Hunting Active Directory Acl Abuse Paths

Hunt privilege escalation through Active Directory object permission abuse, where a low-privileged principal holds a right over a more privileged object, letting it reset a password, add itself to a group, set a delegation or logon script, write a service principal name, or take ownership and rewrite the object's permissions, chaining one granted right into control of a higher-privileged account. Use when directory object permissions may grant a standard user a write over a privileged user, group, computer, or organizational unit. Covers force-password-reset, group membership writes, generic-write and write-owner abuse, and delegated control chains. The low-privileged right over a privileged object is the source, the directory operation that right authorizes is the sink, and gaining control of the higher-privileged account is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-active-directory-acl-abuse-paths commit 99a610c95f

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-active-directory-acl-abuse-paths