ACL Enumeration
Enumerating ACLs with PowerView
Import-Module .\PowerView.ps1 $sid = Convert-NameToSid wleyGet-DomainObjectACL -Identity * | ? {$_.SecurityIdentifier -eq $sid}
$guid= "00299570-246d-11d0-a768-00aa006e0529" Get-ADObject -SearchBase "CN=Extended-Rights,$((Get-ADRootDSE).ConfigurationNamingContext)" -Filter {ObjectClass -like 'ControlAccessRight'} -Properties * |Select Name,DisplayName,DistinguishedName,rightsGuid| ?{$_.rightsGuid -eq $guid} | fl
Find-InterestingDomainAcl -ResolveGUIDsGet-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $sid} # Ex Get-DomainObjectAcl -Identity "Domain Admins" -ResolveGUIDs -
$sid2 = Convert-NameToSid damundsen Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $sid2} -Verbose
image.png Get-DomainGroup -Identity "Help Desk Level 1" | select memberof
$itgroupsid = Convert-NameToSid "Information Technology" Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $itgroupsid} -Verbose
$adunnsid = Convert-NameToSid adunn Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $adunnsid} -Verbose
Enumerating ACLs with other way
BloodHound



Last updated
