Issue
Devices not joined to Active Directory may not have Group Policies or other settings applied to enforce password complexity. For example, they may be managed by Okta, Datto RMM, and other tools. In this case, auditing for weak or blank passwords on local accounts can be challenging.
Solution
WeakPassword.ps1 (below) + your custom passwordlist.txt in the same directory will produce output with the lousy password if there’s a match on the local host. It’s also configured to test for blank passwords, which would immediately drop the user at the desktop:
Note
Update on 11/5/2025 - Note that this has slowed down slightly in Windows 11, doing ~1 password per second. It seemed like Windows 10 would cruise through this quickly, but the updated script remains functional in any case. One thing to keep in mind is that lockout policies must be temporarily disabled for this to work correctly. I could have, but didn’t add any detection for lockout or backoff mechanisms. I’m turning it on/off with ThreatLocker to do the audit.
A custom rule I had in my NGAV Firewall blocking inbound TCP/445 broke the script by displaying this error: Exception calling “Validate Credentials” with “2” arguement(s): The network path was not found. (Script location). I temporarily turned that off for long enough to let the script execute and promptly enabled the policy.
I haven’t included a password list right now. I’d recommend starting with the classic ‘password’, ‘letmein’, ‘123456’, and others, versus loading an entire dictionary. Although a large list doesn’t appear to slow the process down by much, it’s still extensible.
