Back to Active Directory

Gmsa Passwords

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

gMSA (Group Managed Service Account) Password attacks target the ability to retrieve gMSA passwords from Active Directory. Any account with the ability to read msDS-ManagedPassword attribute (or through LDAP queries) can retrieve the current password of a gMSA.

Reading gMSA passwords provides access to service accounts that often have elevated privileges on multiple systems.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Gmsa Passwords:

Get-ADServiceAccount -Identity svc_gmsa -Properties msDS-ManagedPassword
$gmsa = Get-ADServiceAccount -Identity svc_gmsa -Properties msDS-ManagedPassword; $gmsa.msDS-ManagedPassword
gMSADumper.py -u user -p password -d domain.local -l dc.domain.local
python3 gMSADumper.py -u USER -p PASS -d DOMAIN -l DC_IP

Tools & Techniques

Recommended tools for Gmsa Passwords:

  • PowerShell Get-ADServiceAccount: read gMSA password
  • gMSADumper: Python tool for gMSA password extraction
  • Requires: read access to msDS-ManagedPassword attribute

Prevention & Mitigation

Security recommendations to prevent Gmsa Passwords:

  • Restrict read access to msDS-ManagedPassword attribute
  • Delegate gMSA access only to authorized administrators
  • Use separate gMSAs for different services
  • Monitor for unusual LDAP queries against gMSA objects

References

Additional resources: