BackupOperatorToDA – From An Account Member Of The Group Backup Operators To Domain Admin Without RDP Or WinRM On The Domain Controller
If you compromise an account member of the group Backup Operators you can become the Domain Admin without RDP or WinRM on the Domain Controller.
All credit from
What’s the magic ?
The code is really simple, there is only 3 steps:
RegConnectRegistryA
: Establishes a connection to a predefinedDownload BackupOperatorToDA
If you like the site, please consider joining the telegram channel or supporting us on Patreon using the button below.