Enumerating AD Object Permissions with dsacls
Enumeration, living off the land
Execution
dsacls.exe "cn=spotless,cn=users,dc=offense,dc=local" | select-string "spot"

Full Control

Add/Remove self as member

WriteProperty/ChangeOwnerShip

Password Spraying Anyone?


Dirty POC idea for Password Spraying:

References
PreviousActive Directory Enumeration with AD Module without RSAT or Admin PrivilegesNextActive Directory Password Spraying
Last updated