Skip to content
← LibraryTechnique entry
AD-LAPSCredential Access

Read LAPS Password

Read ms-Mcs-AdmPwd (or msLAPS-Password) on a computer object you have READ rights to.

§ Where this technique fits

AD-LAPS is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 3 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Windows Remote Management
    T1021.006 · Lateral Movement
    seen 1×