acl-abuse
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that…
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 0
A reference skill that catalogs Active Directory ACL abuse techniques (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights for DCSync), mapping each to MITRE ATT&CK and to bloodyAD/impacket commands. It also covers detection via Event ID 5136 and remediation guidance for auditing non-default ACEs.
When BloodHound CE shows an outbound control edge from a principal you own, this gives you the exact command to weaponize that ACE plus detection and remediation notes.
Use it to
- Weaponize a BloodHound outbound control edge with bloodyAD or impacket
- Map an abused ACE to its MITRE ATT&CK technique
- Set up detection using directory-modification event IDs
- Write up remediation by auditing non-default ACEs
- Perform DCSync as a post-compromise technique
For Penetration testers and red teamers working Active Directory
- Host repository
- ADScanPro/Claude-AD
- Host stars
- 201