Dynamic Objects in Active Directory: The Stealthy Threat
ID: 8e651d72-8c49-574d-a933-ce89df38f151
STIX ID: report--8e651d72-8c49-574d-a933-ce89df38f151
Feed Name: Tenable Blog
The report analyzes how attackers can weaponize Active Directory dynamic objects—self-deleting entries with TTL—to evade forensic visibility and create persistent “ghost” artifacts across on-prem AD and Entra ID. Through six scenarios (machine account quota bypass, primaryGroupID corruption, AdminSDHolder orphan SIDs, orphaned GPO links with malicious gPCFileSysPath, short-lived DNS records, and cloud sync gaps), it demonstrates how evidence can self-destruct while leaving broken references that hinder incident response. The paper recommends proactive, near real-time monitoring for dynamic object attributes (entryTTL and msDS-Entry-Time-To-Die), disabling or constraining risky defaults like MAQ, and correlating orphaned SIDs and structural inconsistencies to detect and remediate these ephemeral threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
