Unauthorized Modification of AdminSDHolder ACL in Active Directory
Attackers modify the Access Control List of the AdminSDHolder object in Active Directory to establish domain persistence and escalate privileges by leveraging the automated Security Descriptor Propagator process.
The AdminSDHolder object is a critical container in Active Directory that serves as a template for security permissions applied to high-privileged groups and accounts (e.g., Domain Admins, Enterprise Admins). The Security Descriptor Propagator (SDProp) process runs on the domain controller holding the PDC Emulator role and periodically propagates the ACL of the AdminSDHolder object to all protected objects in the domain.
Attackers who gain sufficient privileges (typically Domain Admin or equivalent) can modify the AdminSDHolder ACL to grant themselves or a controlled security principal persistent access. Once the modification occurs, the SDProp process ensures that these permissions are consistently reapplied to protected objects, effectively bypassing manual remediation efforts and providing long-term persistence even if their original credentials are revoked. Monitoring this behavior is essential for detecting unauthorized domain-level privilege escalation attempts.
Attack Chain
- Attacker gains initial access and performs local reconnaissance to identify domain-level vulnerabilities.
- Attacker escalates privileges to a level sufficient to modify Active Directory objects (e.g., Domain Admin).
- Attacker identifies the AdminSDHolder object path in the domain (CN=AdminSDHolder,CN=System).
- Attacker uses LDAP modification or Windows management tools to add a new Access Control Entry (ACE) to the AdminSDHolder's nTSecurityDescriptor attribute.
- The Active Directory environment logs the modification via EventCode 5136.
- The Security Descriptor Propagator (SDProp) runs (typically every 60 minutes).
- SDProp applies the malicious ACL modification to all protected high-privileged groups and accounts.
- Attacker leverages the newly granted permissions to maintain persistent administrative access across the Active Directory environment.
Impact
Successful modification of the AdminSDHolder object allows an attacker to achieve domain-wide persistence and full administrative control over all high-privileged accounts. Because these permissions are managed by the automated SDProp process, simple modifications to group membership or account permissions by defenders are frequently overwritten, making this a highly durable persistence mechanism. This compromises the integrity and security of the entire domain, potentially leading to total loss of control over the identity infrastructure.
Recommendation
- Enable "Audit Directory Services Changes" within the "DS Access" advanced audit policy settings on all Domain Controllers.
- Create a System Access Control List (SACL) for the AdminSDHolder object to ensure modifications are captured in security event logs.
- Deploy the provided Sigma rule to detect EventCode 5136 occurrences where the AdminSDHolder ACL is modified.
- Investigate all alerts triggered by this rule immediately, as unauthorized modifications to protected objects are rarely indicative of benign administrative activity.
Immediate actions
Audit SACL configuration on AdminSDHolder object
Mitigations
Enable Audit Directory Services Changes policy
Persistence via AdminSDHolder
Detection coverage 1
Detect AdminSDHolder ACL Modification
highDetects modifications to the nTSecurityDescriptor attribute of the AdminSDHolder object, which may indicate unauthorized attempts to establish domain persistence.
Detection queries are available on the platform. Get full rules →