Understanding & Mitigating BadSuccessor
ID: b165c88e-c713-5f12-a156-90c0cf4ab17e
STIX ID: report--b165c88e-c713-5f12-a156-90c0cf4ab17e
Feed Name: SpecterOps Blog
BadSuccessor is a new Active Directory attack primitive that abuses Delegated Managed Service Accounts (dMSAs) when a Windows Server 2025 domain controller exists and a KDS Root Key has been generated; by setting msDS-ManagedAccountPrecededByLink and related attributes an attacker who can create or modify a dMSA can obtain a Kerberos TGT impersonating any account (including Domain Admin), enabling full forest compromise. The report explains the attack steps, root causes (KDC blind trust and AD DACL/ownership behaviors), provides layered mitigations (DACL deny ACEs, disabling implicit owner rights/dSHeuristics, LDAP Add restrictions, audit/detection guidance) and supplies PowerShell tooling and guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
