Analyzing Active Directory ACL Abuse
Overview
Active Directory Access Control Lists (ACLs) define permissions on AD objects through Discretionary Access Control Lists (DACLs) containing Access Control Entries (ACEs). Misconfigured ACEs can grant non-privileged users dangerous permissions such as GenericAll (full control), WriteDACL (modify permissions), WriteOwner (take ownership), and GenericWrite (modify attributes) on sensitive objects like Domain Admins groups, domain controllers, or GPOs.
This skill uses the ldap3 Python library to connect to a Domain Controller, query objects with their nTSecurityDescriptor attribute, parse the binary security descriptor into SDDL (Security Descriptor Definition Language) format, and identify ACEs that grant dangerous permissions to non-administrative principals. These misconfigurations are the basis for ACL-based attack paths discovered by tools like BloodHound.
When to Use
- When investigating security incidents that require analyzing active directory acl abuse
- When building detection rules or threat hunting queries for this domain
- When SOC analysts need structured procedures for this analysis type
- When validating security monitoring coverage for related attack techniques
Detection Gaps & Validation
- Edges BloodHound under-collects: default
SharpHound collection misses ACEs on ADCS objects (Enroll/WriteProperty on certificate templates → ESC1-ESC7), GPO-linked OUs, and gMSA/msDS-ManagedPassword read rights. Run Get-DomainObjectAcl -ResolveGUIDs (PowerView) and compare ACE counts against the BloodHound graph.
- Extended-rights blind spots: access masks like
ADS_RIGHT_DS_CONTROL_ACCESS (0x100) gate User-Force-Change-Password and DS-Replication-Get-Changes-All (DCSync). A GenericAll filter that only checks 0x10000000 misses these GUID-scoped ACEs — match the ObjectType GUID, not just the mask.
- Inherited vs explicit: abusable ACEs are often inherited from a parent OU; tooling that only reads
IsInherited=False ACEs misses them. Walk the inheritance chain and flag INHERITED_ACE entries too.
- Deny ACE ordering: a permissive Allow after a Deny still loses, but canonicalization bugs and shadow-credentials (
msDS-KeyCredentialLink WriteProperty) bypass intent — validate with Test-ADCanonicalAcl.
- How to confirm a hit: prove the path, don't just report the ACE. For
GenericAll on a user, confirm a password reset or shadow-credential add in a lab; for WriteDacl on a group, add an ACE then self to the group and verify token group membership with whoami /groups. Cross-check the SID is not a tier-0 principal before flagging.
Prerequisites
- Python 3.9 or later with ldap3 library (
pip install ldap3)
- Domain user credentials with read access to AD objects
- Network connectivity to Domain Controller on port 389 (LDAP) or 636 (LDAPS)
- Understanding of Active Directory security model and SDDL format
Steps
Connect to Domain Controller: Establish an LDAP connection using ldap3 with NTLM or simple authentication. Use LDAPS (port 636) for encrypted connections in production.
Query target objects: Search the target OU or entire domain for objects including users, groups, computers, and OUs. Request the nTSecurityDescriptor, distinguishedName, objectClass, and sAMAccountName attributes.
Parse security descriptors: Convert the binary nTSecurityDescriptor into its SDDL string representation. Parse each ACE in the DACL to extract the trustee SID, access mask, and ACE type (allow/deny).
Resolve SIDs to principals: Map security identifiers (SIDs) to human-readable account names using LDAP lookups against the domain. Identify well-known SIDs for built-in groups.
Check for dangerous permissions: Compare each ACE's access mask against dangerous permission bitmasks: GenericAll (0x10000000), WriteDACL (0x00040000), WriteOwner (0x00080000), GenericWrite (0x40000000), and WriteProperty for specific extended rights.
Filter non-admin trustees: Exclude expected administrative trustees (Domain Admins, Enterprise Admins, SYSTEM, Administrators) and flag ACEs where non-privileged users or groups hold dangerous permissions.
Map attack paths: For each finding, document the potential attack chain (e.g., GenericAll on user allows password reset, WriteDACL on group allows adding self to group).
Generate remediation report: Output a JSON report with all dangerous ACEs, affected objects, non-admin trustees, and recommended remediation steps.
Expected Output
{
"domain": "corp.example.com",
"objects_scanned": 1247,
"dangerous_aces_found": 8,
"findings": [
{
"severity": "critical",
"target_object": "CN=Domain Admins,CN=Users,DC=corp,DC=example,DC=com",
"target_type": "group",
"trustee": "CORP\\helpdesk-team",
"permission": "GenericAll",
"access_mask": "0x10000000",
"ace_type": "ACCESS_ALLOWED",
"attack_path": "GenericAll on Domain Admins group allows adding arbitrary members",
"remediation": "Remove GenericAll ACE for helpdesk-team on Domain Admins"
}
]
}
1---2name: analyzing-active-directory-acl-abuse3description: Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths4license: Apache-2.05---6
7
8# Analyzing Active Directory ACL Abuse
9
10## Overview
11
12Active Directory Access Control Lists (ACLs) define permissions on AD objects through Discretionary Access Control Lists (DACLs) containing Access Control Entries (ACEs). Misconfigured ACEs can grant non-privileged users dangerous permissions such as GenericAll (full control), WriteDACL (modify permissions), WriteOwner (take ownership), and GenericWrite (modify attributes) on sensitive objects like Domain Admins groups, domain controllers, or GPOs.
13
14This skill uses the ldap3 Python library to connect to a Domain Controller, query objects with their nTSecurityDescriptor attribute, parse the binary security descriptor into SDDL (Security Descriptor Definition Language) format, and identify ACEs that grant dangerous permissions to non-administrative principals. These misconfigurations are the basis for ACL-based attack paths discovered by tools like BloodHound.
15
16
17## When to Use
18
19- When investigating security incidents that require analyzing active directory acl abuse
20- When building detection rules or threat hunting queries for this domain
21- When SOC analysts need structured procedures for this analysis type
22- When validating security monitoring coverage for related attack techniques
23
24## Detection Gaps & Validation
25
26- **Edges BloodHound under-collects:** default `SharpHound` collection misses ACEs on ADCS objects (`Enroll`/`WriteProperty` on certificate templates → ESC1-ESC7), GPO-linked OUs, and `gMSA`/`msDS-ManagedPassword` read rights. Run `Get-DomainObjectAcl -ResolveGUIDs` (PowerView) and compare ACE counts against the BloodHound graph.
27- **Extended-rights blind spots:** access masks like `ADS_RIGHT_DS_CONTROL_ACCESS` (0x100) gate `User-Force-Change-Password` and `DS-Replication-Get-Changes-All` (DCSync). A `GenericAll` filter that only checks 0x10000000 misses these GUID-scoped ACEs — match the ObjectType GUID, not just the mask.
28- **Inherited vs explicit:** abusable ACEs are often inherited from a parent OU; tooling that only reads `IsInherited=False` ACEs misses them. Walk the inheritance chain and flag `INHERITED_ACE` entries too.
29- **Deny ACE ordering:** a permissive Allow after a Deny still loses, but canonicalization bugs and shadow-credentials (`msDS-KeyCredentialLink` WriteProperty) bypass intent — validate with `Test-ADCanonicalAcl`.
30- **How to confirm a hit:** prove the path, don't just report the ACE. For `GenericAll` on a user, confirm a password reset or shadow-credential add in a lab; for `WriteDacl` on a group, add an ACE then self to the group and verify token group membership with `whoami /groups`. Cross-check the SID is not a tier-0 principal before flagging.
31
32## Prerequisites
33
34- Python 3.9 or later with ldap3 library (`pip install ldap3`)
35- Domain user credentials with read access to AD objects
36- Network connectivity to Domain Controller on port 389 (LDAP) or 636 (LDAPS)
37- Understanding of Active Directory security model and SDDL format
38
39## Steps
40
411. **Connect to Domain Controller**: Establish an LDAP connection using ldap3 with NTLM or simple authentication. Use LDAPS (port 636) for encrypted connections in production.
42
432. **Query target objects**: Search the target OU or entire domain for objects including users, groups, computers, and OUs. Request the `nTSecurityDescriptor`, `distinguishedName`, `objectClass`, and `sAMAccountName` attributes.
44
453. **Parse security descriptors**: Convert the binary nTSecurityDescriptor into its SDDL string representation. Parse each ACE in the DACL to extract the trustee SID, access mask, and ACE type (allow/deny).
46
474. **Resolve SIDs to principals**: Map security identifiers (SIDs) to human-readable account names using LDAP lookups against the domain. Identify well-known SIDs for built-in groups.
48
495. **Check for dangerous permissions**: Compare each ACE's access mask against dangerous permission bitmasks: GenericAll (0x10000000), WriteDACL (0x00040000), WriteOwner (0x00080000), GenericWrite (0x40000000), and WriteProperty for specific extended rights.
50
516. **Filter non-admin trustees**: Exclude expected administrative trustees (Domain Admins, Enterprise Admins, SYSTEM, Administrators) and flag ACEs where non-privileged users or groups hold dangerous permissions.
52
537. **Map attack paths**: For each finding, document the potential attack chain (e.g., GenericAll on user allows password reset, WriteDACL on group allows adding self to group).
54
558. **Generate remediation report**: Output a JSON report with all dangerous ACEs, affected objects, non-admin trustees, and recommended remediation steps.
56
57## Expected Output
58
59```json
60{
61 "domain": "corp.example.com",
62 "objects_scanned": 1247,
63 "dangerous_aces_found": 8,
64 "findings": [
65 {
66 "severity": "critical",
67 "target_object": "CN=Domain Admins,CN=Users,DC=corp,DC=example,DC=com",
68 "target_type": "group",
69 "trustee": "CORP\\helpdesk-team",
70 "permission": "GenericAll",
71 "access_mask": "0x10000000",
72 "ace_type": "ACCESS_ALLOWED",
73 "attack_path": "GenericAll on Domain Admins group allows adding arbitrary members",
74 "remediation": "Remove GenericAll ACE for helpdesk-team on Domain Admins"
75 }
76 ]
77}
78```