WriteDACL
Last updated
Was this helpful?
Last updated
Was this helpful?
With write access to the target object’s DACL, you can grant yourself any privilege you want on the object.
Grant yourself full control of the group -> Add members to the group (see ).
Grant yourself full control of the user -> See here for exploitation options.
Grant yourself full control of the computer -> read the LAPS password or perform RBCD against the target computer.
Then some options are
Grant yourself DCSync rights -> perform a DCSync attack.
Grant yourself full control of the GPO -> edit the GPO to take over an object the GPO applies to.
Grant yourself full control of the OU -> Add a new ACE to the OU that inherits down to child objects to take over those child objects.