[Speakers]
Adversary Village at
DEF CON 34

Nikos Vourdas

Senior Offensive Security Consultant

Nikos Vourdas, also known as nickvourd or NCV, is a Senior Offensive Security Consultant based in the US. With over five years of professional experience, he has actively participated in various global Tiber-EU and iCAST Red Teaming engagements. Regardless of his young age, Nikos has conducted full Red Teaming operations to major clients across retail, banking, shipping, construction industries. He holds OSCE3, OSCP, OSWP, CRTL, CRTO and OASP certifications. Also, he has previously presented at DEF CON, DevSecCon, and various BSides events around the world. Nikos loves contributing to open-source projects and always starts his day at 05:00 AM with a refreshing jog while listening to French rap music.

Yet Another Walking Dead of Active Directory

12:00-12:30 PDT | Friday, Aug 7th 2026 | DEF CON Creator Stage 3, Las Vegas Convention Center
Talk

Abstract

Disabled Active Directory accounts are commonly treated as harmless remnants of the past. In reality, many of these dead objects still retain dangerous inbound permissions, historical privilege artifacts, inherited ACL relationships, and hidden attack paths that most organizations never investigate.


This talk demonstrates how disabled users, computers, and service accounts can still become active participants in privilege escalation chains through misconfigured DACLs, AdminSDHolder side effects, nested group inheritance, and delegated permissions. Through a real-world inspired case study, attendees will learn how a seemingly low-privileged user leveraged hidden rights over a disabled account to move toward Domain Admin in a mature enterprise environment.


The presentation also introduces LazarusWakeUp, a tool designed to identify and analyze disabled Active Directory principals with dangerous inbound relationships, helping operators uncover hidden privilege escalation paths involving forgotten identities that traditional enumeration techniques and BloodHound analysis may overlook.


Additionally, the talk presents a new perspective on Active Directory Recycle Bin abuse and object resurrection, showing how deleted identities may continue to create security risks even after organizations believe they have been removed entirely.

Talk outline

0:00 – 6:00: Introduction - Dead Does Not Mean Safe
Topics:
- Disabled = harmless?
- ACLs vs authentication
- AdminSDHolder & adminCount
- Historical privilege artifacts
- Identity decay in enterprise environments


6:00 – 12:00: Real-World Inspired Case Study - Lazarus
Topics:
- Mature enterprise environment with minimal initial findings
- Discovery of a forgotten disabled account
- Hidden escalation chain involving legacy permissions
- Why standard enumeration initially missed the path


12:00 – 18:00: Dangerous DACL Rights & LazarusWakeUp
Topics:
- Core dangerous permissions
- Direct vs indirect object control
- Hidden BloodHound relationships
- Disabled user/computer/service abuse
- Introduction to LazarusWakeUp tool (Live demo)


18:00 – 23:00: AD Recycle Bin - The Dead That Return
Topics:
- Object restoration risks
- Restored ACL relationships
- SID history persistence
- Recovered privileged identities
- Identity resurrection attack surface


23:00 – 27:00: Defenses
Topics:
- Detecting account resurrection
- Event ID 4722
- Sigma detections
- Elastic/Kibana workflows
- Detection blind spots


27:00 – 30:00 Conclusions & Q&A

Agency.


Join Adversary Village Discord Server.

Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!