ACE to RCE
ID: 70a3b9a9-ca99-5658-94be-6097f81eba8c
STIX ID: report--70a3b9a9-ca99-5658-94be-6097f81eba8c
Feed Name: SensePost Blog
This write-up demonstrates a technique to abuse Active Directory GenericWrite ACE misconfigurations to execute attacker-controlled payloads at RDP logon by setting per-user Remote Desktop Environment attributes used by the legacy Remote Connection Manager (RCM). It details discovery methods (PowerView, BloodHound, RSAT), attribute manipulation via ADSI/IADsTSUserEx, payload creation (PowerShell compiled with PS2EXE), delivery over SMB, and optional credential capture through RDS profile/home folder paths, and concludes with mitigations including disabling RCM (fQueryUserConfigFromDC), restricting/monitoring SMB, auditing ACL changes, and detecting EventID 1060.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
