CTD-000098

AD Domain Controller with non-admin owner

Critical
Active Directory
Defense Evasion Persistence Privilege Escalation
v26

Signature Identity

CTD-000098
Threat ID
26
Version
IOC
Indicator Type

Threat Description

A threat actor who is an owner of Domain Controller computer accounts and who is not a member of Domain Admins, Enterprise Admins, or is not a built-in Administrator account could elevate their permissions.

MITRE ATT&CK: Attack Tactics

Defense Evasion Persistence Privilege Escalation

D3FEND: Defend Tactics

System Configuration Permissions

Remediation

To remove the owner of a computer object in Active Directory with Active Directory Users and Computers, follow these step-by-step instructions:

  1. Open Active Directory Users and Computers.
  2. Navigate to the Organizational Unit (OU) that contains the computer object you want to modify.
  3. Locate the computer object in the OU and right-click on it.
  4. Select Properties from the context menu.
  5. In the properties window, switch to the Security tab.
  6. Click on the Advanced button to access advanced security settings.
  7. In the advanced security settings window, select the Owner tab.
  8. Click on the Change button to change the owner of the computer object.
  9. Enter the name of the new owner in the text box or click on Advanced to search for a user or group.
  10. Click OK to save the changes and close all windows.

Frequently Asked Questions

What does AD Domain Controller with non-admin owner mean?

AD Domain Controller with non-admin owner refers to a situation where the owner of a Domain Controller computer account is not a member of the Domain Admins or Enterprise Admins group, nor is it a built-in Administrator account. This means that an individual who is not authorized for administrative privileges has control over the Domain Controller.

This condition allows attackers to gain elevated permissions by being added to sensitive groups, such as Domain Admins or Enterprise Admins. This can lead to unauthorized access and modification of security settings, supporting later attacker activity like reconnaissance and privilege escalation.

Attackers can exploit this situation by being added to sensitive groups, such as Domain Admins or Enterprise Admins, which would grant them elevated permissions. This could allow them to perform malicious actions, such as modifying security settings or accessing sensitive data.

Cayosoft Guardian detects AD Domain Controller with non-admin owner by continuously monitoring the group membership and ownership of computer accounts in Active Directory. When it identifies a situation where an unauthorized individual is part of sensitive groups, Guardian flags it as a security issue and alerts administrators to take corrective action.

Cayosoft Guardian helps reduce the risk by providing visibility into group membership and ownership, allowing administrators to review and correct these settings. This ensures that only authorized individuals have control over sensitive systems, reducing the potential for privilege escalation and unauthorized access.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection Privileged Access Management
Attack Tactics
Defense Evasion Persistence Privilege Escalation
Defend Tactics
System Configuration Permissions
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical