Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-561 — Windows Admin Shares with Stolen Credentials
CAPEC-561

Windows Admin Shares with Stolen Credentials

TLP:CLEAR

Description

An adversary guesses or obtains (i.e. steals or purchases) legitimate Windows administrator credentials (e.g. userID/password) to access Windows Admin Shares on a local machine or within a Windows domain.

Mitigation

Do not reuse local administrator account credentials across systems. | Deny remote use of local admin credentials to log into domain systems. | Do not allow accounts to be a local administrator on more than one system.

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.