logo

Adventures in Primary Group Behavior, Reporting, and Exploitation

ID: 5418357f-27b2-57cf-90ae-34df2706ddae

STIX ID: report--5418357f-27b2-57cf-90ae-34df2706ddae

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2026-01-22

Date Updated: 2026-05-01

...
...

This report analyzes abuse of Active Directory's primaryGroupID and associated DACL manipulation—demonstrating how attackers using tools like mimikatz, DCShadow, and DSInternals can set or hide privileged group membership (e.g., Domain Admins), how different AD tools inconsistently report membership, and how a deny DACL can make privileged memberships invisible; it concludes with detection queries and recommendations to audit primaryGroupID settings and validate monitoring tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.