Rogue Domain Controller

T1207

Technique.View on attack.mitre.org

About this technique

Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data. DCShadow may be used to create a rogue Domain Controller (DC). DCShadow is a method of manipulating Active Directory (AD) data, including objects and schemas, by registering (or reusing an inactive registration) and simulating the behavior of a DC. Once registered, a rogue DC may be able to inject and replicate changes into AD infrastructure for any domain object, including credentials and keys.

Registering a rogue DC involves creating a new server and nTDSDSA objects in the Configuration partition of the AD schema, which requires Administrator privileges (either Domain or local to the DC) or the KRBTGT hash.

This technique may bypass system logging and security monitors such as security information and event management (SIEM) products (since actions taken on a rogue DC may not be reported to these sensors). The technique may also be used to alter and delete replication and other associated metadata to obstruct forensic analysis. Adversaries may also utilize this technique to perform SID-History Injection and/or manipulate AD objects (such as accounts, access control lists, schemas) to establish backdoors for Persistence.

Detection rules8

Rules on DetectionCode tagged with T1207.

Sigma2

RuleLevelLog source
Possible DC Shadow Attackmediumwindows / NULL
Add or Remove Computer from DClowwindows / NULL

Splunk6

RuleTypeRiskData source
Windows AD DCShadow Privileges ACL AdditionTTPNULLWindows Event Log Security 5136
Windows AD Domain Controller PromotionTTPNULLWindows Event Log Security 4742
Windows AD Replication Service TrafficTTPNULL
Windows AD Rogue Domain Controller Network ActivityTTPNULL
Windows AD Short Lived Domain Controller SPN AttributeTTPNULLWindows Event Log Security 5136, Windows Event Log Security 4624
Windows AD Short Lived Server ObjectTTPNULLWindows Event Log Security 5137, Windows Event Log Security 5141

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
ToolMimikatz

Mimikatz’s LSADUMP::DCShadow module can be used to make AD updates by temporarily setting a computer to be a DC.

References2

  1. Adsecurity Mimikatz Guide Open source
    Metcalf, S. (2015, November 13). Unofficial Guide to Mimikatz & Command Reference. Retrieved December 23, 2015.
  2. DCShadow Blog Open source
    Delpy, B. & LE TOUX, V. (n.d.). DCShadow. Retrieved March 20, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.