The clearest signs are unusual reads of KDS root key attributes by accounts that are not domain controllers, especially access to msKds-RootKeyData. Defenders should also watch for abnormal logon activity tied to gMSA accounts and security event 4662 on domain controllers when the object type is msKds-ProvRootKey. Those signals indicate an attempt to enumerate or dump root key material.
How to recognise a Golden GMSA attack in progress
The most reliable early warning is access to msKds-RootKeyData or related KDS root key attributes by principals that should not be touching them, especially anything that is not a domain controller. That activity is unusual because Golden GMSA tradecraft depends on enumerating or dumping root key material, not normal gMSA use.
When the attack is underway, defenders often see it paired with abnormal logon patterns involving gMSA accounts. That combination matters because the attacker is usually trying to move from curiosity about the directory structure to usable secret material.
On domain controllers, event 4662 becomes especially important when the object type is msKds-ProvRootKey. In practice, that is the event most likely to surface attempts to read or probe the KDS root key object directly, which is the critical step before offline abuse.
What the activity pattern usually looks like
Golden GMSA attacks are not usually noisy at first. The operator is often testing directory visibility, object permissions, and whether the environment leaks enough KDS data to reconstruct gMSA secrets. That means the pattern can begin as legitimate-looking directory access and only later reveal itself through escalation into root key reads.
The practical distinction is between ordinary gMSA consumption and suspicious gMSA investigation. Normal systems use gMSA material to authenticate services. Suspicious activity is more likely to involve reads against the root key container, enumeration of attributes tied to KDS, and access from accounts that do not need that level of directory visibility.
A useful signal is correlation. A single access event may be ambiguous, but repeated reads, unusual account context, and nearby logon anomalies raise confidence that the actor is not simply administering a service account. That is the point where defenders should treat the activity as a likely precursor to credential extraction rather than a one-off directory query.
Why these signals matter operationally
The main issue is blast radius. If an attacker can obtain KDS root key material, they can work toward deriving or abusing gMSA secrets across systems that trust that directory root. That makes early detection important, because the attacker does not need broad endpoint noise once the directory-level material is obtained.
Detection also depends on good baselining. In mature environments, domain controllers will generate directory-read events for many reasons, so defenders need to know what normal gMSA administration looks like, which accounts should ever read KDS objects, and which logon patterns are expected for each service account population.
For broader attack context, the relevant control problem is privilege and secret access, not just authentication. If the directory exposes the wrong object to the wrong principal, the attack can progress quietly until the resulting secrets are reused elsewhere. That is why the earliest indicators are usually access anomalies, not obvious service disruption.
Risk and Threat Considerations
Golden GMSA activity is dangerous because it targets a high-value secret source inside Active Directory. Once the attacker can read or reconstruct root key material, the compromise can spread from a single directory object to multiple services that rely on generated managed passwords.
Failure mechanism: Excessive directory-read privilege, weak monitoring of KDS-related objects, or suspicious access from non-controller accounts allows an attacker to enumerate or dump root key material before defenders notice the misuse.
Impact: The attacker can pivot from directory reconnaissance to credential abuse across gMSA-backed services, increasing the chance of lateral movement, persistence, and broad operational compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1552 — Unsecured Credentials | Root key reads and secret dumping map to credential access behavior. |
| Recommendation — Correlate directory-read anomalies with credential access tradecraft and investigate for secret dumping. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Event 4662 and unusual directory reads require review and correlation to spot abuse. |
| AC-6 — Least Privilege | Only tightly scoped principals should read KDS root key material or related attributes. | |
| IA-5 — Authenticator Management | Golden GMSA abuse targets secret material used to authenticate service accounts. | |
| Recommendation — Review and correlate directory audit events for suspicious KDS object access. Restrict KDS root key read access to the minimum set of authorized controllers. Protect, rotate, and monitor service-account secrets used for gMSA authentication. | ||
Practitioner Guidance
What to verify: Confirm which principals are permitted to read KDS root key objects and compare that list with actual readers in your logs. Any non-controller access to msKds-RootKeyData or msKds-ProvRootKey should be treated as a review item, not normal background activity.
Decision rule: If the activity involves repeated root-key reads plus abnormal gMSA logons, escalate as a likely secret-extraction attempt even if no service failure is visible yet. The absence of outage does not mean the attacker has not already acquired useful material.
Practitioner takeaway: In this attack, the best signal is not a failed login, it is unauthorized curiosity about the objects that generate trust. Hunt the read path to the root key, not just the use of the resulting accounts.
Related resources from NHI Mgmt Group
- What are the signs that a Golden Ticket attack may be underway in Active Directory?
- What are the signs that an identity attack is underway even when there is no obvious service outage?
- What are the signs that a deepfake attack is underway during customer verification?
- What are the signs that a credential stuffing attack is underway in identity provider logs?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org