A water utility Windows host stores autologon credentials in the registry. Why does privilege-escalation enumeration care about that?
Select an answer to reveal the explanation.
Short Explanation
Autologon in the registry is the sticky note on the monitor—credentials parked for convenience. Enumerators dig there because clear or recoverable secrets often fall out. It is about stored passwords, not screensaver timers or RDP being off.
Full Explanation
Windows autologon configuration historically places account material under well-known registry locations that low-privilege users may read depending on ACLs and storage form. Privilege-escalation and credential-harvest enumeration routinely checks these keys along with other secret stores. Autologon is not merely a timeout setting and does not by itself describe RDP enablement. Discovered credentials should be validated only within scope and documented with remediation guidance to remove cleartext autologon.