Area 08 / 12
Object & ACL Security
Attackers rarely need a zero-day when a helpdesk group has WriteDACL on a privileged object. This area audits the access control lists that grant control of accounts and OUs, finds the replication rights behind DCSync, and keeps AdminSDHolder and adminCount under control.
Start the pathLearning path
0/4 done- 01Auditing Active Directory ACLs before an attacker doesHow to find dangerous AD ACLs like GenericAll and DCSync rights, clean up stale adminCount flags, and use BloodHound defensively.
- 02Finding and removing DCSync rights in Active DirectoryAudit who holds DS-Replication-Get-Changes-All and equivalent rights on the domain root, remove the ones that should not exist, and alert on DCSync.
- 03AdminSDHolder and SDProp: cleanup and monitoringBaseline the AdminSDHolder ACL, find orphaned adminCount=1 accounts, reset their ACLs safely, trigger SDProp on demand, and alert on AdminSDHolder changes.
- 04Attack path management with BloodHound for defendersUse BloodHound defensively: tag Tier Zero correctly, find choke points, fix attack paths in the right order, and track exposure over time with safe collection.