Skip to main content

Overview

AD objects have DACLs (Discretionary Access Control Lists) controlling access. Misconfigured ACLs grant powerful privileges to low-privilege users.

Dangerous ACEs


Find Dangerous ACLs

PowerView

BloodHound

Edges: GenericAll, WriteDacl, WriteOwner, ForceChangePassword, AddMember.

Exploit — GenericAll on User

Reset Password

Set SPN (Targeted Kerberoasting)


Exploit — GenericAll on Group


Exploit — GenericAll on Computer


Exploit — WriteDacl

Grant yourself DCSync rights:
Then DCSync:

Exploit — WriteOwner


Exploit — ForceChangePassword


ACL Persistence

Add Hidden DCSync Rights

Add GenericAll on Domain Admins


Quick Reference