An Arrow to the Heel: Abusing Default Machine Joining to Domain Permissions to Attack AWS Managed Active Directory
ID: 73a20b03-50de-596f-a52c-433118b30cb0
STIX ID: report--73a20b03-50de-596f-a52c-433118b30cb0
Feed Name: Cloud Chronicles
Permiso demonstrates that AWS Managed Active Directory's immutable default ms-ds-MachineAccountQuota and the permissive "AWS Delegated Add Workstations to the Domain" group — combined with ds:CreateComputer access via the Directory Service API or common instance profiles — allow non-privileged users or compromised instances to create machine accounts and abuse Resource-Based Constrained Delegation (RBCD) to escalate to OU/local administrative access; Permiso recommends restricting group membership, monitoring CloudWatch for EventID 4741, and hardening instance profiles, while noting AWS declined to treat the behavior as a service issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
