Acl Abuse

Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that ACE, plus detection and remediation. DCSync is covered here strictly as a post-compromise technique, not a user entry path.

ADScanPro e055fa6 10.2 KB Updated

File contents

ADScanPro/Claude-AD/tree/main/skills/acl-abuse commit e055fa6714

Frequently asked questions

npx skillmds@latest add adscanpro/acl-abuse