Restricted Admin Mode was implemented in Windows 8.1 to prevent credentials from being exposed over RDP. While well-intended, this brought the ability to pass-the-hash to RDP.
This TTP uses RestricedAdmin to disable DisableRestrictedAdmin
To view this TTPs command, you must be logged in with a professional or enterprise license.
Deploy RestrictedAdmin and disable Restricted Admin mode
About PreludePrelude hardens an organization's defenses by continuously “asking” it questions through the form of safe cyberattacks. These attacks respond immediately to the latest vulnerabilities and cyber events, turning complex technical descriptions into deployable “questions”.Our mission is to increase the reach, frequency and usage of advanced security for all organizations.