logo

Understanding & Mitigating BadSuccessor

ID: b165c88e-c713-5f12-a156-90c0cf4ab17e

STIX ID: report--b165c88e-c713-5f12-a156-90c0cf4ab17e

Feed Name: SpecterOps Blog

Threat Score
80/100

Date Published: 2025-05-27

Date Updated: 2026-04-30

Author: Jim Sykora

...
...

BadSuccessor is a new Active Directory attack primitive that abuses Delegated Managed Service Accounts (dMSAs) when a Windows Server 2025 domain controller exists and a KDS Root Key has been generated; by setting msDS-ManagedAccountPrecededByLink and related attributes an attacker who can create or modify a dMSA can obtain a Kerberos TGT impersonating any account (including Domain Admin), enabling full forest compromise. The report explains the attack steps, root causes (KDC blind trust and AD DACL/ownership behaviors), provides layered mitigations (DACL deny ACEs, disabling implicit owner rights/dSHeuristics, LDAP Add restrictions, audit/detection guidance) and supplies PowerShell tooling and guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.