The (Near) Return of the King: Account Takeover Using the BadSuccessor Technique
ID: 1d993e1f-b65b-5316-960a-397ba64f9474
STIX ID: report--1d993e1f-b65b-5316-960a-397ba64f9474
Feed Name: SpecterOps Blog
Threat Score
This blog analyzes how BadSuccessor-related dMSA abuse remains exploitable after Microsoft’s patch, documents updated tools (SharpSuccessor and a native BOF named BadTakeover) that weaponize the technique, and demonstrates account takeover that can yield domain administrator access when an attacker has CreateChild on an OU, write permissions to specific msDS attributes, and at least one Windows Server 2025 DC; it urges defenders to harden DACLs and manage identity attack paths.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
