Active Directory Permissions & ACLs
AD's permission model controls who can do what to every object. ACE misconfigurations are behind most unintended privilege escalation paths BloodHound finds. GenericAll, WriteDACL, WriteOwner — these rights on the wrong object turn a low-privileged account into a Domain Admin.
Members Only Content
This article is exclusively available to registered members of LazyHackers. Login or subscribe to read.