Skip to content

Reset Password

Description

reset password module allows users to reset password of another identity in Entra ID. Resetting the password can allow access as the target entity leading to privilege escalation.

If a target identity's password is successfully reset, this module will store the new credentials for the identity to MAAD Credential Store for use in future.

Trigger

MAAD Attack Arsenal -> "Account" -> 5

MITRE ATT&CK Information

Tactic Technique
Defense Evasion Valid Accounts: Cloud Accounts
Persistence Valid Accounts: Cloud Accounts
Privilege Escalation Valid Accounts: Cloud Accounts
Initial Access Valid Accounts: Cloud Accounts

Additional Details

Microsoft services being accessed by this module:

External PowerShell module used: