acl-enum
PowerView - tool
Import-module .\PowerView.ps1$sid = Convert-NameToSid <username>Get-DomainObjectACL -Identity * | ? {$_.SecurityIdentifier -eq $sid}$guid = '00299570-246d-11d0-a768-00aa006e0529'Get-ADObject -SearchBase "CN=Extended-Rights,$((Get-ADRootDSE).ConfigurationNamingContext)" -Filter {ObjectClass -like 'ControlAccessRight'} -Properties * |Select Name,DisplayName,DistinguishedName,rightsGuid| ?{$_.rightsGuid -eq $guid} | flGet-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $sid}Find-InterestingDomainAclUsing Built-in tools
Get-ADUser -Filter * | Select-Object -ExpandProperty SamAccountName > ad_users.txtFurther rights enumerations
Powerview - tool
AD powershell module (Extra)
Last updated