Active Directory Security Tip #15: Active Directory Domain Root Permissions
好的,我现在需要帮用户总结一篇关于Active Directory域权限的文章,控制在100字以内。首先,我得仔细阅读文章内容,抓住主要点。 文章主要讨论了Active Directory域根目录上的几种危险权限:Directory Changes、Change Owner、Change Permission和Full Control。这些权限可能导致密码哈希提取(DCSync)、权限提升等安全风险。作者还提供了一个PowerShell脚本,用于检测这些权限,并附上了更多资源链接。 接下来,我需要将这些信息浓缩到100字以内。重点包括:Active Directory域根权限、危险的权限类型及其影响、检测脚本和相关资源。要确保语言简洁明了,直接描述内容,不需要开头语。 可能会遇到的问题是如何在有限的字数内涵盖所有关键点而不遗漏重要信息。可能需要舍弃一些细节,比如具体的链接或脚本名称,但保留核心内容。 最后,检查字数是否符合要求,并确保总结准确传达了原文的主要信息。 </think> 文章探讨了Active Directory域根目录上的危险权限,包括密码哈希提取(DCSync)、权限提升等,并提供检测脚本及资源链接。 2025-12-3 01:3:0 Author: adsecurity.org(查看原文) 阅读量:0 收藏

Dec 02 2025

This week let’s look at Active Directory domain permissions which are configured on the domain root and apply to the domain. There are many different type of concerning permissions, but let’s look at the most egregious.

  • Directory Changes & Directory Changes All – provides the ability to pull password hashes for users and computers (aka DCsync permissions).
  • Change Owner – provides the ability to set the owner on the domain root and the owner has the ability to set permissions.
  • Change Permission – provides the ability to set permissions on the domain root.
  • Full Control – provides the ability to control any type of object in the domain.
  • Full Control on Users and/or Computers – provides the ability to control the object type.

I wrote a PowerShell script leveraging the Active Directory PowerShell module that can help identify these permissions on the domain root: https://github.com/PyroTek3/Misc/blob/main/Get-DomainRootPermissions.ps1

For more on Active Directory permissions:
https://hub.trimarcsecurity.com/post/trimarc-whitepaper-owner-or-pwnd
https://specterops.io/wp-content/uploads/sites/3/2022/06/an_ace_up_the_sleeve.pdf

For more on DCSync: https://adsecurity.org/?p=1729

(Visited 17 times, 17 visits today)

Sean Metcalf

I improve security for enterprises around the world working for TrustedSec & I am @PyroTek3 on Twitter.
Read the About page (top left) for information about me. :)
https://adsecurity.org/?page_id=8


文章来源: https://adsecurity.org/?p=4941
如有侵权请联系:admin#unsafe.sh