BigHugger
sk Skill · ADScanPro

acl-abuse

Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0

A reference skill that catalogs Active Directory ACL abuse techniques (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights for DCSync), mapping each to MITRE ATT&CK and to bloodyAD/impacket commands. It also covers detection via Event ID 5136 and remediation guidance for auditing non-default ACEs.

When BloodHound CE shows an outbound control edge from a principal you own, this gives you the exact command to weaponize that ACE plus detection and remediation notes.

Use it to

  • Weaponize a BloodHound outbound control edge with bloodyAD or impacket
  • Map an abused ACE to its MITRE ATT&CK technique
  • Set up detection using directory-modification event IDs
  • Write up remediation by auditing non-default ACEs
  • Perform DCSync as a post-compromise technique

For Penetration testers and red teamers working Active Directory

Host repository
ADScanPro/Claude-AD
Host stars
200
topicsactive-directoryacl-abuseprivilege-escalationlateral-movementdcsyncdetection