The Funny Story of Active Directory Backdooring @FIRSTdotorg
The Funny Story of Active Directory Backdooring  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 8 minutes ago
Sylvain Cortes (Hackuity, FR)

Sylvain Cortes is an international expert in identity and access management (IAM) and cybersecurity. During his career, he has mainly worked with large organizations to carry out identity or directory governance projects, including authentication processes, inter-OS privilege management, cloud identity management and Active Directory cybersecurity. He has developed a deep expertise in Active Directory security and backdooring concept. Sylvain is the president of CADIM, a French non-profit organization that organizes an annual event in Paris dedicated to identity management and cyber security: www.identitydays.com. Sylvain is a speaker for various events such as: Blackhat, Cloud Expo, IdentityDays, FS-ISAC, aOS, IT Nordics, Les Assises de la Sécurité, FIC, etc. For 18 years, Sylvain has been recognized by Microsoft as a Microsoft MVP on Active Directory & Security.
--
What is the hardest question to answer after an Active Directory attack? It's very simple: "Do I have a backdoor in my directory after this attack?"In this session, we will present the state of the art regarding backdoors in AD, with concrete examples of simple and advanced techniques working from AD 2003 to AD 2025 and ensuring attackers' group persistence. We will cover AD backdoors in general, then go into detail about backdooring techniques targeting SIDhistory, Managed by, gPLink, GPOs, ACEs, and more.Finally, we'll look at the combination of multiple techniques used to hide leads and make persistent attackers virtually undetectable.
The Funny Story of Active Directory BackdooringPivoting To Resilience: Disruptive Incidents And How We Prepare For ThemLessons From NPMs Dark Side: Preventing the Next Shai-HuludThe CVE Blind Spot: Defeating Hidden EOLs and Repo Jacking with Engineering Triage & Code DietAll Ransomware Economic Models are Wrong, But This One is UsefulCISA-ENISA Joint MessagingPanel: From Takedown to Touchpoint: An Inside Look at the Data-sharing Pipeline in the Victim ...Bringing Actionable Data to Internet DefendersUnlocking Insights: The Role of TI in Modern DFIR OperationsThe Quality Era of CVE: A Blueprint for Global Software SafetyBattle-Tested Incident Recovery: Lessons from the Front LinesThe AI Assistant’s Betrayal: One-Click for AI to Turn into the Perfect Insider
FIRST |

The Funny Story of Active Directory Backdooring

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER