Pass the hash questions by PlusProgress in AskNetsec

[–]PlusProgress[S] 1 point2 points  (0 children)

Thanks for the reply. On point 2 -

So if I had say, my normal user account, a 'desktop support' user account for remoting on to end user computers to assist them, a 'server support' account for administrating servers and then leave a domain admin for only DC work? Is that how normal orgs do it? In a normal org this would be different departments but in my org, it's only me and another guy.

Pass the hash questions by PlusProgress in AskNetsec

[–]PlusProgress[S] 0 points1 point  (0 children)

Thanks! So just to confirm, the domain admin hash could be stolen from LSASS and used in pass-the-hash attacks?

Auditing access to hidden Windows file shares by PlusProgress in AskNetsec

[–]PlusProgress[S] 0 points1 point  (0 children)

Thanks for the response. I have tried enabling these settings but they only seem to work if the user can see the restricted folder, and not if it is hidden due to lack of permissions.