agent security skill risk: medium
Active Directory ACL Abuse Analyzer
Provides step-by-step instructions for using ldap3 to connect to a Domain Controller, query nTSecurityDescriptor attributes, parse SDDL, resolve SIDs, and detect dangerous ACEs suc…
- Policy sensitive
- Human review
- External action: medium
SKILL 4 files · 2 folders
SKILL.md
---
name: analyzing-active-directory-acl-abuse
description: "Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and"
---
# Analyzing Active Directory ACL Abuse
## Overview
Active Directory Access Control Lists (ACLs) define permissions on AD objects through Discretionary Access Control Lists (DACLs) containing Access Control Entries (ACEs). Misconfigured ACEs can grant non-privileged users dangerous permissions such as GenericAll (full control), WriteDACL (modify permissions), WriteOwner (take ownership), and GenericWrite (modify attributes) on sensitive objects like Domain Admins groups, domain controllers, or GPOs.
This skill uses the ldap3 Python library to connect to a Domain Controller, query objects with their nTSecurityDescriptor attribute, parse the binary security descriptor into SDDL (Security Descriptor Definition Language) format, and identify ACEs that grant dangerous permissions to non-administrative principals. These misconfigurations are the basis for ACL-based attack paths discovered by tools like BloodHound.
## When to Use
- When investigating security incidents that require analyzing active directory acl abuse
- When building detection rules or threat hunting queries for this domain
- When SOC analysts need structured procedures for this analysis type
- When validating security monitoring coverage for related attack techniques
## Prerequisites
- Python 3.9 or later with ldap3 library (`pip install ldap3`)
- Domain user credentials with read access to AD objects
- Network connectivity to Domain Controller on port 389 (LDAP) or 636 (LDAPS)
- Understanding of Active Directory security model and SDDL format
## Steps
1. **Connect to Domain Controller**: Establish an LDAP connection using ldap3 with NTLM or simple authentication. Use LDAPS (port 636) for encrypted connections in production.
2. **Query target objects**: Search the target OU or entire domain for objects including users, groups, computers, and OUs. Request the `nTSecurityDescriptor`, `distinguishedName`, `objectClass`, and `sAMAccountName` attributes.
3. **Parse security descriptors**: Convert the binary nTSecurityDescriptor into its SDDL string representation. Parse each ACE in the DACL to extract the trustee SID, access mask, and ACE type (allow/deny).
4. **Resolve SIDs to principals**: Map security identifiers (SIDs) to human-readable account names using LDAP lookups against the domain. Identify well-known SIDs for built-in groups.
5. **Check for dangerous permissions**: Compare each ACE's access mask against dangerous permission bitmasks: GenericAll (0x10000000), WriteDACL (0x00040000), WriteOwner (0x00080000), GenericWrite (0x40000000), and WriteProperty for specific extended rights.
6. **Filter non-admin trustees**: Exclude expected administrative trustees (Domain Admins, Enterprise Admins, SYSTEM, Administrators) and flag ACEs where non-privileged users or groups hold dangerous permissions.
7. **Map attack paths**: For each finding, document the potential attack chain (e.g., GenericAll on user allows password reset, WriteDACL on group allows adding self to group).
8. **Generate remediation report**: Output a JSON report with all dangerous ACEs, affected objects, non-admin trustees, and recommended remediation steps.
## Expected Output
```json
{
"domain": "corp.example.com",
"objects_scanned": 1247,
"dangerous_aces_found": 8,
"findings": [
{
"severity": "critical",
"target_object": "CN=Domain Admins,CN=Users,DC=corp,DC=example,DC=com",
"target_type": "group",
"trustee": "CORP\\helpdesk-team",
"permission": "GenericAll",
"access_mask": "0x10000000",
"ace_type": "ACCESS_ALLOWED",
"attack_path": "GenericAll on Domain Admins group allows adding arbitrary members",
"remediation": "Remove GenericAll ACE for helpdesk-team on Domain Admins"
}
]
}
```
REQUIRED CONTEXT
- Domain Controller connectivity
- domain user credentials
- ldap3 library
OPTIONAL CONTEXT
- target OU
- LDAPS usage
EXPECTED OUTPUT
- Format
- json
- Schema
- json_schema · domain, objects_scanned, dangerous_aces_found, findings, severity, target_object, target_type, trustee, permission, access_mask, ace_type, attack_path, remediation
- Constraints
-
- match the provided findings schema
- include severity, target_object, trustee, permission, attack_path, remediation
SUCCESS CRITERIA
- Detect dangerous ACL misconfigurations
- Identify GenericAll, WriteDACL, WriteOwner, and GenericWrite ACEs
- Filter non-admin trustees
- Generate remediation report in JSON
EXAMPLES
Includes one sample JSON report structure showing domain summary and an array of findings with a critical GenericAll example.
CAVEATS
- Dependencies
-
- Python 3.9 or later with ldap3 library
- Domain user credentials with read access to AD objects
- Network connectivity to Domain Controller on port 389 or 636
- Understanding of Active Directory security model and SDDL format
- Ambiguities
-
- Description field is truncated mid-sentence: "using ldap3 to identify GenericAll, WriteDACL, and"
QUALITY
- OVERALL
- 0.70
- CLARITY
- 0.90
- SPECIFICITY
- 0.85
- REUSABILITY
- 0.35
- COMPLETENESS
- 0.80
IMPROVEMENT SUGGESTIONS
- Add explicit placeholders (e.g., {{domain}}, {{target_ou}}) to raise reusability.
- Specify exact JSON schema version or validation rules for the expected output.
USAGE
Copy the prompt above and paste it into your AI of choice — Claude, ChatGPT, Gemini, or anywhere else you're working. Replace any placeholder sections with your own context, then ask for the output.
MORE FOR AGENT
- MoltPass Client for AI Agent Identities agent security
- Supply Chain Dependency Risk Auditor agent security
- Supply Chain Dependency Risk Auditor agent security
- Threat Modeling Security Expert agent security
- Security Bluebook Policy Builder agent security
- Security Bluebook Policy Builder agent security
- Security Blue Book Policy Builder agent security
- Threat Modeling Security Architecture Expert agent security
- Supply Chain Dependency Risk Auditor agent security
- Threat Modeling Security Expert agent security
- SIEM Detection Rule Tuning Guide agent security
- AI File Metadata Compliance Auditor agent security
- Azure Storage Misconfiguration Audit Reporter agent security
- Implementing PAM for Database Access agent security
- AFL++ Coverage-Guided Fuzzing Procedure agent security
- Supply Chain Attack Simulation Detector agent security
- Security Audit Fix Verifier agent security
- Privileged Access Workstation Implementation Guide agent security
- SSRF Vulnerability Testing and Reporting Guide agent security
- Security Audit Fix Reviewer agent security
- AWS IAM Privilege Escalation Detector agent security
- SSL/TLS Security Assessment with Sslyze agent security
- GCP Penetration Testing with GCPBucketBrute agent security
- AWS CloudTrail Anomaly Detection Guide agent security
- Security Audit Fix Commit Reviewer agent security