Senior Offensive Security Consultant
Nikos Vourdas, also known as nickvourd or NCV, is a Senior Offensive Security Consultant based in the US. With over five years of professional experience, he has actively participated in various global Tiber-EU and iCAST Red Teaming engagements. Regardless of his young age, Nikos has conducted full Red Teaming operations to major clients across retail, banking, shipping, construction industries. He holds OSCE3, OSCP, OSWP, CRTL, CRTO and OASP certifications. Also, he has previously presented at DEF CON, DevSecCon, and various BSides events around the world. Nikos loves contributing to open-source projects and always starts his day at 05:00 AM with a refreshing jog while listening to French rap music.
12:00-12:30 PDT | Friday, Aug 7th 2026 | DEF CON Creator Stage 3, Las Vegas Convention Center Talk
Disabled Active Directory accounts are commonly treated as harmless remnants of the past. In reality, many of these dead objects still retain dangerous inbound permissions, historical privilege artifacts, inherited ACL relationships, and hidden attack paths that most organizations never investigate.
This talk demonstrates how disabled users, computers, and service accounts can still become active participants in privilege escalation chains through misconfigured DACLs, AdminSDHolder side effects, nested group inheritance, and delegated permissions. Through a real-world inspired case study, attendees will learn how a seemingly low-privileged user leveraged hidden rights over a disabled account to move toward Domain Admin in a mature enterprise environment.
The presentation also introduces LazarusWakeUp, a tool designed to identify and analyze disabled Active Directory principals with dangerous inbound relationships, helping operators uncover hidden privilege escalation paths involving forgotten identities that traditional enumeration techniques and BloodHound analysis may overlook.
Additionally, the talk presents a new perspective on Active Directory Recycle Bin abuse and object resurrection, showing how deleted identities may continue to create security risks even after organizations believe they have been removed entirely.
0:00 – 6:00: Introduction - Dead Does Not Mean Safe
Topics:
- Disabled = harmless?
- ACLs vs authentication
- AdminSDHolder & adminCount
- Historical privilege artifacts
- Identity decay in enterprise environments
6:00 – 12:00: Real-World Inspired Case Study - Lazarus
Topics:
- Mature enterprise environment with minimal initial findings
- Discovery of a forgotten disabled account
- Hidden escalation chain involving legacy permissions
- Why standard enumeration initially missed the path
12:00 – 18:00: Dangerous DACL Rights & LazarusWakeUp
Topics:
- Core dangerous permissions
- Direct vs indirect object control
- Hidden BloodHound relationships
- Disabled user/computer/service abuse
- Introduction to LazarusWakeUp tool (Live demo)
18:00 – 23:00: AD Recycle Bin - The Dead That Return
Topics:
- Object restoration risks
- Restored ACL relationships
- SID history persistence
- Recovered privileged identities
- Identity resurrection attack surface
23:00 – 27:00: Defenses
Topics:
- Detecting account resurrection
- Event ID 4722
- Sigma detections
- Elastic/Kibana workflows
- Detection blind spots
27:00 – 30:00 Conclusions & Q&A
Agency.
Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!