STORAGE AND PROTECTION OF DOMAIN ACCOUNTS IN WINDOWS OPERATING SYSTEMS: PASSWORD EXTRACTION TOOLS
Abstract
The article examines the storage and protection of domain accounts in a Windows Server 2019 Active Directory infrastructure. The relevance of the study is determined by the fact that domain credentials remain one of the primary targets in attacks against corporate networks: once such data is compromised, an attacker may escalate privileges, maintain persistence, and gain access to critical resources. The purpose of the work is to assess, in practice, the risks associated with extracting authentication data and to analyze the effectiveness of basic protective measures. The study considers the mechanisms for storing secrets in the LSASS process and in the NTDS.dit database, and includes a controlled laboratory experiment using the Mimikatz utility. The results are compared for a weak password, a cryptographically stronger password, and a configuration with LSA Protection enabled. It is shown that a strong password reduces the probability of rapid password recovery from a hash, but it does not eliminate the possibility of offline cracking and does not prevent the leakage of the hash itself. The most significant result is the confirmation that domain infrastructure protection requires an integrated approach: enabling LSA Protection and Credential Guard, using the Protected Users group, enforcing strict privilege separation, and applying a tiered administration model. The findings may be used in educational laboratories and in the development of organizational and technical measures for protecting Windows domain infrastructures.
Online viewer
References
- Success with Enterprise Mobility + Identity [Электронный ресурс] : блог-пост // Microsoft Security Blog. Microsoft Tech Community. — 2016. — URL: https://techcommunity.microsoft.com/blog/microsoft-security-blog/success-with-enterprise-mobility-identity/248613 (дата обращения: 31.12.2025).
- Active Directory under siege: Why traditional hardening isn’t enough [Электронный ресурс] // The Hacker News. — 2025. — URL: https://thehackernews.com/2025/11/active-directory-under-siege-why.html (дата обращения: 31.12.2025).
- Хакер, С. Mimikatz — легенда хакерских инструментов: как работает, зачем нужен и почему его боятся все админы [Электронный ресурс] / С. Хакер // SecurityLab. — 2024. — URL: https://www.securitylab.ru/blog/personal/SimlpeHacker/355268.php (дата обращения: 31.12.2025).
- Fazel, M. A. P. Comprehensive Mimikatz Ebook: A Practical Guide to Post-Exploitation / M. A. P. Fazel, M. Rashidi // SSRN Electronic Journal. — 2025. — DOI: 10.2139/ssrn.5190361.
- How It Works (Credential Guard) [Электронный ресурс] // Microsoft Learn. — URL: https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/how-it-works (дата обращения: 31.12.2025).
- Why You Should Enable LSA Protection [Электронный ресурс] // Lepide. — 2023. — URL: https://www.lepide.com/blog/why-you-should-enable-lsa-protection/ (дата обращения: 31.12.2025).
- Protected Users Security Group [Электронный ресурс] // Microsoft Learn. — URL: https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/protected-users-security-group (дата обращения: 31.12.2025).
- Binduf, H. O. Active Directory and Related Aspects of Security / H. O. Binduf, H. Alamoudi, S. Balahmar, H. Alshamrani, H. Al-Omar, N. Nagy // 2018 21st Saudi Computer Society National Computer Conference (NCC). — Riyadh, 2018. — P. 4474–4479. — DOI: 10.1109/NCG.2018.8593188.
- Ebad, S. A. Lessons learned from offline assessment of security-critical systems: the case of Microsoft’s Active Directory / S. A. Ebad // International Journal of System Assurance Engineering and Management. — 2022. — Vol. 13. — P. 535–545. — DOI: 10.1007/s13198-021-01236-2.
- Grillenmeier, G. Protecting Active Directory against modern threats / G. Grillenmeier // Network Security. — 2021. — Vol. 2021, iss. 11. — P. 15–17. — DOI: 10.1016/S1353-4858(21)00132-X.
- Kumar, C. Active Directory and Its Security Testing / C. Kumar, S. S. Debnath, A. Kar, P. Debbarma, S. Piramanayagam // Proceedings of International Conference on Advanced Communications and Machine Intelligence. MICA 2023. — Singapore : Springer, 2024. — DOI: 10.1007/978-981-97-6222-4_43.
- Tier model [Электронный ресурс] // Microsoft Learn. — URL: https://learn.microsoft.com/en-us/microsoft-identity-manager/pam/tier-model-for-partitioning-administrative-privileges (дата обращения: 31.12.2025).
- Reducing the Active Directory attack surface [Электронный ресурс] // Microsoft Learn. — URL: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/reducing-the-active-directory-attack-surface (дата обращения: 31.12.2025).
- T1558.001 Golden Ticket [Электронный ресурс] // MITRE ATT&CK. — URL: https://attack.mitre.org/techniques/T1558/001/ (дата обращения: 31.12.2025).
- Уймин, А. Г. Сетевое и системное администрирование. Демонстрационный экзамен КОД 1.1 : учебно-методическое пособие для СПО / А. Г. Уймин. — 3-е изд., стер. — Санкт-Петербург : Лань, 2022. — 480 с. — ISBN 978-5-8114-9255-8.
License
Copyright (c) 2025 R. A. Bogdanov , G. D. Gadadov (Authors)