LogoAwesome Skills
  • Search
  • Category
  • Tag
  • Blog
LogoAwesome Skills
LogoAwesome Skills

Discover Open-Source Agent Skills for AI Coding Assistants

Product

  • Search
  • Category
  • Tag
  • Blog

Resources

  • Claude Skill Docs
  • Antigravity Skills Docs

Tools

  • Claude Code
  • OpenCode
  • Cursor
  • Codex
  • Antigravity

Company

  • Privacy Policy
  • Terms of Service
  • Sitemap

©2026 Awesome Skills. All rights reserved.

Privacy PolicyTerms
Back to Skills

active-directory-acl-abuse

Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS reading, GPO abuse, and BloodHound-guided attack paths.

1,297stars177forksUpdated 7/7/2026
Security#security#active-directory#penetration-testing#privilege-escalation#windows

Security Assessment

Safe(100/100)
Security Score100/100

About active-directory-acl-abuse

An offensive-security playbook for abusing misconfigured Active Directory access-control entries during authorized penetration testing. It focuses on the dangerous permissions attackers chain to escalate inside a domain — GenericAll, GenericWrite, WriteDACL, WriteOwner, ForceChangePassword, AddMember, AllExtendedRights, ReadLAPSPassword, and WriteSPN — and how each translates into concrete effects on users, groups, and computers.

Enumeration starts with BloodHound: collecting data via SharpHound from a domain-joined Windows host or bloodhound-python from Linux, choosing collection methods (DCOnly, Session, All with GPOLocalGroup), and running built-in queries such as shortest paths to Domain Admins from owned principals or principals with DCSync rights. A companion BLOODHOUND_PATHS reference is called out for Cypher queries and ingestion tips.

The exploitation sections give command-level recipes per ACE. GenericAll on a user can force a password change, set an SPN for targeted Kerberoasting, add shadow credentials with Whisker, or set a logon script; GenericAll or GenericWrite on a computer enables resource-based constrained delegation or shadow credentials via rbcd.py and pywhisker. WriteDACL grants the attacker DCSync rights (PowerView Add-DomainObjectAcl or Impacket dacledit.py); WriteOwner is a take-ownership-then-WriteDACL chain; ForceChangePassword is shown with rpcclient, PowerView, and net rpc; AddMember adds the attacker to privileged groups. The DCSync section documents the two required replication rights (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) and dumping hashes with secretsdump.py. Tooling spans SharpHound, PowerView, Impacket, Whisker/pywhisker, and rbcd/dacledit, and related routing points to Kerberos attacks, AD Certificate Services, NTLM relay/coercion, and lateral movement that commonly chain with ACL abuse. It is presented factually as a security-testing reference for authorized engagements.

FAQ

What does this skill help test?

Abuse of misconfigured Active Directory ACLs — dangerous ACEs like GenericAll, GenericWrite, WriteDACL, WriteOwner, and DCSync rights — during authorized penetration testing.

How is attack-path enumeration done?

With BloodHound, collecting data via SharpHound on Windows or bloodhound-python on Linux and running built-in queries such as shortest paths to Domain Admins or principals with DCSync rights.

What can GenericAll on a user account be used for?

Forcing a password change, setting an SPN for targeted Kerberoasting, adding shadow credentials with Whisker, or setting a malicious logon script.

What rights are required for a DCSync attack?

Both DS-Replication-Get-Changes and DS-Replication-Get-Changes-All on the domain object, after which hashes can be dumped with secretsdump.py.

Which tools does it reference?

SharpHound and BloodHound for enumeration, PowerView, Impacket (secretsdump.py, dacledit.py, rbcd.py), and Whisker/pywhisker for shadow credentials, among others.

All Files

2 files
SKILL.md9.2 KB
View
BLOODHOUND_PATHS.md6.8 KB
View

Install active-directory-acl-abuse

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill

Repository

yaklang/hack-skills

Related Skills

referral-program

2,132

agentmail-cli

22

codex

3,038

content-modeling

192