Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you…
Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). Use when the target runs a Certificate Authority and you want to find vulnerable certificate templates or CA misconfigurations, request a certificate that impersonates a privileged user, and know…
Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB. Use when SMB signing is not enforced or LDAP channel binding is missing, and you want to force a privileged machine account to…
Use when classifying or explaining authorized Active Directory attack techniques—Kerberos and NTLM paths, coercion awareness, delegation and RBCD, ACL and DCSync concepts, LAPS and shadow credentials, GPP, trust paths, AD-joined SQL pivots, and lateral movement by protocol. Use as a reference when writing findings or…
Use when triaging or reporting authorized Active Directory Certificate Services risk—enterprise CA inventory, template permissions, ESC1–ESC11 style labels from Certipy-style tools, DC certificate mapping and strong-binding evidence, web enrollment and RPC relay surfaces. Use with /web3-audit command content and…
Use when performing or planning authorized Active Directory reconnaissance—DNS and DC SRV, forest and trust mapping, LDAP/LDAPS and signing posture, gMSA discovery, SMB signing, password policy and spray approval gates, Kerberos SPN and pre-auth discovery, BloodHound collection choice, and LDAP filter cookbook. Use…