Who holds the keys to the kingdom?

Written by

in

Your company is the target of a cyber attack. What does that look like?

For a long time, it went something like this:

  • Compromise of a workstation
  • Elevation of privileges
  • Lateral movement
  • Compromise of Domain Admin
  • Own the enterprise

The “Holy Grail” for the attacker was Domain Admin. The one account that was guaranteed to have access to everything, everywhere, either directly, or by virtue of being able to manage account and machines across the entire estate.

But is this still true? The answer may seem like a clear “no”, but who actually does hold the keys to kingdom in 2026?

The Domain Administrator wasn’t just that person that looked after your IT. The Domain Admin account had control over authentication, workstations, servers, Group Policy, software deployment, and user management. The objective was never really to get access to the DA account. The objective was control. DA was a convenient place to find it.

Control over various domains has shifted in recent years. Some of these shifts have been obvious, such as the move of Identity to platforms such as Entra ID and Okta. Some may be less obvious as a source of authority, such as control of application source code through GitHub or Azure DevOps.

Authority in the modern enterprise is fragmented across numerous control planes, each entrusted with administering a different aspect of the organisation, from identity and endpoints to cloud infrastructure and software delivery.

Rather than targeting the route of workstation compromise, elevation of privileges, lateral movement and domain, attackers are targeting the systems that already posses the authority that they need.

Recent vulnerabilities affecting Cisco FMC, N-central and Artifcatory lead to compromise of not just another server, but a platform trusted to administer infrastructure, manage endpoints or distribute software throughout the enterprise.

In a recent attack on Coder’s registry infrastructure, attackers gained access to the platform responsible for distributing Terraform modules to customer environments. Rather than targeting individual workstations or attempting to gain Domain Admin privileges, the attackers targeted a trusted component of the software delivery process itself. By compromising a platform responsible for provisioning infrastructure and development environments, they gained access to cloud credentials, CI/CD secrets and other privileged artefacts. The objective was achieved through compromise of a trusted delivery mechanism rather than through traditional privilege escalation within the target environment.

So what does this mean for you as the owner of these systems?

It raises a number of uncomfortable questions:

  • What systems can make changes to other systems?
  • Which platforms can deploy code?
  • Which platforms can create identities?
  • Which platforms can access business-critical data?
  • Which platforms could perform organisation-wide actions without Domain Admin?

These are the platforms that should form your real Tier 0 environment.

Domain Admin was never the objective. Authority was. For many organisations, authority now lives across identity platforms, management systems, cloud control planes and software supply chains. Attackers appear to have noticed. The question is whether defenders have.

If an attacker gained control of just one platform in your organisation, which platform would give them the greatest ability to affect every other system?