ad-dacl-abuse
Installation
SKILL.md
AD ACL / DACL abuse
When it applies
You have domain creds and BloodHound shows your principal (or one you control) has a dangerous ACL edge over another object — a user, group, computer, GPO, or the domain. These edges chain into a path to Domain Admin without any CVE.
Why it works
AD access control is a web of object permissions. Over-permissive ACLs let you modify other principals: reset a password, add yourself to a privileged group, take ownership then rewrite the DACL, or grant yourself DCSync — each turning a small right into control.