Active Directory Attack Vectors

Active Directory Attack Vectors

To secure and defend an Active Directory deployment, one must also be aware of the various attack vectors that perpetrators employ in their attempts to compromise the various high-value assets that comprise Active Directory's attack surface.


The following is an asset-focused list of attack vectors employed by perpetrators against the various Active Directory assets -

  1. Attack Vectors used to compromise Domain Controllers

    Note - The contents of this section apply equally to Secure Administrative Workstations (SAWs), which (as also mentioned here) must be considered as valuable as DCs and afforded the same level of physical network and systems security as afforded to DCs.
    1. Engage in unauthorized modification to compromise a domain controller's computer account in Active Directory -
      1. Modify the security permissions protecting a domain controller computer account in Active Directory
      2. Modify the ownership of a domain controller computer account in Active Directory
      3. Modify various security-sensitive attributes on a domain controller computer account in Active Directory
    2. Engage in Active Directory Privilege Escalation to compromise a domain controller's computer account in Active Directory
    3. Engage in credential theft to compromise a domain controller's computer account in Active Directory
    4. Employ any one of numerous standard well-known ways of attempting to compromise a Windows host
    5. Employ any one of numerous standard specific ways of attempting to compromise a Domain Controller

  2. Attack Vectors used to compromise Administrative Access

    1. Engage in unauthorized modification to compromise an Active Directory administrative account or group -
      1. Modify the security permissions protecting an Active Directory administrative account
      2. Modify the security permissions protecting an Active Directory administrative group
      3. Modify the ownership of an Active Directory administrative account
      4. Modify the ownership of an Active Directory administrative group
      5. Reset the password of an administrative account in Active Directory
      6. Modify the membership of an administrative group in Active Directory
      7. Add oneself to the membership of an administrative group in Active Directory
      8. Modify various security-sensitive attributes on an administrative account in Active Directory
    2. Engage in Active Directory Privilege Escalation to compromise an Active Directory administrative account or group
    3. Engage in credential theft to compromise an Active Directory administrative account

  3. Attack Vectors used to compromise Active Directory Contents

    1. Engage in unauthorized modification to create, delete, modify or compromise an Active Directory object -
      1. Create an Active Directory object
      2. Delete an Active Directory object
      3. Modify an attribute of an Active Directory object
      4. Modify the security permission on an Active Directory object
      5. Modify the ownership of an Active Directory object
    2. Engage in Active Directory Privilege Escalation to be able to create, delete, modify or compromise an Active Directory object

  4. Attack Vectors used to compromise Active Directory Backups

    1. Obtain unauthorized access to an Active Directory backup and subject it to techniques that can be used to gain access to the credentials of all accounts in Active Directory

  5. Attack Vectors used to exploit Weaknesses in in Active Directory's Logical Structure

    1. Engage in unauthorized modification to alter/tamper Active Directory trust relationships -
      1. Create new (external, cross-forest or Kerberos realm) trust relationships
      2. Delete existing trust relationships
      3. Change the direction of existing trust relationships
      4. Disable SID filtering across a trust relationship
    2. Engage in Active Directory Privilege Escalation to be able to alter/tamper Active Directory trust relationships
    3. Engage in credential theft to compromise a trust account in Active Directory

  6. +

  7. Attack Vectors used to compromise Critical Dependencies

    Note - The security of critical dependencies is currently out of the scope of this undertaking.