Skip to main content
AD Academy
Advanced Attacks and Modern Defenses
Advanced14 minLast updated: Topic 3 of 4

ACL Abuse in Active Directory

GenericAll, WriteDACL, and quiet escalation paths.

Not read

What you will learn here

  • How ACL permissions become an attack path
  • What GenericAll and WriteDACL are
  • How to spot dangerous permissions

Worth reading first:Golden Ticket and Silver Ticket

Permissions carelessly granted on objects in are one of the most common escalation paths — and they require no technical vulnerability exploitation at all.

  • GenericAll — full control over the object (you can reset the password).
  • WriteDACL — lets you grant yourself any permission.
  • WriteOwner — lets you become the owner and then change permissions.
  • ForceChangePassword — resetting another user's password.
# ACL check on object
(Get-Acl "AD:\CN=Domain Admins,CN=Users,DC=lab,DC=local").Access |
  Where-Object { $_.ActiveDirectoryRights -match "GenericAll|WriteDacl|WriteOwner" }
powershell
Architecture and Theory — Under the Hood

Every object in carries a DACL — a list of permissions. 'Innocent' permissions like WriteDacl or GenericAll on a group allow a regular user to add themselves to Admins. This is a more common escalation path than any exploit.

  • GenericAll — full control over an object.
  • WriteDacl — modifying the permissions themselves.
  • WriteOwner — taking ownership and then changing everything.
  • ForceChangePassword — resetting another user's password.
  • AddMember — adding members to a group.
Practical Configuration (PowerShell / GUI)
# ACL check on critical group
(Get-Acl "AD:$( (Get-ADGroup 'Domain Admins').DistinguishedName )").Access |
  Where-Object { $_.ActiveDirectoryRights -match 'Write|GenericAll' }

# Remove suspicious permission
$acl = Get-Acl "AD:$( (Get-ADGroup 'Domain Admins').DistinguishedName )"
$acl.RemoveAccessRuleAll(($acl.Access | Where IdentityReference -eq 'CORP\bad_user'))
Set-Acl -Path "AD:$( (Get-ADGroup 'Domain Admins').DistinguishedName )" -AclObject $acl
powershell
Real-world scenarios in an organization
  • Helpdesk with ForceChangePassword on sensitive users = readily available escalation.
  • Forgotten OU with Everyone:GenericAll — a classic case of company mergers.
  • AdminSDHolder with unnecessary permissions — affects all protected accounts.
Troubleshooting and Diagnosis
  • Event 5136 — object modification (Directory Service Changes must be enabled).
  • Event 4728/4732 — adding a member to a global/local group.
  • AdminSDHolder is checked hourly (SDProp) — it restores permissions.
Glossary and Quick Command Line
  • DACL — Discretionary ACL.
  • SDProp — A process that applies AdminSDHolder.
  • — A free tool for mapping escalation paths.

Check yourself

What does the WriteDACL permission on an object allow?

Was this page helpful?