acl-abuse - Exploit Active Directory ACLs for privilege escalation
Exploits misconfigured Active Directory ACLs to identify and execute privilege-escalation paths using Kerberos-based techniques.
Tags
Updated: 2026-10-06Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Enumerate exploitable ACLs
- Analyze BloodHound attack paths
- Manipulate Active Directory permissions
- Add shadow credentials
- Authenticate through PKINIT
- Manipulate service principal names
- Request Kerberos service tickets
- Reset user passwords
- Modify group membership
- Grant DCSync rights
- Record engagement evidence
- Clean up temporary changes
Inputs
- Written authorization
- Domain credentials
- Active Directory domain
- Domain controller address
- Identified ACL misconfiguration
- BloodHound attack paths
- Engagement directory
- Engagement state
Outputs
- Activation message
- ACL findings
- Discovered hosts and services
- Credentials or tokens
- Privilege changes
- Confirmed vulnerabilities
- Pivot paths
- Blocked items
- Evidence files
- Kerberos tickets
- Credential hashes
- Temporary ACL changes
Requirements
- Explicit written authorization
- bloodyAD
- Impacket suite
- Kerberos ccache
- Optional PowerView
- Optional pywhisker
- Optional Certipy
- Optional dacledit.py
- State MCP server
- Windows Server 2016+ for shadow credentials
- AD CS and PKINIT for shadow credentials
