Title:DMSA Link Attributes Modified Status:experimental Description:Detects modification of dMSA link attributes (msDS-ManagedAccountPrecededByLink) via PowerShell scripts.
This command line pattern could be an indicator an attempt to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025.
References: -https://www.akamai.com/blog/security-research/abusing-bad-successor-for-privilege-escalation-in-active-directory Author: Swachchhanda Shrawan Poudel (Nextron Systems) Date: 2025-05-24 modified:None Tags: