Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
acltoolkit — Toolkit per l'abuso delle ACL di Active Directory per elevazione dei privilegi, DCSync, modifica della proprietà degli oggetti e movimento laterale tramite manipolazione degli script di accesso e modifiche dell'appartenenza ai gruppi. | Kitploit
Strumenti/GitHubGitHub/zblurx/acltoolkit
Escalation di PrivilegiExploitMovimento LateralePost-ExploitPenetration Testing
GitHubzblurx/acltoolkit

acltoolkit

Toolkit per l'abuso delle ACL di Active Directory per elevazione dei privilegi, DCSync, modifica della proprietà degli oggetti e movimento laterale tramite manipolazione degli script di accesso e modifiche dell'appartenenza ai gruppi.

Vedi Repository
129133 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

acltoolkit

acltoolkit è un coltellino svizzero per abusi ACL. Implementa molteplici abusi ACL.

Indice

  • acltoolkit
    • Indice
    • Installazione
    • Utilizzo
    • Comandi
      • get-objectacl
      • set-objectowner
      • give-genericall
      • give-dcsync
      • add-groupmember
      • set-logonscript

Installazione

root@kitploit:~
pip install acltoolkit-ad

oppure

root@kitploit:~
git clone https://github.com/zblurx/acltoolkit.git
cd acltoolkit
make

Utilizzo

root@kitploit:~
usage: acltoolkit [-h] [-debug] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-dc-ip ip address] [-scheme ldap scheme]
                  target {get-objectacl,set-objectowner,give-genericall,give-dcsync,add-groupmember,set-logonscript} ...

ACL abuse swiss-army knife

positional arguments:
  target                [[domain/]username[:password]@]<target name or address>
  {get-objectacl,set-objectowner,give-genericall,give-dcsync,add-groupmember,set-logonscript}
                        Action
    get-objectacl       Get Object ACL
    set-objectowner     Modify Object Owner
    give-genericall     Grant an object GENERIC ALL on a targeted object
    give-dcsync         Grant an object DCSync capabilities on the domain
    add-groupmember     Add Member to Group
    set-logonscript     Change Logon Sript of User

options:
  -h, --help            show this help message and exit
  -debug                Turn DEBUG output ON
  -no-pass              don't ask for password (useful for -k)
  -k                    Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will use the ones specified in the
                        command line
  -dc-ip ip address     IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter
  -scheme ldap scheme

authentication:
  -hashes LMHASH:NTHASH
                        NTLM hashes, format is LMHASH:NTHASH

Comandi

get-objectacl

root@kitploit:~
$ acltoolkit get-objectacl -h
usage: acltoolkit target get-objectacl [-h] [-object object] [-all]

options:
  -h, --help      show this help message and exit
  -object object  Dump ACL for <object>. Parameter can be a sAMAccountName, a name, a DN or an objectSid
  -all            List every ACE of the object, even the less-interesting ones

Il comando get-objectacl prenderà come input un sAMAccountName, un nome, un DN o un objectSid tramite -object e elencherà Sid, Nome, DN, Classe, adminCount, LogonScript configurato, Gruppo Primario, Proprietario e DACL dell'oggetto. Se non viene fornito alcun parametro, elencherà le informazioni sull'account utilizzato per autenticarsi.

root@kitploit:~
$ acltoolkit waza.local/jsmith:Password#[email protected] get-objectacl
Sid                 : S-1-5-21-267175082-2660600898-836655089-1103
Name                : waza\John Smith
DN                  : CN=John Smith,CN=Users,DC=waza,DC=local
Class               : top, person, organizationalPerson, user
adminCount          : False

Logon Script
  scriptPath        : \\WAZZAAAAAA\OCD\test.bat
  msTSInitialProgram: \\WAZZAAAAAA\OCD\test.bat

PrimaryGroup
  Sid               : S-1-5-21-267175082-2660600898-836655089-513
  Name              : waza\Domain Users
  DN                : CN=Domain Users,OU=Builtin Groups,DC=waza,DC=local

[...]

OwnerGroup
  Sid               : S-1-5-21-267175082-2660600898-836655089-512
  Name              : waza\Domain Admins

Dacl
  ObjectSid         : S-1-1-0
  Name              : Everyone
  AceType           : ACCESS_ALLOWED_OBJECT_ACE
  AccessMask        : 256
  ADRights          : EXTENDED_RIGHTS
  IsInherited       : False
  ObjectAceType     : User-Change-Password

[...]

  ObjectSid         : S-1-5-32-544
  Name              : BUILTIN\Administrator
  AceType           : ACCESS_ALLOWED_ACE
  AccessMask        : 983485
  ADRights          : WRITE_OWNER, WRITE_DACL, GENERIC_READ, DELETE, EXTENDED_RIGHTS, WRITE_PROPERTY, SELF, CREATE_CHILD
  IsInherited       : True

set-objectowner

root@kitploit:~
$ acltoolkit set-objectowner -h
usage: acltoolkit target set-objectowner [-h] -target-sid target_sid [-owner-sid owner_sid]

options:
  -h, --help            show this help message and exit
  -target-sid target_sid
                        Object Sid targeted
  -owner-sid owner_sid  New Owner Sid

Il comando set-objectowner prenderà come input un SID di destinazione e un SID proprietario, e modificherà il proprietario dell'oggetto target.

give-genericall

root@kitploit:~
$ acltoolkit give-genericall -h
usage: acltoolkit target give-genericall [-h] -target-sid target_sid [-granted-sid owner_sid]

options:
  -h, --help            show this help message and exit
  -target-sid target_sid
                        Object Sid targeted
  -granted-sid owner_sid
                        Object Sid granted GENERIC_ALL

Il comando give-genericall prenderà come input un SID di destinazione e un SID concesso, e assegnerà il permesso GENERIC_ALL al SID concesso sull'oggetto target.

give-dcsync

root@kitploit:~
$ acltoolkit give-dcsync -h
usage: acltoolkit target give-dcsync [-h] [-granted-sid owner_sid]

options:
  -h, --help            show this help message and exit
  -granted-sid owner_sid
                        Object Sid granted DCSync capabilities

Il comando give-dcsync prenderà come input un SID concesso, e assegnerà le capacità DCSync al SID concesso.

add-groupmember

root@kitploit:~
$ acltoolkit add-groupmember -h
usage: acltoolkit target add-groupmember [-h] [-user user] -group group

options:
  -h, --help    show this help message and exit
  -user user    User added to a group
  -group group  Group where the user will be added

Il comando add-groupmember prenderà come input un sAMAccountName utente e un sAMAccountName gruppo, e aggiungerà l'utente al gruppo.

set-logonscript

root@kitploit:~
$ acltoolkit set-logonscript -h
usage: acltoolkit target set-logonscript [-h] -target-sid target_sid -script-path script_path [-logonscript-type logonscript_type]

options:
  -h, --help            show this help message and exit
  -target-sid target_sid
                        Object Sid of targeted user
  -script-path script_path
                        Script path to set for the targeted user
  -logonscript-type logonscript_type
                        Logon Script variable to change (default is scriptPath)

Il comando set-logonscript prenderà come input un SID di destinazione e un percorso script, e imposterà il percorso dello script di accesso dell'utente target al percorso specificato.

Scarica lo strumento