← LibraryTechnique entry
AD-ZLPrivilege Escalation
ZeroLogon (CVE-2020-1472)
Reset a DC's machine account password to empty via Netlogon to take over the domain.
§ Where this technique fits
AD-ZL is catalogued under the Privilege Escalation tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 2 on average.
§ Dossiers chaining this technique
§ What commonly comes next
- 01DCSyncseen 1×T1003.006 · Credential Access
- 02Golden Ticketseen 1×T1558.001 · Credential Access