BadSuccessor: How to Detect and Mitigate dMSA Privilege Escalation
semperis.com | vulnerability | #active-directory | #privilege-escalation | #detection | #indicators-of-compromise | #directory-services-protector | #dmsa | #badsuccessor
Summary
BadSuccessor lets attackers abuse a dMSA to impersonate any AD user, including Domain Admins, with no patch available. Semperis DSP adds an exposure indicator plus three IOCs to detect it.
- Published
- Collected
Skip to content