CTD-000005

AD object with non-default permissions on AdminSDHolder

Critical
Active Directory
Defense Evasion Privilege Escalation
v28

Signature Identity

CTD-000005
Threat ID
28
Version
IOC
Indicator Type

Threat Description

A modification of the AdminSDHolder object might be an indication of threat actor activities. Active Directory is using AdminSDHolder object, protected groups and Security Descriptor propagator (SDPROP) as protection for privileged users and groups. When an Active Directory group is marked a protected group; Active Directory will ensure that the owner, the ACLs and the inheritance applied on this group are the same as the ones applied on AdminSDHolder container. The same is applied on the protected group members. Threat actors might modify AdminSDHolder object to propagate altered permissions to the protected objects.

MITRE ATT&CK: Attack Tactics

Defense Evasion Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening Domain Account Monitoring

Remediation

  1. Review recent changes of the AdminSDHolder object using Change History and undo unwanted changes.
  2. If changes were made before Cayosoft Guardian was installed, consider restoring default permissions.
  3. To restore default permissions of the AdminSDHolder object:
    1. Open ADSIEdit.
    2. Connect to the Default naming context.
    3. Select the AdminSDHolder container under CN=System.
    4. Click Properties.
    5. Switch to the Security tab.
    6. Click the Advanced button.
    7. Review the AdminSDHolder permissions.
    8. Remove unexpected permissions.

Frequently Asked Questions

What does AD object with non-default permissions on AdminSDHolder mean?

An Active Directory object has been granted permissions on the AdminSDHolder container that are not part of its default configuration. This can allow a threat actor to modify the permissions of protected groups and users, enabling them to gain elevated access and privileges within the domain.

This vulnerability allows attackers to propagate altered permissions to protected objects, effectively elevating their access and privileges within the domain. This can lead to significant security risks and potential compromise of sensitive data due to unauthorized changes to group membership and permission settings.

Attackers can use this access to modify the permissions of protected groups and users, enabling them to gain elevated access and privileges within the domain. This can be used to propagate malware, steal credentials, or perform other malicious activities by manipulating group membership and permission settings.

Cayosoft Guardian continuously monitors the permissions of Active Directory objects and identifies any deviations from their default configuration. When a non-standard permission is detected, Guardian flags it as a security issue so administrators can take corrective action.

Cayosoft Guardian alerts administrators to any non-standard permissions and provides visibility into changes made to the AdminSDHolder container. This enables teams to quickly identify and remediate any security issues, reducing the risk of compromise and data loss by ensuring that only authorized changes are made to group membership and permission settings.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
AD Delegation AdminSDHolder
Attack Tactics
Defense Evasion Privilege Escalation
Defend Tactics
Application Configuration Hardening Domain Account Monitoring
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical