How Attackers Can Use Active Directory Primary Group Membership for Defense Evasion
semperis.com | blog | #active-directory | #privilege-escalation | #detection | #defense-evasion | #primary-group-id | #dacl
Summary
A little-known DACL trick lets attackers use the Primary Group ID attribute plus a specific ACE to hide their membership in a group they belong to—no permissions on the group needed—concealing malicious users; detection guidance included.
- Published
- Collected
Skip to content