AdminSDHolder: Misconceptions, Misconfigurations, and Myths
ID: ff06687e-98a5-583a-a5ff-3356408deeb0
STIX ID: report--ff06687e-98a5-583a-a5ff-3356408deeb0
Feed Name: SpecterOps Blog
A concise blog distilling a 150+ page whitepaper on Active Directory AdminSDHolder clarifies that AdminSDHolder is both an object and a background task designed to protect privileged principals, debunks incorrect Microsoft documentation about SDProp’s role, and warns against weakening defaults via DACL or dSHeuristics changes while noting scope and exclusions (e.g., DC groups, cross-domain limits). It also announces BloodHound v8.3.0 and SharpHound updates that expose AdminSDHolder protection status, highlight Tier Zero gaps, and provide remediation guidance for DACL-based risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
