Rights Abuse
Rights Abuse - using ACLs
It is dangerous as MDI detect the activity when we do DCSync using this.
We make changes to the Domain Object ACL, which gives 4662 logs with a message (write DACL perform on the object) which will be visible in Security Logs.
There are even more interesting ACLs which can be abused.
For example, with DA privileges, the ACL for the domain root can be modified to provide useful rights like FullControl or the ability to run "DCSync".
Add FullControl rights -
Using ActiveDirectory Module and RACE -
Add rights for DCSync -
Execute DCSync -
Rights Abuse (In this case, Replication rights to abuse DCSync)
Last updated