Service Accounts: The Shortest Path to Domain Admin | Ep 194
Show notes
Service accounts are one of the easiest paths to domain admin on an internal
pen test, and one of the most neglected accounts in Active Directory.
In this episode, Spencer and Tyler break down why service accounts keep
falling: Kerberoasting every service account (not just the privileged ones),
cracking the hashes offline, and spraying what cracks across the environment.
Tyler shares a recent engagement where a non-administrative service account
shared its password with a domain admin. Same password, one "SVC_" prefix
apart. That spray handed over the domain. He's also seen the built-in RID 500
administrator account used as a service account on three separate engagements
this year.
They also get into where these credentials actually live: web.config files on
open file shares, plaintext password files (present on roughly 90% of their
pen tests), and one .eml attachment with the credentials sitting inside a
screenshot.
Then the fix list, in the order they'd actually do it:
- Inventory the accounts and document where each one is used, before you touch a password
- Delete the service accounts that don't need to exist
- Strip privileges and restrict interactive logon rights
- Get a password vault or PAM solution, and make every password long and unique
- Alert on service accounts logging on interactively
- Move to group managed service accounts (gMSA) where you can
- Enforce 20-25 character minimums in the meantime. They've cracked 20+ character passphrases with a gaming rig, a 180 GB wordlist, and mutation rules producing roughly four quadrillion permutations
Plus the three cleanup mistakes that cause the most damage, including the story
of a $70 billion enterprise where one undocumented password reset turned into a
10-hour troubleshooting call.
Blog: https://offsec.blog/
Youtube: https://www.youtube.com/@cyberthreatpov
Twitter: https://x.com/cyberthreatpov
Follow Spencer on social ⬇
Spencer's Links: https://spenceralessi.com
Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.