Skip to main content
AD Academy

Privilege ladder

An attacker's path from bottom to top: from a regular user to the domain controller. Each step — why it's dangerous and how to spot it.

  1. 1

    Authenticated user

    Danger: Can read the whole domain: users, groups, GPOs — a map for attack

    Detection: Mass enumeration (BloodHound): 4662, anomalous LDAP

  2. 2

    Local admin

    Danger: Steals hashes from memory — a step to the next machine

    Detection: 4672, correlated 4624/4634, LSASS access

  3. 3

    Domain Admins

    Danger: Full domain control: any user, computer, GPO

    Detection: 4728/4732/4756 (group membership), 4672 on DCs

  4. 4

    Enterprise Admins

    Danger: Control of the whole forest — every domain

    Detection: 4728 in the EA group, site/replication changes

  5. 5

    The DC itself

    Danger: Access to NTDS.dit — every password in the domain

    Detection: 4662 (replication), shadow copies on DC, odd backups