Active › Module 6 › Lesson 2
ACL Paths Named
ACL abuse paths named at literacy — GenericAll, WriteDACL, force-change-password — graph awareness on $LAB_AD, defenses not takeover recipes.
Visual · t25_acl_paths_named
ACL paths = named permission edges. BloodHound literacy. $LAB_AD only. Original Cyberlium.
Opening
BloodHound shows paths — defenders fix ACLs; attackers need authorization before touching any forest.
ACL-based privilege paths in AD include edges like GenericAll, GenericWrite, WriteDACL, WriteOwner, ForceChangePassword, and AddMember on groups — literacy for reading BloodHound-style graphs on YOUR $LAB_AD. Analyst names the edge, identifies excessive delegation on service accounts or helpdesk groups, and recommends remediation: remove dangerous ACEs, implement tiering, regular ACL audits. Cyberlium teaches path naming and defender cleanup — NOT full stranger-domain escalation cookbooks, NOT exporting real enterprise BloodHound zips from leaks, NOT 'GenericAll to DA' homework against production. On $LAB_AD per brief: document one named path from lab graph with impact literacy and fix recommendation. Purple tie-in: path existed because ACL hygiene failed.
1. Named ACL edges
GenericAll, WriteDACL, ForceChangePassword, AddMember — one-line each for graph reading.
Path = chain of edges from low-priv lab user to high-value object — literacy only.
Command guide
Try these commands — Named ACL edges
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
MITRE T1222 ACL abuse — https://attack.mitre.org/techniques/T1222/ (ACL path literacy) BloodHound ACL edges — https://bloodhound.readthedocs.io/ (path concepts — docs only) Microsoft AD ACLs — https://learn.microsoft.com/en-us/windows/win32/ad/active-directory-security-descriptors (ACL literacy)
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
export LAB_AD=${LAB_AD:-$HOME/cyberlium-lab/t25-ad}
cat > "$LAB_AD/notes/acl-paths.txt" <<'EOF'
ACL abuse paths (named): GenericAll, WriteDacl, ForceChangePassword
BloodHound shows edges — study docs, collector on YOUR lab only
Defender: audit privileged ACLs, remove excessive GenericAll
EOFCommand — copy this
grep -E 'GenericAll|BloodHound|Defender' "$LAB_AD/notes/acl-paths.txt" curl -sS https://bloodhound.readthedocs.io/ | head -6
Primary tools to practice this lesson: curl, grep. Reference sites: MITRE T1222 ACL abuse (https://attack.mitre.org/techniques/T1222/); BloodHound ACL edges (https://bloodhound.readthedocs.io/); Microsoft AD ACLs (https://learn.microsoft.com/en-us/windows/win32/ad/active-directory-security-descriptors). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Defender remediation
Remove unnecessary ACEs, use AdminSDHolder protection awareness, delegate minimally.
Regular BloodHound collection on YOUR tenant with blue-team lens — not attack export.
3. Scope refuse
No ACL abuse against stranger domains, no leaked enterprise graphs as lab input.
Findings describe misconfig on $LAB_AD — not live escalation proof on unauthorized AD.
4. What you ship: ACL paths literacy card
Five named edges + one lab path row + remediation line + $LAB_AD scope.
5. What you record before the next lesson
ACL paths literacy card path.
6. Wrong vs right: stranger-domain attacks vs lab AD literacy
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Import stranger BloodHound zip and execute GenericAll path on production.
Right
ACL paths named with defender remediation. Next: Delegation Named.
Mission: ACL paths literacy card
1) Define five ACL edges one line each. 2) Document one $LAB_AD path row. 3) Write remediation for that path. 4) NEVER stranger-domain ACL abuse.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “GenericAll vs WriteDACL — defender fix order?”
Knowledge Check
APPLY: ACL paths literacy teaches:
Multiple choice
Knowledge Check
APPLY: True or False: BloodHound on stranger enterprise zip is lab.
True or False
Knowledge Check
APPLY: ForceChangePassword edge means:
Multiple choice