DCShadow is an Active Directory manipulation technique/tool used to register or reuse an inactive domain controller registration and simulate the behavior of a legitimate Domain Controller in order to push unauthorized changes into AD. The provided content describes it being used to create a rogue Domain Controller and to manipulate AD data, including objects and schemas. It is specifically associated with direct modification of attributes such as primaryGroupID, including setting a user’s primaryGroupID to 512 (Domain Admins) to obtain effective privileged group membership. The content also notes that DCShadow can bypass LSASS and directly modify the AD database, and references use via mimikatz. Reported effects include inconsistencies in how AD tools display membership when primaryGroupID is abused: some tools and queries may show or omit membership differently, and recursive enumeration may miss users whose membership is derived through primaryGroupID. The content further discusses that changing primaryGroupID in testing also removed the prior primary-group membership, and highlights monitoring blind spots around privileged-group enumeration. Targeted environment is Windows Active Directory domain infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Active Directory database replication/forgery technique used to directly modify AD objects/attributes (e.g., primaryGroupID) by simulating a domain controller, bypassing typical controls and enabling stealthy privilege manipulation.
A post-compromise technique/tool for manipulating Active Directory by registering a rogue domain controller and injecting replicated changes into AD.
A post-compromise technique/tool for registering a rogue domain controller and manipulating Active Directory objects and schema data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.