Skip to content
Threat Feed
high advisory

Unauthorized Modification of AdminSDHolder ACL in Active Directory

Attackers modify the Access Control List of the AdminSDHolder object in Active Directory to establish domain persistence and escalate privileges by leveraging the automated Security Descriptor Propagator process.

The AdminSDHolder object is a critical container in Active Directory that serves as a template for security permissions applied to high-privileged groups and accounts (e.g., Domain Admins, Enterprise Admins). The Security Descriptor Propagator (SDProp) process runs on the domain controller holding the PDC Emulator role and periodically propagates the ACL of the AdminSDHolder object to all protected objects in the domain.

Attackers who gain sufficient privileges (typically Domain Admin or equivalent) can modify the AdminSDHolder ACL to grant themselves or a controlled security principal persistent access. Once the modification occurs, the SDProp process ensures that these permissions are consistently reapplied to protected objects, effectively bypassing manual remediation efforts and providing long-term persistence even if their original credentials are revoked. Monitoring this behavior is essential for detecting unauthorized domain-level privilege escalation attempts.

Attack Chain

  1. Attacker gains initial access and performs local reconnaissance to identify domain-level vulnerabilities.
  2. Attacker escalates privileges to a level sufficient to modify Active Directory objects (e.g., Domain Admin).
  3. Attacker identifies the AdminSDHolder object path in the domain (CN=AdminSDHolder,CN=System).
  4. Attacker uses LDAP modification or Windows management tools to add a new Access Control Entry (ACE) to the AdminSDHolder's nTSecurityDescriptor attribute.
  5. The Active Directory environment logs the modification via EventCode 5136.
  6. The Security Descriptor Propagator (SDProp) runs (typically every 60 minutes).
  7. SDProp applies the malicious ACL modification to all protected high-privileged groups and accounts.
  8. Attacker leverages the newly granted permissions to maintain persistent administrative access across the Active Directory environment.

Impact

Successful modification of the AdminSDHolder object allows an attacker to achieve domain-wide persistence and full administrative control over all high-privileged accounts. Because these permissions are managed by the automated SDProp process, simple modifications to group membership or account permissions by defenders are frequently overwritten, making this a highly durable persistence mechanism. This compromises the integrity and security of the entire domain, potentially leading to total loss of control over the identity infrastructure.

Recommendation

  1. Enable "Audit Directory Services Changes" within the "DS Access" advanced audit policy settings on all Domain Controllers.
  2. Create a System Access Control List (SACL) for the AdminSDHolder object to ensure modifications are captured in security event logs.
  3. Deploy the provided Sigma rule to detect EventCode 5136 occurrences where the AdminSDHolder ACL is modified.
  4. Investigate all alerts triggered by this rule immediately, as unauthorized modifications to protected objects are rarely indicative of benign administrative activity.

Immediate actions

Audit SACL configuration on AdminSDHolder object

SOC 48h

Mitigations

Enable Audit Directory Services Changes policy

immediate IT Operations

Persistence via AdminSDHolder

Detection coverage 1

Detect AdminSDHolder ACL Modification

high

Detects modifications to the nTSecurityDescriptor attribute of the AdminSDHolder object, which may indicate unauthorized attempts to establish domain persistence.

sigma tactics: persistence techniques: T1546 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →