Accueil SSI audit Password audit

Password robustness audit

Test the robustness of your Active Directory passwords with statistical cryptanalysis.

“A single compromised corporate account (login and password) can lead to the compromise of an organization’s Information System.”
RetEx from SYNETIS teams during offensive audits.

The health of an Information System is very closely linked to the passwords it contains. Employee or service provider accounts, application accounts, service accounts, administration accounts… All these passwords are highly prized and targeted by external attackers, but also by malicious or careless internal actors.

Despite the presence of bastions, identity federation and strong authentication, what’s really going on in terms of hygiene and compliance with internal password policy? And what does a robust password policy really guarantee?

Judge the overall strength of passwords using statistical cryptanalysis

A password audit using statistical cryptanalysis enables you to assess the overall strength of your employees’ Active Directory passwords, as well as those of service or administration accounts. From this, we can deduce a potential compromise rate (proportion of weak passwords).


The aim is also to make users more aware of the weaknesses in their passwords, an essential lever in strengthening security levels.

Today, on average, Synetis breaks over 50% of passwords in less than 5 hours.

Discover the benefits of a password audit

A password audit, whether one-off or recurring (every 3 or 6 months), provides decision-makers with concrete statistics, indicators and metrics:

Rely on a rigorous, proven approach

Benefit from a full appraisal report

A statistical cryptanalysis mission gives rise to a report containing all the results and indicators generated. It includes a list of recommendations, best practices and an action plan:

  • By length, by domain, by models / patterns / masks, by algorithms ;
  • By complexity (standard, ANSSI, Active Directory compliance) ;
  • Top 100 most frequently used passwords and base words(blacklist);
  • Percentage of passwords leaked in the past (DarkWeb) ;
  • Evolution of cryptanalysis over time(timeline);
  • And many other metrics to monitor the health of the IS through the passwords used.

Examples of deliverables

Why Synetis?

  • An overall percentage of successful breakage close to 80% for all areas, customers and sectors combined;
  • Millions of passwords analyzed ;
  • On average, 50% of passwords are broken in less than 5 hours;
  • Concrete, comprehensive results within 2 weeks of analysis;
  • This service is carried out using standard equipment, without supercomputers, for greater realism.

Are your passwords really secure? Synetis’ statistical cryptanalysis audit reveals your vulnerabilities and gives you the keys to correcting them.

Are you planning an audit?
Pentest
Architecture
Configuration
Red Team
Social Engineering
Organizational and Physical
Source code

Incident response

CERT contact details

Mail: cert@synetis.com

Telephone: 02 30 21 31 04

USER ID : CERT SYNETIS

KEY ID : 2F6F A FE30 7877

PGP key fingerprint: 8D8ACAAC20557C7C1FF58332F6FA110FE307877

CERT Synetis is in the process of obtaining PRIS (Prestataires de Réponse aux Incidents de Sécurité) qualification from ANSSI (the French national agency for security incident response).

Incident response

CERT contact details

Mail: cert@synetis.com

Telephone: 02 30 21 31 04

USER ID : CERT SYNETIS

KEY ID : 2F6F A FE30 7877

PGP key fingerprint: 8D8ACAAC20557C7C1FF58332F6FA110FE307877

CERT Synetis is in the process of obtaining PRIS (Prestataires de Réponse aux Incidents de Sécurité) qualification from ANSSI (the French national agency for security incident response).

Contact our Audit team