CTD-000036

Stale administrative account in AD domain

Medium
Active Directory
Credential Access Privilege Escalation
v96

Signature Identity

CTD-000036
Threat ID
96
Version
IOE
Indicator Type

Threat Description

Enabled administrative account that has not logged in during the specified period poses a threat to your Active Directory environment. Such an account could be used by a former employee or another threat actor. An unused administrative account increases the potential attack surface.

NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.

According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.

Note: If the ms-DS-Logon-Time-Sync-Interval Active Directory Schema attribute is greater than the Time Interval parameter defined in the threat rule, the accuracy of the threat rule results may be compromised. This discrepancy can lead to inaccurate detection outcomes, such as false positives or false negatives.

MITRE ATT&CK: Attack Tactics

Credential Access Privilege Escalation

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

To deprovision stale user account:
  1. Disable user’s account.
  2. Remove user from all groups to ensure that she doesn’t have access to organization’s resources.

Frequently Asked Questions

What does Stale administrative account in AD domain mean?

Stale administrative account in AD domain refers to an enabled administrative account that has not logged in during the specified period, potentially allowing unauthorized access.

The stale account's elevated privileges can be exploited for privilege escalation and credential access, providing a foothold for attackers to collect information and plan more serious intrusions. This is because the account's cached Kerberos ticket or credentials remain valid even after the account has been disabled.

Attackers can use a stale administrative account's Kerberos ticket or cached credentials to obtain unauthorized access to other resources, leveraging the account's elevated privileges. This allows them to escalate their privileges and move laterally within the network.

Cayosoft Guardian continuously monitors the state of administrative accounts across the Active Directory environment domain, flagging enabled accounts that have not logged in during the specified period as a security issue.

Cayosoft Guardian alerts administrators to disable and deprovision stale user accounts, ensuring unnecessary access points are closed and limiting reconnaissance opportunities for attackers. This helps prevent privilege escalation and reduces the attacker's ability to move laterally within the network.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access Privilege Escalation
Defend Tactics
Domain Account Monitoring
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical