← All Lessons
Premium

TechniqueActive Directory

AdminSDHolder Persistence

After reaching domain dominance, an attacker can turn one of Active Directory's own security features into a self-healing backdoor by editing the AdminSDHolder template. This lesson explains how the SDProp process re-applies a planted permission to Domain Admins every hour, why removing your rights from the group does not remove them, and how to communicate the risk clearly in interviews, reports, and stakeholder conversations.

Sign in or upgrade to unlock the full premium library.

What you'll learn

  • AdminSDHolder
  • SDProp (Security Descriptor Propagator)
  • Protected groups / adminCount
  • Template backdoor
  • Self-healing persistence
  • Right selection

What premium includes

  • All 78 lessons: AD techniques, professional skills, each with interview answers and study kits
  • Complete study kit for every lesson: quizzes, flashcards, and briefs
  • Every learning track with full structured progression
  • All 12 attack paths: full compromise walkthroughs for interviews and reports
  • New lessons and attack paths added regularly

Continue with free content

AdminSDHolder Persistence — ExplainTheHack