Analyzing Active Directory ACL Abuse

SkillSecurity

This is a skill that detects dangerous ACL misconfigurations in Active Directory using ldap3. It connects to a Domain Controller, reads each object's security descriptor, and parses the access control entries. It flags permissions like GenericAll, WriteDACL, and WriteOwner held by non-admin users or groups, then produces a JSON report with attack paths and remediation steps.

Use Analyzing Active Directory ACL Abuse in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Analyzing Active Directory ACL Abuse and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Analyzing Active Directory ACL Abuse skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Install Python 3.9 or later and the ldap3 library with pip install ldap3.

Analyzing Active Directory ACL AbuseStart free

What your AI can do with it

  • Connects to a Domain Controller over LDAP or LDAPS with domain credentials
  • Reads the nTSecurityDescriptor attribute of AD objects
  • Parses binary security descriptors into SDDL format
  • Flags GenericAll, WriteDACL, and WriteOwner held by non-admin principals
  • Produces a JSON report with attack paths and remediation steps

Getting started

  1. Install Python 3.9 or later and the ldap3 library with pip install ldap3.
  2. Obtain domain user credentials that have read access to Active Directory objects.
  3. Ensure network connectivity to the Domain Controller on port 389 for LDAP or 636 for LDAPS.
  4. Configure the skill with the Domain Controller address and credentials, then run it to scan the target OU or domain.

What this skill tells your AI

The instructions your AI receives, as published by mukul975/anthropic-cybersecurity-skills in skills/analyzing-active-directory-acl-abuse/SKILL.md and read by ahel’s review.

Overview

Active Directory Access Control Lists (ACLs) define permissions on AD objects through Discretionary Access Control Lists (DACLs) containing Access Control Entries (ACEs). Misconfigured ACEs can grant non-privileged users dangerous permissions such as GenericAll (full control), WriteDACL (modify permissions), WriteOwner (take ownership), and GenericWrite (modify attributes) on sensitive objects like Domain Admins groups, domain controllers, or GPOs.

This skill uses the ldap3 Python library to connect to a Domain Controller, query objects with their nTSecurityDescriptor attribute, parse the binary security descriptor into SDDL (Security Descriptor Definition Language) format, and identify ACEs that grant dangerous permissions to non-administrative principals. These misconfigurations are the basis for ACL-based attack paths discovered by tools like BloodHound.

When to Use

  • When investigating security incidents that require analyzing active directory acl abuse
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Python 3.9 or later with ldap3 library (pip install ldap3)
  • Domain user credentials with read access to AD objects
  • Network connectivity to Domain Controller on port 389 (LDAP) or 636 (LDAPS)
  • Understanding of Active Directory security model and SDDL format

Steps

  1. Connect to Domain Controller: Establish an LDAP connection using ldap3 with NTLM or simple authentication. Use LDAPS (port 636) for encrypted connections in production.

  2. Query target objects: Search the target OU or entire domain for objects including users, groups, computers, and OUs. Request the nTSecurityDescriptor, distinguishedName, objectClass, and sAMAccountName attributes.

  3. Parse security descriptors: Convert the binary nTSecurityDescriptor into its SDDL string representation. Parse each ACE in the DACL to extract the trustee SID, access mask, and ACE type (allow/deny).

  4. Resolve SIDs to principals: Map security identifiers (SIDs) to human-readable account names using LDAP lookups against the domain. Identify well-known SIDs for built-in groups.

  5. Check for dangerous permissions: Compare each ACE's access mask against dangerous permission bitmasks: GenericAll (0x10000000), WriteDACL (0x00040000), WriteOwner (0x00080000), GenericWrite (0x40000000), and WriteProperty for specific extended rights.

  6. Filter non-admin trustees: Exclude expected administrative trustees (Domain Admins, Enterprise Admins, SYSTEM, Administrators) and flag ACEs where non-privileged users or groups hold dangerous permissions.

  7. Map attack paths: For each finding, document the potential attack chain (e.g., GenericAll on user allows password reset, WriteDACL on group allows adding self to group).

  8. Generate remediation report: Output a JSON report with all dangerous ACEs, affected objects, non-admin trustees, and recommended remediation steps.

Expected Output

{
  "domain": "corp.example.com",
  "objects_scanned": 1247,
  "dangerous_aces_found": 8,
  "findings": [
    {
      "severity": "critical",
      "target_object": "CN=Domain Admins,CN=Users,DC=corp,DC=example,DC=com",
      "target_type": "group",
      "trustee": "CORP\\helpdesk-team",
      "permission": "GenericAll",
      "access_mask": "0x10000000",
      "ace_type": "ACCESS_ALLOWED",
      "attack_path": "GenericAll on Domain Admins group allows adding arbitrary members",
      "remediation": "Remove GenericAll ACE for helpdesk-team on Domain Admins"
    }
  ]
}

Signals

GitHub stars
34k
Forks
4k
Last commit
Aug 2026

ahel review

  • K1binfo
    installs-packages

Automated review, not a security audit. Ruleset v1+k2.

Questions

What permissions does it look for?
It flags GenericAll, WriteDACL, WriteOwner, and GenericWrite held by non-admin users or groups on sensitive objects.
What does the report contain?
The skill produces a JSON report with attack paths and remediation steps for each dangerous permission found.
What credentials are needed?
Domain user credentials with read access to AD objects are required.
Which ports does it use?
It connects on port 389 for LDAP or 636 for LDAPS. LDAPS is recommended for encrypted connections in production.
Does it support encrypted connections?
Yes, it supports LDAPS on port 636 for encrypted connections.
Advanced
Item type
skill
Key
analyzing-active-directory-acl-abuse-mukul975
Source
github.com/mukul975/anthropic-cybersecurity-skills