CTD-000080

Regular AD user account with permissions to modify DNS server objects

High
Active Directory DNS
Execution Privilege Escalation
v26

Signature Identity

CTD-000080
Threat ID
26
Version
IOE
Indicator Type

Threat Description

A regular user who is a member of the DNS Admins group or has write permissions on a DNS server object poses a threat to your Active Directory environment. A threat actor might use such an account to escalate privileges by injecting a malicious DLL into the DNS process running as a System to escalate when the service restarts.

NOTE: Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. Privileged users are defined in Active Directory as users with AdminCount=1. By design, Active Directory uses this attribute to protect members of administrative groups.

According to security best practices, it is not recommended to reuse admin accounts; instead, these accounts must be de-provisioned. If an account has administrative permissions, it may also gain access to other resources using these permissions and retain this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.

MITRE ATT&CK: Attack Tactics

Execution Privilege Escalation

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

Remove regular users from the DNS Admins group or remove the permissions to modify DNS Server objects. Learn more about revoking permissions. 

To remove a user from a group using Active Directory Users and Computers (ADUC):

  1. Open the Active Directory Users and Computers tool. You can access it by searching for Active Directory Users and Computers in the Start menu or by opening the Administrative Tools folder.
  2. Once the tool is open, navigate to the domain or organizational unit (OU) where the DNSAdmins group is located. 
  3. Locate and select the group from which you want to remove the user. 
  4. Right-click on the group and select Properties from the context menu. This will open the properties window for the group.
  5. In the group properties window, switch to the Members tab. This tab displays a list of users currently a part of the group.
  6. Locate the user you want to remove from the group in the list of members. Select the user by clicking on their name.
  7. Once the user is selected, click the Remove button. This will remove the user from the group.
  8. After clicking Remove, a confirmation prompt will appear. Click Yes to confirm the removal of the user from the group.
  9. The user will now be removed from the group. Click OK to close the group properties window.
  10. Verify that the user has been successfully removed by checking the list of members on the Members tab of the group properties window. The user’s name should no longer be listed.

Frequently Asked Questions

What does Regular AD user account with permissions to modify DNS server objects mean?

This refers to an Active Directory user who is a member of the DNS Admins group or has write permissions on a DNS server object, allowing them to make changes to DNS settings.

This type of access allows an attacker to inject a malicious DLL into the DNS process running as System, which can be used to escalate privileges when the service restarts. This privilege escalation can also grant access to other resources in the environment due to the administrative scope and permissions associated with DNS server object modifications.

Attackers can inject a malicious DLL into the DNS process running as System, which can be used to escalate privileges when the service restarts. This type of access can also grant unauthorized access to other resources in the environment through persistence and reconnaissance capabilities.

Cayosoft Guardian continuously monitors Active Directory for accounts with DNS modification permissions and flags them as security issues, alerting administrators to potential risks. This detection is based on the identification of accounts with write permissions on DNS server objects or membership in the DNS Admins group.

Cayosoft Guardian alerts administrators to remove users from the DNS Admins group or revoke their write permissions on DNS server objects, reducing the risk of privilege escalation and unauthorized access. Ongoing monitoring ensures that if such an account is re-enabled later, the change is caught quickly, providing visibility and support for investigation and response.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory DNS
Themes
Account protection
Attack Tactics
Execution Privilege Escalation
Defend Tactics
Domain Account Monitoring
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical