Join our Newsletter — 33% off our NHI Course
Home› Glossary› Threats, Abuse & Incident Response› Zero Logon Attack
Threats, Abuse & Incident Response

Zero Logon Attack

← Back to Glossary
By NHI Mgmt Group Updated September 27, 2026 Domain: Threats, Abuse & Incident Response

A Zero Logon attack is an exploit against the Netlogon protocol that can force a domain controller password to an empty value. Once the controller is compromised, an attacker may gain broad control over Active Directory and use that access to move to other systems in the environment.

How Zero Logon Works

Zero Logon is a Netlogon protocol weakness that lets an attacker abuse insecure cryptographic negotiation between a client and a domain controller. In the successful case, the attacker can make the controller accept an all-zero session key and then impersonate the machine account.

This matters because Netlogon is part of the trust fabric between domain-joined systems and Active Directory. When that trust is broken, the attacker is no longer limited to a single host or user, but can start operating as if they were a trusted domain participant.

Why It Becomes So Dangerous in Active Directory

The core danger is not just protocol abuse, but what the protocol protects. A compromised domain controller can expose password reset paths, authentication decisions, directory objects, and administrative trust relationships across the environment.

That is why Zero Logon is usually discussed as an identity compromise pattern with broad blast radius: once the controller is compromised, the attacker may be able to pivot into broader Active Directory control and then reuse that access for lateral movement.

Where the Attack Sits in the Kill Chain

Zero Logon is often a foothold, not the end state. After gaining control of the domain controller relationship, an attacker can use that position to escalate privileges, modify trust settings, dump sensitive directory material, and stage follow-on activity against other systems.

That makes the technique especially valuable to intruders who want stealthy, high-privilege access rather than noisy malware. It can support intrusion persistence, credential harvesting, and downstream compromise of servers, endpoints, and administrative accounts.

Defensive Meaning for Domain-Joined Environments

For defenders, the key issue is that the vulnerable surface sits in a trusted internal protocol, not in an obvious internet-facing application. Exposure therefore depends on patch status, domain controller hardening, and whether older or noncompliant systems are still allowed to negotiate insecure Netlogon behavior.

Zero Logon is a reminder that trust relationships inside the directory are security boundaries. If those boundaries are weak, one protocol flaw can turn into enterprise-wide compromise, especially where privileged administration is centralized.

Risk and Threat Considerations

Zero Logon creates a high-severity trust and privilege risk because successful exploitation can convert a protocol flaw into domain-level compromise. The concern is not just unauthorized access to one controller, but the attacker’s ability to use that position for broad directory control, persistence, and lateral movement.

Failure mechanism: The attacker abuses weak Netlogon authentication behavior to force acceptance of an all-zero credential state, then leverages the trusted controller relationship to impersonate a machine account and extend control across Active Directory.

Impact: A compromised domain controller can undermine authentication, authorization, and administrative trust across the environment, creating a path to widespread takeover of systems and directory-managed assets.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Zero Logon undermines authenticated trust in domain access paths.
IA-5 — Authenticator ManagementThe attack abuses credentials and machine trust material in Netlogon.
AC-6 — Least PrivilegeDomain compromise turns excessive privilege into broad environment takeover.
Recommendation — Enforce strong organizational authentication and monitor for trust relationship abuse. Harden credential lifecycle controls and rotate or invalidate compromised authenticators promptly. Restrict privileged access paths so one compromise cannot control the directory.
MITRE ATT&CKT1078 — Valid AccountsAttackers exploit trusted account or machine-authentication paths after compromise.
T1550 — Use Alternate Authentication MaterialThe exploit abuses authentication material to impersonate a trusted domain participant.
Recommendation — Hunt for misuse of trusted accounts and machine identities after authentication abuse. Detect alternate-authentication abuse and validate unexpected trust delegation.

Practitioner Guidance

Why practitioners should care: Treat this as a domain-control emergency class issue, not a single-host vulnerability. Once a domain controller or equivalent trust anchor is compromised, the response scope usually expands to directory integrity, privileged access review, and compromise assessment across the estate.

What to watch for: Pay attention to indicators that a controller or machine trust relationship has been abused, especially unexpected password resets, abnormal Netlogon behavior, or signs that domain-level privileges were used to touch multiple systems in quick succession.

Practitioner takeaway: The most important question is not whether the exploit worked on one controller, but whether any trust relationship it touched has already been used to move deeper into the directory.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org