CTD-000004

AD object with non-default primary group

High
Active Directory
Defense Evasion Persistence Privilege Escalation
v98

Signature Identity

CTD-000004
Threat ID
98
Version
IOC
Indicator Type

Threat Description

A non-default Primary Group ID enables a stealth privilege escalation path in Active Directory that bypasses traditional group membership monitoring. By modifying the primaryGroupID attribute, an attacker can assign an account to a privileged group such as Domain Admins and inherit its permissions without appearing in group membership. This technique is commonly used for defense evasion, as it avoids detection by tools that monitor group changes, and for persistence, as the attacker can revert the value after use and reapply it later, leaving minimal audit trail.

MITRE ATT&CK: Attack Tactics

Defense Evasion Persistence Privilege Escalation

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

For users, set the primary group to Domain Users, for computers set the primary group to Domain Computers:
  1. Open Active Directory Users and Computers.
  2. Select user or computer object.
  3. Right-click on the object and select Properties.
  4. Open Member Of tab.
  5. Select a group to make it primary.
  6. Press the Set Primary Group button.

Frequently Asked Questions

What does AD object with non-default primary group mean?

An AD object has a non-default primary group when its Primary Group IDs (PGIDs) are set to a value other than the default, allowing it to inherit permissions from the corresponding group.

This condition enables an attacker to silently inherit elevated permissions and hide their persistence in Active Directory by manipulating group membership and permissions. Specifically, an attacker can exploit this vulnerability to gain Domain Admin privileges without being detected.

Attackers can use the inherited elevated permissions to perform malicious activities such as lateral movement, privilege escalation, and data exfiltration. Additionally, they can hide their persistence in the domain by manipulating group membership and permissions.

Cayosoft Guardian continuously monitors Active Directory for changes to Primary Group IDs (PGIDs) on user or computer accounts, flagging non-default PGIDs as security issues so administrators can take action.

Cayosoft Guardian alerts administrators to disable or correct non-default PGIDs on affected accounts, preventing attackers from exploiting this vulnerability and limiting their ability to elevate privileges and persist in the domain. This helps provide visibility into potential attack paths and supports investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Defense Evasion Persistence Privilege Escalation
Defend Tactics
Domain Account Monitoring
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical