarily generated VSS snapshot file to prevent external unauthorized access; S1.
4. Perform advanced encryption algorithm processing on the password hash snapshot file before packaging, and use a secure external hard drive or encrypted network tunnel for transmission, so that the receiving end can obtain the password hash snapshot file after verifying the digital signature and file integrity.
3. A method for detecting weak passwords of Windows Active Directory domain accounts based on offline analysis according to claim 1, characterized in that, Conducting an offline analysis and comparison of the environment in an independent or securely isolated management server includes the following steps: S2.
1. Configure the hardware information, including multi-core CPUs, high-frequency memory, and high-IOPS SSD storage, to meet the throughput requirements of large-scale password dictionaries and hash comparisons and perform hash parallel computing to meet the acceleration detection requirements; S2.
2. Isolate from the production network for environment analysis, implement a whitelist policy for all access paths, and strictly restrict the inbound and outbound traffic; S2.
3. Set hierarchical access permissions for security administrators and auditors.
4. The method for detecting weak passwords of Windows Active Directory domain accounts based on offline analysis according to claim 1, wherein: The weak password list includes a core basic library, an enterprise custom module, and a statistical extension module; the core basic library is used to integrate common weak passwords released by the National Internet Emergency Center and various types of security databases; the enterprise custom module is used to dynamically add passwords according to industry characteristics or common internal enterprise vocabulary; the statistical extension module is used to perform analysis using the N-gram model to mine high-frequency combinations.
5. A method for detecting weak passwords of Windows Active Directory domain accounts based on offline analysis according to claim 1, characterized in that Loading the weak password list into the system configuration interface and text file according to the enterprise characteristics and common weak passwords in the industry includes the following steps: S3.
1. Import the weak password list; S3.
2. Parse the password hash snapshot file exported from the domain controller; S3.
3. Calculate the password hash snapshot file of the weak password list and perform a comparison.
6. The method for detecting weak passwords of Windows Active Directory domain accounts based on offline analysis according to claim 5, characterized in that Read and parse user information in the system and ntds files, extract the NTLM hashes of domain users and map them to the corresponding user names or user IDs, including the following steps: S4.1, Import the password hash snapshot file, parse the domain user information, and extract the NTLM hash of each account; S4.2, Establish a mapping table from user ID to NTLM hash, and establish a mapping table from user name to attribute information; S4.3, Generate NTLM hashes in a loop in the weak password list, and use block calculation or multithreaded queue for fast matching; if the match is successful, record "user name + weak password flag + user ID" in the memory log and summarize it when generating the report later; S4.4, Display the user names corresponding to the weak password accounts in the report and match the weak password strength levels.
7. A method for detecting weak passwords of Windows Active Directory domain accounts based on offline analysis according to claim 1, characterized in that: Build a secondary password verification mechanism on the domain controller. When the administrator starts the collection process, a one-time token needs to be verified; After completing the snapshot, automatically trigger a security audit report.
8. A method for detecting weak passwords of Windows Active Directory domain accounts based on offline analysis according to claim 1, characterized in that: Perform symmetric encryption on the password hash snapshot file before transmission and sign it with a hardware private key; verify the signature after decryption at the transmission terminal, and the administrator loads the detection process after passing the verification.
Citation Information
Patent Citations
Method and system for checking weak password of operating system
CN105184146A
Weak password rapid comparison and searching method
CN106411530A
Domain user weak password detection method based on hash collision
CN110633565A
Offline weak password checking method and device based on Hash matching
CN112948815A
Weak password detection method and device, electronic equipment and medium
CN116055067A