Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS reading, GPO abuse, and BloodHound-guided attack paths.
An offensive-security playbook for abusing misconfigured Active Directory access-control entries during authorized penetration testing. It focuses on the dangerous permissions attackers chain to escalate inside a domain — GenericAll, GenericWrite, WriteDACL, WriteOwner, ForceChangePassword, AddMember, AllExtendedRights, ReadLAPSPassword, and WriteSPN — and how each translates into concrete effects on users, groups, and computers.
Enumeration starts with BloodHound: collecting data via SharpHound from a domain-joined Windows host or bloodhound-python from Linux, choosing collection methods (DCOnly, Session, All with GPOLocalGroup), and running built-in queries such as shortest paths to Domain Admins from owned principals or principals with DCSync rights. A companion BLOODHOUND_PATHS reference is called out for Cypher queries and ingestion tips.
The exploitation sections give command-level recipes per ACE. GenericAll on a user can force a password change, set an SPN for targeted Kerberoasting, add shadow credentials with Whisker, or set a logon script; GenericAll or GenericWrite on a computer enables resource-based constrained delegation or shadow credentials via rbcd.py and pywhisker. WriteDACL grants the attacker DCSync rights (PowerView Add-DomainObjectAcl or Impacket dacledit.py); WriteOwner is a take-ownership-then-WriteDACL chain; ForceChangePassword is shown with rpcclient, PowerView, and net rpc; AddMember adds the attacker to privileged groups. The DCSync section documents the two required replication rights (DS-Replication-Get-Changes and DS-Replication-Get-Changes-All) and dumping hashes with secretsdump.py. Tooling spans SharpHound, PowerView, Impacket, Whisker/pywhisker, and rbcd/dacledit, and related routing points to Kerberos attacks, AD Certificate Services, NTLM relay/coercion, and lateral movement that commonly chain with ACL abuse. It is presented factually as a security-testing reference for authorized engagements.
Abuse of misconfigured Active Directory ACLs — dangerous ACEs like GenericAll, GenericWrite, WriteDACL, WriteOwner, and DCSync rights — during authorized penetration testing.
With BloodHound, collecting data via SharpHound on Windows or bloodhound-python on Linux and running built-in queries such as shortest paths to Domain Admins or principals with DCSync rights.
Forcing a password change, setting an SPN for targeted Kerberoasting, adding shadow credentials with Whisker, or setting a malicious logon script.
Both DS-Replication-Get-Changes and DS-Replication-Get-Changes-All on the domain object, after which hashes can be dumped with secretsdump.py.
SharpHound and BloodHound for enumeration, PowerView, Impacket (secretsdump.py, dacledit.py, rbcd.py), and Whisker/pywhisker for shadow credentials, among others.
Quick Setup:
.claude/skills/Repository
yaklang/hack-skills