CTD-000115

AD domain with Operator Groups that are not empty

Medium
Active Directory
Credential Access Privilege Escalation
v13

Signature Identity

CTD-000115
Threat ID
13
Version
IOE
Indicator Type

Threat Description

Account Operators, Server Operators, Backup Operators, Print Operators might have permissions to access resources in your environment. A threat actor could compromise accounts that are members of these groups in order to get access to critical data. Also, in many cases the member of such group can elevate their permission to Domain Admins.

MITRE ATT&CK: Attack Tactics

Credential Access Privilege Escalation

D3FEND: Defend Tactics

User Account Permissions

Remediation

To remove a group member in Active Directory using Active Directory Users and Computers (ADUC), follow these step-by-step instructions:
  1. Open ADUC.
  2. Expand the Domain node and navigate to the OU (Organizational Unit) containing the group from which you want to remove a member.
  3. Locate the group from which you want to remove the member and double-click on it to open its properties.
  4. Inside the group’s properties window, go to the Members tab.
  5. Find and Select the Member to remove.
  6. Once the member is selected, click the Remove or Remove from Group button (usually located near the member list).
  7. A confirmation dialog box will appear asking if you are sure you want to remove the member from the group. Click Yes to confirm.
  8. Check the member list to ensure the specific user has been removed from the group.

Frequently Asked Questions

What does AD domain with Operator Groups that are not empty mean?

An Active Directory (AD) domain has one or more built-in Operator Groups, such as Account Operators, Server Operators, Backup Operators, or Print Operators, with members in the environment. These groups often have permissions to access resources and can elevate their privileges to Domain Admins through group membership and permission inheritance.

This condition allows attackers to gain unauthorized access to sensitive data by compromising accounts in these groups, which can then be used for privilege escalation. The attacker's goal is to maintain persistence and reconnaissance capabilities within the environment.

Attackers can use compromised accounts in these groups to access sensitive data, exploit vulnerabilities, or engage in social engineering tactics. They can also escalate their privileges through group membership and permission inheritance, enabling them to move laterally within the environment.

Cayosoft Guardian continuously monitors group membership and permissions across the Active Directory environment to identify non-empty Operator Groups. When an Operator Group is found to have members, Guardian alerts administrators to review the group's access and privileges.

Cayosoft Guardian helps reduce the risk by providing visibility into group membership and permissions, allowing teams to remove unnecessary members from these groups. This limits the potential for attackers to gain unauthorized access to sensitive data through compromised accounts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Domain-wide
Attack Tactics
Credential Access Privilege Escalation
Defend Tactics
User Account Permissions
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical