[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPsEHgTE--bMmv-DBjjRb9PLsIuDxRg_pwik-EGy1aOg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":49,"createdAt":49,"_status":48},39,"How can a non-privileged user create a DNS record for a machine account?","Using the Invoke-DNSUpdate.ps1 script from the Powermad toolkit, a non-privileged user can add various DNS records (A, AAAA, CNAME, etc.) for machine accounts they create. This helps an attacker blend into the network or redirect services. For more on obtaining DNS records before creating them, refer to [Domain Penetration - Obtaining DNS Records with Regular User Privileges](\u002Fnews\u002Fdomain-penetration-obtaining-dns-records-with-regular-user-privileges).","\u003Cp>Using the Invoke-DNSUpdate.ps1 script from the Powermad toolkit, a non-privileged user can add various DNS records (A, AAAA, CNAME, etc.) for machine accounts they create. This helps an attacker blend into the network or redirect services. For more on obtaining DNS records before creating them, refer to [Domain Penetration - Obtaining DNS Records with Regular User Privileges](\u002Fnews\u002Fdomain-penetration-obtaining-dns-records-with-regular-user-privileges).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dns-records-and-machineaccount\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-a-non-privileged-user-create-a-dns-record-for-a-machine-account-1777485455108","DNS records, Invoke-DNSUpdate, Powermad, non-privileged user",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},11,"Domain Penetration - DNS Records and MachineAccount","domain-penetration-dns-records-and-machineaccount","Learn how non-privileged users create DNS records and MachineAccounts in domain environments for penetration testing and security analysis.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Previous articles \"Domain Penetration - Obtaining DNS Records\" and \"Domain Penetration - Obtaining DNS Records with Standard User Privileges\" introduced methods for acquiring DNS records in domain environments, which help us quickly understand the internal network architecture.\u003C\u002Fp>\u003Cp>However, DNS records can only serve as auxiliary indicators. There is no direct correlation between DNS records, the corresponding MachineAccount in DNS records, and the actual computers.\u003C\u002Fp>\u003Cp>Non-privileged users within the domain can freely create DNS records and MachineAccounts.\u003C\u002Fp>\u003Cp>This article will introduce methods for non-privileged users to create DNS records and MachineAccounts within a domain, documenting the essential knowledge points to master.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to MachineAccount\u003C\u002Fli>\u003Cli>Methods for non-privileged users to create MachineAccounts\u003C\u002Fli>\u003Cli>Methods for non-privileged users to create DNS records\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to MachineAccount\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. MachineAccount\u003C\u002Fh3>\u003Cp>Whenever a computer joins a domain, a machine account (MachineAccount) is created as a member of the \"Domain Computers\" group.\u003C\u002Fp>\u003Cp>In a domain environment, the list of all machine accounts can be obtained with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net group \"Domain Computers\" \u002Fdomain\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Each machine account name ends with the character $.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When using Mimikatz's DCSync feature to export all user hashes, all machine account hashes are also exported.\u003C\u002Fp>\u003Cp>If a machine account hash is obtained, it can be used to forge a Silver Ticket, thereby gaining access to corresponding services. For exploitation methods, refer to the previous article \"Domain Penetration – Pass The Ticket\".\u003C\u002Fp>\u003Ch3>2. MachineAccountQuota\u003C\u002Fh3>\u003Cp>Indicates the number of computer accounts a user is allowed to create in the domain, with a default value of 10.\u003C\u002Fp>\u003Cp>Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fadschema\u002Fa-ms-ds-machineaccountquota\u003C\u002Fp>\u003Cp>For an introduction to MachineAccountQuota (MAQ), refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.netspi.com\u002Fmachineaccountquota-is-useful-sometimes\u002F\u003C\u002Fp>\u003Cp>Here is a brief summary of the 10 rules mentioned in the reference material, along with personal insights. The characteristics are as follows:\u003C\u002Fp>\u003Cp>(1) Allow non-privileged users to create computer accounts via MAQ, default is 10, but cannot delete created computer accounts\u003C\u002Fp>\u003Cp>To disable MAQ, refer to: https:\u002F\u002Fsocial.technet.microsoft.com\u002Fwiki\u002Fcontents\u002Farticles\u002F5446.active-directory-how-to-prevent-authenticated-users-from-joining-workstations-to-a-domain.aspx\u003C\u002Fp>\u003Cp>(2) The creator account's SID is stored in the ms-DS-CreatorSID attribute of the computer account\u003C\u002Fp>\u003Cp>That is, for computer accounts created via MAQ, viewing the ms-DS-CreatorSID attribute can reveal the creator account's SID\u003C\u002Fp>\u003Cp>(3) Computer accounts created via MAQ will be placed in the \"Domain Computers\" group\u003C\u002Fp>\u003Cp>(4) For computer accounts created via MAQ, the following attributes can be modified:\u003C\u002Fp>\u003Cul>\u003Cli>AccountDisabled\u003C\u002Fli>\u003Cli>description\u003C\u002Fli>\u003Cli>displayName\u003C\u002Fli>\u003Cli>DnsHostName\u003C\u002Fli>\u003Cli>ServicePrincipalName\u003C\u002Fli>\u003Cli>userParameters\u003C\u002Fli>\u003Cli>userAccountControl\u003C\u002Fli>\u003Cli>msDS-AdditionalDnsHostName\u003C\u002Fli>\u003Cli>msDS-AllowedToActOnBehalfOfOtherIdentity\u003C\u002Fli>\u003Cli>samAccountName\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The AccountDisabled property can be used to disable this user\u003C\u002Fp>\u003Cp>The userAccountControl property records the user's attribute information. For details, refer to https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F305144\u002Fhow-to-use-useraccountcontrol-to-manipulate-user-account-properties\u003C\u002Fp>\u003Cp>(5) Adding a computer account will create the following 4 SPNs:\u003C\u002Fp>\u003Cul>\u003Cli>HOST\u002FMachineAccountName\u003C\u002Fli>\u003Cli>HOST\u002FMachineAccountName.domain.name\u003C\u002Fli>\u003Cli>RestrictedKrbHost\u002FMachineAccountName\u003C\u002Fli>\u003Cli>RestrictedKrbhost\u002FMachineAccountName.domain.name\u003C\u002Fli>\u003C\u002Ful>\u003Cp>(6) Machine accounts do not have local login permissions\u003C\u002Fp>\u003Cp>But commands can be executed via \"runas \u002Fnetonly\"\u003C\u002Fp>\u003Ch2>0x03 Methods for Non-Privileged Users to Create MachineAccounts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. PowerShell Implementation\u003C\u002Fh3>\u003Cp>Requires Powermad\u003C\u002Fp>\u003Cp>The command to create a computer account testNew via MAQ is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-MachineAccount -MachineAccount testNew -Password $(ConvertTo-SecureString \"123456789\" -AsPlainText -Force)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View the full properties of the computer account testNew:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-ADComputer testNew -Properties *\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Specifically includes the following properties:\u003C\u002Fp>\u003Cul>\u003Cli>AccountExpirationDate\u003C\u002Fli>\u003Cli>accountExpires\u003C\u002Fli>\u003Cli>AccountLockoutTime\u003C\u002Fli>\u003Cli>AccountNotDelegated\u003C\u002Fli>\u003Cli>AllowReversiblePasswordEncryption\u003C\u002Fli>\u003Cli>AuthenticationPolicy\u003C\u002Fli>\u003Cli>AuthenticationPolicySilo\u003C\u002Fli>\u003Cli>BadLogonCount\u003C\u002Fli>\u003Cli>badPasswordTime\u003C\u002Fli>\u003Cli>badPwdCount\u003C\u002Fli>\u003Cli>CannotChangePassword\u003C\u002Fli>\u003Cli>CanonicalName\u003C\u002Fli>\u003Cli>Certificates\u003C\u002Fli>\u003Cli>CN\u003C\u002Fli>\u003Cli>codePage\u003C\u002Fli>\u003Cli>CompoundIdentitySupported\u003C\u002Fli>\u003Cli>countryCode\u003C\u002Fli>\u003Cli>Created\u003C\u002Fli>\u003Cli>createTimeStamp\u003C\u002Fli>\u003Cli>Deleted\u003C\u002Fli>\u003Cli>Description\u003C\u002Fli>\u003Cli>DisplayName\u003C\u002Fli>\u003Cli>DistinguishedName\u003C\u002Fli>\u003Cli>DNSHostName\u003C\u002Fli>\u003Cli>DoesNotRequirePreAuth\u003C\u002Fli>\u003Cli>dSCorePropagationData\u003C\u002Fli>\u003Cli>Enabled\u003C\u002Fli>\u003Cli>HomedirRequired\u003C\u002Fli>\u003Cli>HomePage\u003C\u002Fli>\u003Cli>instanceType\u003C\u002Fli>\u003Cli>IPv4Address\u003C\u002Fli>\u003Cli>IPv6Address\u003C\u002Fli>\u003Cli>isCriticalSystemObject\u003C\u002Fli>\u003Cli>isDeleted\u003C\u002Fli>\u003Cli>KerberosEncryptionType\u003C\u002Fli>\u003Cli>LastBadPasswordAttempt\u003C\u002Fli>\u003Cli>LastKnownParent\u003C\u002Fli>\u003Cli>lastLogoff\u003C\u002Fli>\u003Cli>lastLogon\u003C\u002Fli>\u003Cli>LastLogonDate\u003C\u002Fli>\u003Cli>localPolicyFlags\u003C\u002Fli>\u003Cli>Location\u003C\u002Fli>\u003Cli>LockedOut\u003C\u002Fli>\u003Cli>logonCount\u003C\u002Fli>\u003Cli>ManagedBy\u003C\u002Fli>\u003Cli>MemberOf\u003C\u002Fli>\u003Cli>MNSLogonAccount\u003C\u002Fli>\u003Cli>Modified\u003C\u002Fli>\u003Cli>modifyTimeStamp\u003C\u002Fli>\u003Cli>mS-DS-CreatorSID\u003C\u002Fli>\u003Cli>msDS-User-Account-Control-Computed\u003C\u002Fli>\u003Cli>Name\u003C\u002Fli>\u003Cli>nTSecurityDescriptor\u003C\u002Fli>\u003Cli>ObjectCategory\u003C\u002Fli>\u003Cli>ObjectClass\u003C\u002Fli>\u003Cli>ObjectGUID\u003C\u002Fli>\u003Cli>objectSid\u003C\u002Fli>\u003Cli>OperatingSystem\u003C\u002Fli>\u003Cli>OperatingSystemHotfix\u003C\u002Fli>\u003Cli>OperatingSystemServicePack\u003C\u002Fli>\u003Cli>OperatingSystemVersion\u003C\u002Fli>\u003Cli>PasswordExpired\u003C\u002Fli>\u003Cli>PasswordLastSet\u003C\u002Fli>\u003Cli>PasswordNeverExpires\u003C\u002Fli>\u003Cli>PasswordNotRequired\u003C\u002Fli>\u003Cli>PrimaryGroup\u003C\u002Fli>\u003Cli>primaryGroupID\u003C\u002Fli>\u003Cli>PrincipalsAllowedToDelegateToAccount\u003C\u002Fli>\u003Cli>ProtectedFromAccidentalDeletion\u003C\u002Fli>\u003Cli>pwdLastSet\u003C\u002Fli>\u003Cli>SamAccountName\u003C\u002Fli>\u003Cli>sAMAccountType\u003C\u002Fli>\u003Cli>sDRightsEffective\u003C\u002Fli>\u003Cli>ServiceAccount\u003C\u002Fli>\u003Cli>servicePrincipalName\u003C\u002Fli>\u003Cli>ServicePrincipalNames\u003C\u002Fli>\u003Cli>SID\u003C\u002Fli>\u003Cli>SIDHistory\u003C\u002Fli>\u003Cli>TrustedForDelegation\u003C\u002Fli>\u003Cli>TrustedToAuthForDelegation\u003C\u002Fli>\u003Cli>UseDESKeyOnly\u003C\u002Fli>\u003Cli>userAccountControl\u003C\u002Fli>\u003Cli>userCertificate\u003C\u002Fli>\u003Cli>UserPrincipalName\u003C\u002Fli>\u003Cli>uSNChanged\u003C\u002Fli>\u003Cli>uSNCreated\u003C\u002Fli>\u003Cli>whenChanged\u003C\u002Fli>\u003Cli>whenCreated\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Get-ADComputer command requires the ActiveDirectory module, which is typically installed on domain controllers.\u003C\u002Fp>\u003Cp>For systems without the Active Directory module installed, you can import it using the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Microsoft.ActiveDirectory.Management.dll is generated after installing the PowerShell Active Directory module; I have extracted it and uploaded it to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Powermad also supports viewing computer account attributes, but specific attributes to view must be specified.\u003C\u002Fp>\u003Cp>For example, the command to view the servicePrincipalName attribute is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MachineAccountAttribute -MachineAccount testNew -Attribute servicePrincipalName\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Powermad's Get-MachineAccountCreator command can enumerate the creators of all computer accounts (MachineAccount).\u003C\u002Fp>\u003Cp>To modify computer account attributes, use Powermad's Set-MachineAccountAttribute command, which supports modifying the following attributes:\u003C\u002Fp>\u003Cul>\u003Cli>AccountDisabled\u003C\u002Fli>\u003Cli>description\u003C\u002Fli>\u003Cli>displayName\u003C\u002Fli>\u003Cli>DnsHostName\u003C\u002Fli>\u003Cli>ServicePrincipalName\u003C\u002Fli>\u003Cli>userParameters\u003C\u002Fli>\u003Cli>userAccountControl\u003C\u002Fli>\u003Cli>msDS-AdditionalDnsHostName\u003C\u002Fli>\u003Cli>msDS-AllowedToActOnBehalfOfOtherIdentity\u003C\u002Fli>\u003Cli>SamAccountName\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Example as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-MachineAccountAttribute -MachineName testNew -Attribute SamAccountName -Value test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2.C# Implementation\u003C\u002Fh3>\u003Cp>SharpAllowedToAct includes this functionality\u003C\u002Fp>\u003Cp>I extracted the function for creating a MachineAccount, made simple modifications to support compilation with csc.exe or Visual Studio\u003C\u002Fp>\u003Cp>The complete code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>You can use Visual Studio to create a C# project and compile AddMachineAccountofDomain.cs to generate an exe file, or upload AddMachineAccountofDomain.cs to a test environment and compile it using csc.exe\u003C\u002Fp>\u003Cp>The environment using csc.exe for compilation supports .NET 3.5 or higher\u003C\u002Fp>\u003Cp>The compilation command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe AddMachineAccountofDomain.cs \u002Fr:System.DirectoryServices.dll,System.DirectoryServices.Protocols.dll\u003Cbr>or\u003Cbr>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe AddMachineAccountofDomain.cs \u002Fr:System.DirectoryServices.dll,System.DirectoryServices.Protocols.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Method for Non-Privileged Users to Create DNS Records\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Here, you can use Invoke-DNSUpdate.ps1 from Powermad\u003C\u002Fp>\u003Cp>The Invoke-DNSUpdate command supports adding the following records:\u003C\u002Fp>\u003Cul>\u003Cli>A\u003C\u002Fli>\u003Cli>AAAA\u003C\u002Fli>\u003Cli>CNAME\u003C\u002Fli>\u003Cli>MX\u003C\u002Fli>\u003Cli>PTR\u003C\u002Fli>\u003Cli>SRV\u003C\u002Fli>\u003Cli>TXT\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add an A record for the machine account testNew with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-DNSUpdate -DNSType A -DNSName testNew -DNSData 192.168.1.111\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to delete this record is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-DNSUpdate -DNSType A -DNSName testNew\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Non-privileged users cannot modify or delete existing records\u003C\u002Fp>\u003Cp>For more details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.netspi.com\u002Fexploiting-adidns\u002F\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for creating DNS records and Machine Accounts by non-privileged users within the domain, demonstrating that DNS records can only serve as an auxiliary method for determining the internal network architecture\u003C\u002Fp>\u003Cp>From a defensive perspective, if an attacker only has the permissions of a non-privileged user within the domain, when attempting to create a computer account via MAQ, if they do not obtain higher privileges, they cannot clear attack traces (unable to delete computer accounts created via MAQ). The attacker can be identified by checking the creator of the computer account\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",4,"published","2026-02-02T08:20:29.495Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Domain Penetration: Creating DNS Records & MachineAccounts","domain penetration, DNS records, MachineAccount, non-privileged users, Active Directory, cybersecurity",false,[],{"docs":41,"hasNextPage":38},[42,4,43,44],40,38,37,{"title":30,"description":30,"image":30},"2026-07-24T02:07:30.657Z","2026-07-23T16:00:54.701Z","draft","2026-07-23T16:03:06.702Z"]