netwrix / pingcastle

PingCastle - Get Active Directory Security at 80% in 20% of the time
https://www.pingcastle.com
Other
2.35k stars 292 forks source link

3.1.5.0 Beta issue with rule P-AdminLogin "Administrator account has been used recently" #207

Closed mpgn closed 10 months ago

mpgn commented 10 months ago

By testing the version 3.1.5.0 Beta a rule has been flagged on our domain which was not flagged on version 3.1.0.0:

The native administrator account has been used recently: 0 day(s) ago

image

Nevertheless, this account is no active on our side and not used since many years.

image

image

So maybe a regression from 3.1 :)

The version 3.1.0.0 does not report this rule.

RGAGPB commented 10 months ago

Hi, same problem for me in the latest beta (3.2 in the package name, 3.1.5 in the report), this rule keeps telling me my admin account has been used recently. I always had the problem because pingcastle was looking at lastlogontimestamp instead of lastlogon, I thought it was supposed to change with this version (the rule description talks about it btw) but I just checked and the lastlogon is indeed September 2021 on all my DCs, so there must still be a little problem 😬 Merci !

mpgn commented 10 months ago

Fixed on the new version 3.2.0.0 beta !