Acl Abuse

Exploits misconfigured Active Directory ACLs for privilege escalation. Covers GenericAll, GenericWrite, WriteDACL, WriteOwner, ForceChangePassword, targeted Kerberoasting via SPN manipulation, shadow credentials (msDS-KeyCredentialLink → PKINIT), and AdminSDHolder persistence.

blacklanternsecurity 2546942 19.1 KB Updated

File contents

blacklanternsecurity/red-run/tree/main/skills/ad/acl-abuse commit 25469429f0

Frequently asked questions

npx skillmds@latest add blacklanternsecurity/acl-abuse