Active Directory Persistence

๐Ÿ”’ Secure Bits ๐Ÿ’ก
Did you know you can ๐—ต๐—ถ๐—ฑ๐—ฒ ๐—ถ๐—ป ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜†โ€”๐—ฒ๐˜ƒ๐—ฒ๐—ป ๐—ณ๐—ฟ๐—ผ๐—บ ๐——๐—ผ๐—บ๐—ฎ๐—ถ๐—ป ๐—”๐—ฑ๐—บ๐—ถ๐—ป๐˜€?

Itโ€™s surprisingly easy to make an account nearly invisible, and most administrators wouldnโ€™t even notice. Hereโ€™s how:

1๏ธโƒฃ ๐— ๐—ฎ๐—ธ๐—ฒ ๐˜๐—ต๐—ฒ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜ ๐˜‚๐—ป๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต๐—ฎ๐—ฏ๐—น๐—ฒ
Apply a Deny Full Control ACL for “Everyone” on the target accountโ€”this prevents anyone from seeing or modifying it.

2๏ธโƒฃ ๐—ฃ๐—ฟ๐—ฒ๐˜ƒ๐—ฒ๐—ป๐˜ ๐—ด๐—ฟ๐—ผ๐˜‚๐—ฝ ๐—บ๐—ฒ๐—บ๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ต๐—ถ๐—ฝ ๐—ณ๐—ฟ๐—ผ๐—บ ๐—ฏ๐—ฒ๐—ถ๐—ป๐—ด ๐˜ƒ๐—ถ๐˜€๐—ถ๐—ฏ๐—น๐—ฒ
Even if an account is hidden, its group membership might still be exposed.
๐Ÿ‘‰ Use the Primary Group feature instead of traditional group memberships. Since the primary group is stored in the accountโ€™s attributes, it wonโ€™t show up in standard group lookupsโ€”if combined with Deny ACLs, it becomes almost invisible.

3๏ธโƒฃ ๐—›๐—ถ๐—ฑ๐—ฒ ๐˜๐—ต๐—ฒ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜ ๐—ถ๐—ป ๐˜‚๐—ป๐—ฒ๐˜…๐—ฝ๐—ฒ๐—ฐ๐˜๐—ฒ๐—ฑ ๐—น๐—ผ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€
Place it in a misleading Organizational Unit (OU), ideally one only visible in Advanced Mode. Apply Deny List Content ACLs on the final OU to obscure it further.

๐——๐—ผ๐—ฒ๐˜€ ๐—ถ๐˜ ๐—ฎ๐—น๐˜„๐—ฎ๐˜†๐˜€ ๐˜„๐—ผ๐—ฟ๐—ธ?
Not for officially privileged groupsโ€”AdminSDHolder protection kicks in for accounts in groups like Domain Admins (I wrote posts about this).

๐—–๐—ฎ๐—ป ๐—ถ๐˜ ๐˜€๐˜๐—ถ๐—น๐—น ๐—ฏ๐—ฒ ๐—ฑ๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ฒ๐—ฑ?
Yes, you should monitor for:
โœ” Primary group changes
โœ” Suspicious ACL modifications (especially Deny)
โœ” AD object-level changes (Event logs)

Also SAM-R protocol can be used for enumeration (depending on configuration).

๐Ÿ’ก ๐—ง๐—ต๐—ถ๐˜€ ๐—ถ๐˜€ ๐˜„๐—ต๐˜† ๐˜€๐—ฐ๐—ฎ๐—ป๐—ป๐—ถ๐—ป๐—ด ๐—”๐—— ๐—ฟ๐—ฒ๐—ด๐˜‚๐—น๐—ฎ๐—ฟ๐—น๐˜† ๐—ณ๐—ผ๐—ฟ ๐—บ๐—ถ๐˜€๐—ฐ๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐—ถ๐˜€ ๐—ฐ๐—ฟ๐˜‚๐—ฐ๐—ถ๐—ฎ๐—น. My AD Probe tool helps uncover hidden accounts like this:
https://horizon-secured.com/tools/

Have you checked your environment for this? Letโ€™s discuss ๐Ÿ‘‡