Privilege Escalation Commands
33 commands across 5 subcategories. Every entry lists the authentication material it needs, the protocols it speaks and links to upstream tool documentation.
ACL / DACL Abuse 10
- BloodyAD Add User to Group Add user to group using BloodyAD
- bloodyAD Grant DCSync Grant a target principal the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights…
- BloodyAD Set Object Owner Set object owner using BloodyAD
- Impacket badsuccessor Exploit the BadSuccessor vulnerability to escalate privileges via delegated Managed Service Accounts (dMSA)
- Impacket dacledit Read or write DACL entries on AD objects to grant or abuse ACL rights
- Impacket dacledit.py Read, write, or remove DACL ACEs on AD objects from Linux. Use to grant yourself GenericAll/WriteDacl over a…
- Impacket owneredit Read or rewrite the nTSecurityDescriptor owner of an AD object. Use after a WriteOwner edge to seize an…
- Impacket owneredit Change the owner of an AD object (WriteOwner abuse)
- NetExec LDAP BadSuccessor Check and exploit the BadSuccessor vulnerability via delegated Managed Service Accounts (dMSA)
- NetExec LDAP DACL Read Read DACL entries on an AD object to identify abusable ACL permissions
Delegation Abuse 9
- bloodyAD add badSuccessor Create a Delegated Managed Service Account (dMSA) and chain it via msDS-ManagedAccountPrecededByLink to a…
- bloodyAD Set RBCD Configure Resource-Based Constrained Delegation: write msDS-AllowedToActOnBehalfOfOtherIdentity on a target…
- Impacket Add Computer Create a new computer account in Active Directory (used for RBCD attacks)
- Impacket getST (S4U) Abuse constrained delegation or RBCD via S4U2Self/S4U2Proxy to impersonate a user
- Impacket RBCD Write Write msDS-AllowedToActOnBehalfOfOtherIdentity to configure RBCD on a target
- NetExec badsuccessor Module (dMSA Abuse) Detect BadSuccessor dMSA-link abuse: a Server 2025 delegated Managed Service Account whose…
- PyWhisker Shadow Credentials Add shadow credentials to a target account's msDS-KeyCredentialLink attribute
- RBCD Attack Configure Resource-Based Constrained Delegation (RBCD) on a target computer
- Rubeus S4U Delegation Abuse constrained delegation via S4U on Windows using Rubeus
GPO Abuse 2
- Force GPO Update Force Group Policy update
- SharpGPOAbuse Local Admin GPO abuse to add user as local admin
Local PrivEsc 4
- NetExec SMB Enum Impersonate Enumerate tokens and privileges available for impersonation on remote hosts
- NetExec SMB MS17-010 (EternalBlue) Check for MS17-010 (EternalBlue) vulnerability without credentials
- NetExec SMB PrintNightmare Exploit PrintNightmare (CVE-2021-1675/34527) to load a malicious DLL via the Print Spooler service
- NetExec SMB SMBGhost Check for SMBGhost (CVE-2020-0796) SMBv3 compression vulnerability without credentials
Trust Attacks 8
- Impacket goldenPac (MS14-068) Exploit MS14-068 Kerberos privilege escalation to obtain Domain Admin via forged PAC
- Impacket LookupSID Enumerate domain SIDs and discover trust relationships via SID brute-forcing
- Impacket raiseChild Escalate from child domain DA to forest root DA via inter-realm Kerberos trust
- Inter-Realm Golden Ticket Forge a cross-domain Golden Ticket to escalate from child to parent domain
- LDAPSearch Shadow Principals (PAM Trust) Enumerate msDS-ShadowPrincipal objects to identify PAM trust shadow principals
- NetExec LDAP Raise Child Escalate from child domain DA to forest root DA via inter-realm Kerberos trust abuse
- NetExec SMB NoPAC Check for and exploit the NoPAC (CVE-2021-42278/42287) Kerberos privilege escalation vulnerability
- NetExec SMB Zerologon Check for Zerologon (CVE-2020-1472) vulnerability — resets DC computer account password to empty