BIOC Informational

Password policy discovery via command-line tool

Attackers may use chage to list the password policy and the user's last access time.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Discovery
Status:
Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Password Policy Discovery (T1201)
Indicator:

Process action type = execution AND target process cmd = *-l* AND target process name = chage

Preventable: yes