ACL / DACL Abuse Commands
10 ACL / DACL Abuse commands from the Privilege Escalation category, each with its placeholders, supported authentication methods and upstream references.
Tools covered: bloodyAD, impacket-badsuccessor, impacket-dacledit, impacket-owneredit, nxc
- BloodyAD Add User to Group Add user to group using BloodyAD
- bloodyAD Grant DCSync Grant a target principal the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights…
- BloodyAD Set Object Owner Set object owner using BloodyAD
- Impacket badsuccessor Exploit the BadSuccessor vulnerability to escalate privileges via delegated Managed Service Accounts (dMSA)
- Impacket dacledit Read or write DACL entries on AD objects to grant or abuse ACL rights
- Impacket dacledit.py Read, write, or remove DACL ACEs on AD objects from Linux. Use to grant yourself GenericAll/WriteDacl over a…
- Impacket owneredit Read or rewrite the nTSecurityDescriptor owner of an AD object. Use after a WriteOwner edge to seize an…
- Impacket owneredit Change the owner of an AD object (WriteOwner abuse)
- NetExec LDAP BadSuccessor Check and exploit the BadSuccessor vulnerability via delegated Managed Service Accounts (dMSA)
- NetExec LDAP DACL Read Read DACL entries on an AD object to identify abusable ACL permissions