Skip to content
Back to skills

Ad Dacl Abuse

ASecurity

Abuse Active Directory object ACLs/DACLs for lateral movement and escalation — GenericAll, WriteDACL, GenericWrite, WriteOwner, AddMember, ForceChangePassword, and DCSync rights. Load with domain creds + BloodHound showing an ACL edge, on "GenericAll", "WriteDACL", "DCSync", "abuse this edge".

  • 20 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 22, 2026
ai-agentsgo

Security analysis

A100/100

Scanned September 22, 2026

npx -y skills add NoorQureshi/SploitAgent --skill ad-dacl-abuse --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ad Dacl Abuse?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ad Dacl Abuse
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-ad-dacl-abuse/badge)](https://www.skillsdirectory.com/skills/noorqureshi-ad-dacl-abuse)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ad-dacl-abuse
description: >
  Abuse Active Directory object ACLs/DACLs for lateral movement and escalation — GenericAll,
  WriteDACL, GenericWrite, WriteOwner, AddMember, ForceChangePassword, and DCSync rights. Load with
  domain creds + BloodHound showing an ACL edge, on "GenericAll", "WriteDACL", "DCSync", "abuse this edge".
domain: ad
type: technique
stability: learning
modes: [pentest]
severity: high
mitre: [T1222, T1098, T1003.006]
cwe: [CWE-284, CWE-269]
tools: [bloodhound, netexec, impacket, powerview]
schema_version: 1
---

# AD ACL / DACL abuse

## When it applies
You have domain creds and BloodHound shows your principal (or one you control) has a dangerous
**ACL edge** over another object — a user, group, computer, GPO, or the domain. These edges chain
into a path to Domain Admin without any CVE.

## Why it works
AD access control is a web of object permissions. Over-permissive ACLs let you *modify* other
principals: reset a password, add yourself to a privileged group, take ownership then rewrite the
DACL, or grant yourself DCSync — each turning a small right into control.

## Method — abuse per edge (BloodHound names the edge; it also shows the command)
1. **ForceChangePassword** over a user → reset their password: `net rpc password` / `bloodyAD set password`.
2. **GenericWrite / GenericAll over a user** → set an SPN and Kerberoast, or set `msDS-KeyCredentialLink`
   (shadow credentials, `certipy shadow`/`pywhisker`) → auth as them.
3. **AddMember / GenericAll over a group** → add yourself to it (e.g. a privileged group): `net group ... /add`.
4. **WriteDACL / WriteOwner over an object** → take ownership, grant yourself GenericAll, then abuse as above.
5. **DCSync rights** (GetChanges/GetChangesAll on the domain) → `impacket-secretsdump -just-dc` to
   dump all hashes incl. krbtgt (→ golden ticket).
6. **GPO edit rights** → push a scheduled task/immediate task to hosts the GPO applies to → RCE.

## Gotchas
- Let BloodHound plan the *path* — abuse edges in order; each step unlocks the next.
- Shadow credentials (KeyCredentialLink) need a 2016+ DC with PKINIT — often cleaner than a password reset (less noisy, reversible).
- Clean up: remove added group memberships / added creds after proving impact.

## Verify success
Control of the target principal (password/hash/TGT), membership in a privileged group, or a hash
dump via DCSync — advancing the path toward DA.

## References
SpecterOps BloodHound docs (edge abuse); harmj0y "ACL attacks"; impacket/bloodyAD.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…