logo

A Hitch-hacker's Guide to DACL-Based Detections (Part…

ID: b9dcde2a-52d7-5042-adfa-9069b6a07d08

STIX ID: report--b9dcde2a-52d7-5042-adfa-9069b6a07d08

Feed Name: TrustedSec blog

Date Published: 2025-03-24

Date Updated: 2026-05-01

...
...

This Part 1B technical blog details Active Directory attribute-based attack techniques (manipulating DACLs, ForceChangePassword, ownership changes, LAPS/gMSA abuses, and granting DCSync rights), demonstrates proof-of-concept abuse using common post-exploitation tools (PowerView, PowerSploit, Impacket, PowerMad), and supplies Splunk-oriented detection queries and SDDL analysis to help defenders detect and investigate such modifications and privileges escalation attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.