OpenAgentSkill Registry Manifest Skill: acl-abuse Slug: adscanpro-acl-abuse Category: productivity Description: Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that ACE, plus detection and remediation. DCSync is covered here strictly as a post-compromise technique, not a user entry path. Agent fit: - Decision: 67/100 Prototype first - Primary fit: Browser automation - Role: Fallback candidate Supply profile: - Track: Coding and developer agents - Scenario: Testing and QA - Applicable agents: Claude Code, CLI, Codex, Cursor - Maintenance: 12d since push - Risk: Needs review Trust: - Trust score: 77/100 Strong shortlist - Audit: 80/100 Needs review Attribution: - Status: Registry indexed - Source: github fast track - Creator: ADScanPro - Claim URL: https://www.openagentskill.com/skills/adscanpro-acl-abuse#claim-this-skill Install: npx skills add ADScanPro/Claude-AD --skill acl-abuse URLs: - Web: https://www.openagentskill.com/skills/adscanpro-acl-abuse - API: https://www.openagentskill.com/api/agent/skills/adscanpro-acl-abuse - Install API: https://www.openagentskill.com/api/skills/adscanpro-acl-abuse/install - Repository: https://github.com/ADScanPro/Claude-AD/tree/main/skills/acl-abuse