Language:
Multiple problems can arise with Active Directory account passwords (insufficient complexity, obsolete cryptography, blank, reused, leaked...), leading to a decrease in Active Directory security by allowing "brute-force", "password spraying" and "lateral movement" attacks.
Good administrative practices for domain user passwords involve using strong and unique passwords, avoiding unchanged default values that relate to domain-authenticated accounts, and securely storing passwords with robust algorithms.
Name: Detection of Password Weaknesses
Codename: C-PASSWORD-HASHES-ANALYSIS
Severity: High
OpenWall: John the Ripper - A fast password cracker
Jens Steube, Gabriele Gristina: hashcat - advanced password recovery tool