Escalating privileges with ACLs in Active Directory
ID: 9204d123-96e9-5233-bf99-04a1bed2e73f
STIX ID: report--9204d123-96e9-5233-bf99-04a1bed2e73f
Feed Name: Fox-IT blog
This blogpost describes advanced Active Directory privilege escalation attacks that enumerate and abuse ACLs and Exchange default group permissions to escalate to Domain Administrator; it introduces the Invoke-ACLPwn PowerShell tool and an ntlmrelayx extension that automate finding and exploiting ACL/group chains, demonstrates DCSync and LDAP/NTLM relay-based escalation, and provides mitigation guidance such as removing dangerous ACLs, monitoring critical group memberships, and auditing ACL changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
