Hiding in Active Directory

๐Ÿ”’ Secure Bits ๐Ÿ’ก
Did you know ๐˜†๐—ผ๐˜‚ ๐—ฐ๐—ฎ๐—ป ๐—ต๐—ถ๐—ฑ๐—ฒ ๐——๐—ผ๐—บ๐—ฎ๐—ถ๐—ป ๐—”๐—ฑ๐—บ๐—ถ๐—ป๐˜€ from standard discoveryโ€”even from other admins?

Active Directory is a โ€œ๐—ฟ๐—ฒ๐—ฎ๐—ฑ-๐—บ๐—ฎ๐—ป๐˜†โ€ ๐—ฑ๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† by design.
But ๐—Ÿ๐—ถ๐˜€๐˜ ๐—ข๐—ฏ๐—ท๐—ฒ๐—ฐ๐˜ ๐— ๐—ผ๐—ฑ๐—ฒ (๐—Ÿ๐—ข๐— ) can change that.
๐Ÿ•ต๏ธโ€โ™‚๏ธ Martin Handl shows how to leverage LOM to make Tier-0 accounts completely invisible to lower-tier admins.

๐Ÿ”งย ๐—›๐—ผ๐˜„ ๐—ถ๐˜ ๐˜„๐—ผ๐—ฟ๐—ธ๐˜€:
1๏ธโƒฃ ๐—˜๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ ๐—Ÿ๐—ถ๐˜€๐˜ ๐—ข๐—ฏ๐—ท๐—ฒ๐—ฐ๐˜ ๐— ๐—ผ๐—ฑ๐—ฒ (๐—Ÿ๐—ข๐— )
Set dSHeuristics=001 in ADโ€™s Configuration partition. No restart neededโ€”takes effect instantly across the forest.

2๏ธโƒฃ ๐—จ๐˜€๐—ฒ ๐˜€๐—ฝ๐—ฒ๐—ฐ๐—ถ๐—ฎ๐—น ๐—”๐—–๐—Ÿ ๐—ฐ๐—ผ๐—บ๐—ฏ๐—ถ๐—ป๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€:
On the parent OU: Deny List contents
On the Tier-0 object itself: Deny List object
Together, this hides the objectโ€”even if a user has read access on the directory.

3๏ธโƒฃ ๐—Ÿ๐—ฒ๐˜ ๐—”๐—ฑ๐—บ๐—ถ๐—ป๐—ฆ๐——๐—›๐—ผ๐—น๐—ฑ๐—ฒ๐—ฟ ๐—ฝ๐—ฟ๐—ผ๐—ฐ๐—ฒ๐˜€๐˜€ย ๐—ฑ๐—ผ ๐˜๐—ต๐—ฒ ๐˜„๐—ผ๐—ฟ๐—ธ:
Apply custom ACLs to the AdminSDHolder containerโ€”those propagate automatically to all protected Tier-0 accounts every hour.
Bonus: Martin provides a PowerShell script to apply/revert this across any OU.

๐Ÿ‘๏ธ ๐—ช๐—ต๐—ฎ๐˜โ€™๐˜€ ๐˜๐—ต๐—ฒ ๐—ฒ๐—ณ๐—ณ๐—ฒ๐—ฐ๐˜?
From the viewpoint of Tier-1 or Tier-2 users (like helpdesk or server admins), the hidden accounts donโ€™t exist.
No group listing, no LDAP enumeration, no PowerShell output.

๐Ÿ“Œ ๐—จ๐˜€๐—ฒ ๐—ฟ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ถ๐—ฏ๐—น๐˜†:
Hiding is not a replacement for proper security controls (Tiering, Security Baselines, LAPS, Role Separation, …, ). But it adds another layerโ€”obscurity that frustrates attackers and tools alike.

๐Ÿ“„ ๐—™๐˜‚๐—น๐—น ๐—ฝ๐—ผ๐˜€๐˜ + ๐—ฃ๐—ผ๐˜„๐—ฒ๐—ฟ๐—ฆ๐—ต๐—ฒ๐—น๐—น ๐˜€๐—ฐ๐—ฟ๐—ถ๐—ฝ๐˜ by Martin Handl: https://www.linkedin.com/feed/update/urn:li:activity:7353348333903482880/

๐—›๐—ถ๐—ฑ๐—ถ๐—ป๐—ด ๐—ฐ๐—ฎ๐—ป ๐—ฏ๐—ฒ ๐—ฎ๐—น๐˜€๐—ผ ๐˜‚๐˜€๐—ฒ๐—ฑ ๐—ฏ๐˜† ๐—ฎ๐—ป ๐—ฎ๐˜๐˜๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ฟ, are you sure nothing hides in your Active Directory? How do you search for something like that?
โœ… PS: I got you covered, ๐—”๐——๐—ฃ๐—ฟ๐—ผ๐—ฏ๐—ฒ can discover hidden accounts…