Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/M1027
MITRE ATT&CK Mitigation

M1027: Password Policies

ShareXLinkedInRedditHN

Set and enforce secure password policies for accounts to reduce the likelihood of unauthorized access. Strong password policies include enforcing password complexity, requiring regular password changes, and preventing password reuse. This mitigation can be implemented through the following measures: Windows Systems: - Use Group Policy Management Console (GPMC) to configure: - Minimum password length (e.g., 12+ characters). - Password complexity requirements. - Password history (e.g., disallow last 24 passwords). - Account lockout duration and thresholds. Linux Systems: - Configure Pluggable Authentication Modules (PAM): - Use `pam_pwquality` to enforce complexity and length requirements. - Implement `pam_tally2` or `pam_faillock` for account lockouts. - Use `pwunconv` to disable password reuse. Password Managers: - Enforce usage of enterprise password managers (e.g., Bitwarden, 1Password, LastPass) to generate and store strong passwords. Password Blacklisting: - Use tools like Have I Been Pwned password checks or NIST-based blacklist solutions to prevent users from setting compromised passwords. Regular Auditing: - Periodically audit password policies and account configurations to ensure compliance using tools like LAPS (Local Admin Password Solution) and vulnerability scanners. *Tools for Implementation* Windows: - Group Policy Management Console (GPMC): Enforce password policies. - Microsoft Local Administrator Password Solution (LAPS): Enforce random, unique admin passwords. Linux/macOS: - PAM Modules (pam_pwquality, pam_tally2, pam_faillock): Enforce password rules. - Lynis: Audit password policies and system configurations. Cross-Platform: - Password Managers (Bitwarden, 1Password, KeePass): Manage and enforce strong passwords. - Have I Been Pwned API: Prevent the use of breached passwords. - NIST SP 800-63B compliant tools: Enforce password guidelines and blacklisting.

▪Techniques addressed (47)

T1599.001Network Address Translation TraversalT1078.004Cloud AccountsT1556.005Reversible EncryptionT1552.002Credentials in RegistryT1550.003Pass the TicketT1552.004Private KeysT1558.002Silver TicketT1599Network Boundary BridgingT1003.003NTDST1558.003KerberoastingT1078Valid AccountsT1552Unsecured CredentialsT1110.004Credential StuffingT1110.002Password CrackingT1550Use Alternate Authentication MaterialT1187Forced AuthenticationT1003.006DCSyncT1556Modify Authentication ProcessT1003.002Security Account ManagerT1558.004AS-REP RoastingT1003.004LSA SecretsT1072Software Deployment ToolsT1003OS Credential DumpingT1003.005Cached Domain CredentialsT1078.003Local AccountsT1003.007Proc FilesystemT1003.008/etc/passwd and /etc/shadowT1078.001Default AccountsT1601Modify System ImageT1110.001Password GuessingT1555.001KeychainT1563.001SSH HijackingT1563Remote Service Session HijackingT1078.002Domain AccountsT1555Credentials from Password StoresT1110.003Password SprayingT1558Steal or Forge Kerberos TicketsT1110Brute ForceT1555.003Credentials from Web BrowsersT1601.002Downgrade System ImageT1201Password Policy DiscoveryT1021Remote ServicesT1555.005Password ManagersT1021.002SMB/Windows Admin SharesT1003.001LSASS MemoryT1552.001Credentials In FilesT1601.001Patch System Image

▪Reference

M1027on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.