ACL Abuse
Enumeration
ReadProperty, ExtendedRight over OU / Computer Object
Most likely LAPS. The IdentityReferenceName can read the LAPS password in cleartext for the OU.
WriteProperty | Self-Membership | GenericAll over Group
Can add members to the group
GenericWrite | GenericAll | WriteProperty over Computer Object
Can perform Resource Based Constrained Delegation Attack
GenericAll over User Object
Can reset their password without knowing the old one
WriteDACL over DC
Can give DCSync privs to user
Resources
Last updated