Active Directory Security Descriptors

How to work with Active Directory security descriptors (SDDL) for penetration testing and security assessments. Use this skill whenever the user mentions security descriptors, SDDL, ACL manipulation, WMI access, WinRM access, hash dumping, DAMP, or any technique related to modifying object permissions in Active Directory. Also trigger when users want to create persistence mechanisms, escalate privileges through ACL changes, or understand how security descriptors store permissions in Windows/AD environments.

abelrguezr Updated

File contents

abelrguezr/hacktricks-skills/tree/main/skills/windows-hardening/active-directory-methodology/security-descriptors commit 470dd36be9

Frequently asked questions

npx skillmds@latest add abelrguezr/active-directory-security-descriptors