Skip to content

User Guide

CravateRouge edited this page Nov 20, 2023 · 25 revisions

Global Arguments

$ bloodyAD -h

usage: bloodyAD.py [-h] [-d DOMAIN] [-u USERNAME] [-p PASSWORD] [-k] [-c CERTIFICATE] [-s] [--host HOST] [-v {QUIET,INFO,DEBUG}] {add,get,remove,set} ...

AD Privesc Swiss Army Knife

options:
  -h, --help            show this help message and exit
  -d DOMAIN, --domain DOMAIN
                        Domain used for NTLM authentication
  -u USERNAME, --username USERNAME
                        Username used for NTLM authentication
  -p PASSWORD, --password PASSWORD
                        Cleartext password or LMHASH:NTHASH for NTLM authentication
  -k, --kerberos
  -c CERTIFICATE, --certificate CERTIFICATE
                        Certificate authentication, e.g: "path/to/key:path/to/cert"
  -s, --secure          Try to use LDAP over TLS aka LDAPS (default is LDAP)
  --host HOST           Hostname or IP of the DC (ex: my.dc.local or 172.16.1.3)
  -v {QUIET,INFO,DEBUG}, --verbose {QUIET,INFO,DEBUG}
                        Adjust output verbosity

Commands:
  {add,get,remove,set}
    add                 [ADD] function category
    get                 [GET] function category
    remove              [REMOVE] function category
    set                 [SET] function category

Commands Arguments

get Commands

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -c ":bloodyadmin.pem" -s get -h

usage: bloodyAD get [-h] {children,dnsDump,membership,object,search,writable} ...

options:
  -h, --help            show this help message and exit

get commands:
  {children,dnsDump,membership,object,search,writable}
    children            Lists children for a given target object
    dnsDump             Retrieves DNS records of the Active Directory readable/listable by the user
    membership          Retrieves SID and SAM Account Names of all groups a target belongs to
    object              Retrieves LDAP attributes for the target object provided, binary data will be outputed in base64
    search              Searches in LDAP database, binary data will be outputed in base64
    writable            Retrieves objects writable by client

get children

List children for a given target object:

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -p 'Password123!' get children -h

usage: bloodyAD.py get children [-h] [--target TARGET] [--otype OTYPE] [--direct]

options:
  -h, --help       show this help message and exit
  --target TARGET  sAMAccountName, DN, GUID or SID of the target (default: DOMAIN)
  --otype OTYPE    special keyword "useronly" or objectClass of objects to fetch e.g. user, computer, group, organizationalUnit, container, groupPolicyContainer, msDS-
                   GroupManagedServiceAccount, etc (default: *)
  --direct         Fetch only direct children of target (default: False)

get dnsDump

Retrieve DNS records of the Active Directory readable/listable by the user:

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -p 'Password123!' get dnsDump -h

usage: bloodyAD get dnsDump [-h] [--zone ZONE] [--no-detail]

options:
  -h, --help   show this help message and exit
  --zone ZONE  if set, prints only records in this zone (default: None)
  --no-detail  if set doesn't include system records such as _ldap, _kerberos, @, etc (default: False)

--zone can be used e.g. to display only our domain zone --zone bloody.local

get membership

Retrieve SID and SAM Account Names of all groups a target belongs to:

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -p 'Password123!' get membership -h

usage: bloodyAD get membership [-h] [--no-recurse] target

positional arguments:
  target        sAMAccountName, DN, GUID or SID of the target

options:
  -h, --help    show this help message and exit
  --no-recurse  if set, doesn't retrieve groups where target isn't a direct member (default: False)

If --no-recurse is set, and our target john belongs to a group printer admins which belongs to Domain Admins, Domain Admins will not be displayed in the result.

get object

Retrieve LDAP attributes for the target object provided, binary data will be outputted in base64:

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -p 'Password123!' get object -h

usage: bloodyAD get object [-h] [--attr ATTR] [--resolve-sd] [--raw] target

positional arguments:
  target        sAMAccountName, DN, GUID or SID of the target

options:
  -h, --help    show this help message and exit
  --attr ATTR   name of the attribute to retrieve, retrieves all the attributes by default (default: *)
  --resolve-sd  if set, permissions linked to a security descriptor will be resolved (see bloodyAD github wiki/Access-Control for more information) (default:
                False)
  --raw         if set, will return attributes as sent by the server without any formatting, binary data will be outputted in base64 (default: False)

Examples:

# Get group members
bloodyAD -u john.doe -d bloody -p Password512! --host 192.168.10.2 get object "Domain Admins" --attr member # Get UserAccountControl flags

# Get User account controls (e.g. see if user is locked)
bloodyAD -u Administrator -d bloody -p Password512! --host 192.168.10.2 get object john.doe --attr userAccountControl

# Read GMSA account password
bloodyAD -u john.doe -d bloody -p Password512 --host 192.168.10.2 get object 'gmsaAccount$' --attr msDS-ManagedPassword

# Read LAPS password
bloodyAD -u john.doe -d bloody -p Password512 --host 192.168.10.2 get object 'COMPUTER$' --attr ms-Mcs-AdmPwd

get search

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -p 'Password123!' get search -h

usage: bloodyAD get search [-h] [--filter FILTER] [--attr ATTR] [--resolve-sd] [--raw] searchbase

positional arguments:
  searchbase       DN of the parent object

options:
  -h, --help       show this help message and exit
  --filter FILTER  filter to apply to the LDAP search (see Microsoft LDAP filter syntax) (default: (objectClass=*))
  --attr ATTR      attributes to retrieve separated by a comma (default: *)
  --resolve-sd     if set, permissions linked to a security descriptor will be resolved (see bloodyAD github wiki/Access-Control for more information)
                   (default: False)
  --raw            if set, will return attributes as sent by the server without any formatting, binary data will be outputed in base64 (default: False)

get writable

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -p 'Password123!' get writable -h
usage: bloodyAD get writable [-h] [--otype {ALL,OU,USER,COMPUTER,GROUP,DOMAIN,GPO}] [--right {ALL,WRITE,CHILD}] [--detail]

options:
  -h, --help            show this help message and exit
  --otype {ALL,OU,USER,COMPUTER,GROUP,DOMAIN,GPO}
                        type of writable object to retrieve (default: ALL)
  --right {ALL,WRITE,CHILD}
                        type of right to search (default: ALL)
  --detail              if set, displays attributes/object types you can write/create for the object (default: False)

set Commands

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -c ":bloodyadmin.pem" -s set -h

usage: bloodyAD set [-h] {object,owner,password} ...

options:
  -h, --help            show this help message and exit

set commands:
  {object,owner,password}
    object              Add/Replace/Delete target's attribute
    owner               Changes target ownership with provided owner (WriteOwner permission required)
    password            Change password of a user/computer

set object

$ bloodyAD --host 10.1.0.4 -d bloody -u red.team -p 'Password123!' set object -h

usage: bloodyAD set object [-h] [-v V] target attribute

positional arguments:
  target      sAMAccountName, DN, GUID or SID of the target
  attribute   name of the attribute

options:
  -h, --help  show this help message and exit
  -v V        add value if attribute doesn't exist, replace value if attribute exists, delete if no value given, can be called multiple times if multiple values to set (e.g -v HOST/janettePC -v HOST/janettePC.bloody.local) (default: None)

set owner

$ bloodyAD --host 10.1.0.4 -d bloody -u red.team -p 'Password123!' set owner -h
usage: bloodyAD set owner [-h] target owner

positional arguments:
  target      sAMAccountName, DN, GUID or SID of the target
  owner       sAMAccountName, DN, GUID or SID of the new owner

options:
  -h, --help  show this help message and exit

Warning

If you only have WRITE_OWNER or SE_TAKE_OWNERSHIP_PRIVILEGE, you can only set yourself as owner. You must have DS-Set-Owner on the domain or SeRestorePrivilege to set any other users as owners (see [MS-ADTS] 6.1.3.5 and this article)

set password

$ bloodyAD --host 172.16.1.15 -d bloody.local -u jane.doe -p :70016778cb0524c799ac25b439bd6a31 set password -h
usage: bloodyAD.py set password [-h] [--oldpass OLDPASS] target newpass

positional arguments:
  target             sAMAccountName, DN, GUID or SID of the target
  newpass            new password for the target

options:
  -h, --help         show this help message and exit
  --oldpass OLDPASS  old password of the target, mandatory if you don't have "change password" permission on the target (default: None)

Note

You can use oldpass to change the password of another user without having any special right on it. (Useful when the target is locked because the password is expired)

add Commands

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -c ":bloodyadmin.pem" -s add -h
usage: bloodyAD add [-h] {computer,dcsync,dnsRecord,genericAll,groupMember,rbcd,shadowCredentials,uac,user} ...

options:
  -h, --help            show this help message and exit

add commands:
  {computer,dcsync,dnsRecord,genericAll,groupMember,rbcd,shadowCredentials,uac,user}
    computer            Adds new computer
    dcsync              Adds DCSync right on domain to provided trustee (Requires to own or to have WriteDacl on domain object)
    dnsRecord           This function adds a new DNS record into an AD environment.
    genericAll          Gives full control to trustee on target (you must own the object or have WriteDacl)
    groupMember         Adds a new member (user, group, computer) to group
    rbcd                Adds Resource Based Constraint Delegation for service on target, used to impersonate a user on target with service (Requires
                        "Write" permission on target's msDS-AllowedToActOnBehalfOfOtherIdentity and Windows Server >= 2012)
    shadowCredentials   Adds Key Credentials to target, used to impersonate target with added credentials
    uac                 Adds property flags altering user/computer object behavior
    user                Adds a new user

add computer

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody add computer -h
usage: bloodyAD add computer [-h] [--ou OU] hostname password

positional arguments:
  hostname    computer name (without trailing $)
  password    password for computer

options:
  -h, --help  show this help message and exit
  --ou OU     Organizational Unit for computer (default: DefaultOU)

Tip

Make sure to provide the domain FQDN as domain global argument -d bloody.lab or you will run into an issue as problem 1005 (CONSTRAINT_ATT_TYPE), data 0, Att 9026b (dNSHostName)

add dcsync

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody add dcsync -h
usage: bloodyAD add dcsync [-h] trustee

positional arguments:
  trustee     sAMAccountName, DN, GUID or SID of the trustee

options:
  -h, --help  show this help message and exit

add dnsRecord

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody add dnsRecord -h
usage: bloodyAD add dnsRecord [-h] [--dnstype {A,AAAA,CNAME,MX,PTR,SRV,TXT}] [--zone ZONE] [--ttl TTL] [--preference PREFERENCE] [--port PORT]
                              [--priority PRIORITY] [--weight WEIGHT] [--forest]
                              name data

positional arguments:
  name                  name of the dnsNode object (hostname) which will contain the new record
  data                  DNS record data, for most record types this will be the destination hostname or IP address, for TXT records this can be used for text

options:
  -h, --help            show this help message and exit
  --dnstype {A,AAAA,CNAME,MX,PTR,SRV,TXT}
                        DNS record type (default: A)
  --zone ZONE           DNS zone (default: CurrentDomain)
  --ttl TTL             DNS record TTL, time in seconds the record stays in DNS caches, must be low if you want to propagate record updates quickly
                        (default: 300)
  --preference PREFERENCE
                        DNS MX record preference, must be lower than the concurrent records to be chosen (default: 10)
  --port PORT           listening port of the service in a DNS SRV record (default: None)
  --priority PRIORITY   priority of a DNS SRV record against concurrent, must be lower to be chosen, if identical to others, highest weight will be chosen
                        (default: 10)
  --weight WEIGHT       weight of a DNS SRV record against concurrent, must be higher with the lowest priority to be chosen (default: 60)
  --forest              if set, registers dns record in forest instead of domain (default: False)

Simplest usage:

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody add dnsRecord test.bloody.local 8.8.8.8

add genericAll

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody add genericAll -h
usage: bloodyAD add genericAll [-h] target trustee

positional arguments:
  target      sAMAccountName, DN, GUID or SID of the target
  trustee     sAMAccountName, DN, GUID or SID of the trustee which will have full control on target

options:
  -h, --help  show this help message and exit

add groupMember

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody add groupMember -h
usage: bloodyAD add groupMember [-h] group member

positional arguments:
  group       sAMAccountName, DN, GUID or SID of the group
  member      sAMAccountName, DN, GUID or SID of the member

options:
  -h, --help  show this help message and exit

Note

Support Foreign Users

add rbcd

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody add rbcd -h
usage: bloodyAD add rbcd [-h] target service

positional arguments:
  target      sAMAccountName, DN, GUID or SID of the target
  service     sAMAccountName, DN, GUID or SID of the service account

options:
  -h, --help  show this help message and exit

add shadowCredentials

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody add shadowCredentials -h
usage: bloodyAD add shadowCredentials [-h] [--path PATH] target

positional arguments:
  target       sAMAccountName, DN, GUID or SID of the target

options:
  -h, --help   show this help message and exit
  --path PATH  filepath for the generated Key Credentials certificate (default: CurrentPath)

add uac

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody add uac -h
usage: bloodyAD add uac [-h] [-f F] target

positional arguments:
  target      sAMAccountName, DN, GUID or SID of the target

options:
  -h, --help  show this help message and exit
  -f F        name of property flag to add, can be called multiple times if multiple flags to add (e.g -f DONT_REQ_PREAUTH -f DONT_EXPIRE_PASSWORD)
              (default: None)

add user

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody add user -h
usage: bloodyAD add user [-h] [--ou OU] sAMAccountName password

positional arguments:
  sAMAccountName  sAMAccountName for new user
  password        password for new user

options:
  -h, --help      show this help message and exit
  --ou OU         Organizational Unit for new user (default: DefaultOU)

remove Commands

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -c ":bloodyadmin.pem" -s remove -h

usage: bloodyAD remove [-h] {dcsync,dnsRecord,genericAll,groupMember,object,rbcd,shadowCredentials,uac} ...

options:
  -h, --help            show this help message and exit

remove commands:
  {dcsync,dnsRecord,genericAll,groupMember,object,rbcd,shadowCredentials,uac}
    dcsync              Removes DCSync right for provided trustee
    dnsRecord           Removes a DNS record of an AD environment.
    genericAll          Removes full control of trustee on target
    groupMember         Removes member (user, group, computer) from group
    object              Removes object (user, group, computer, organizational unit, etc)
    rbcd                Removes Resource Based Constraint Delegation for service on target
    shadowCredentials   Removes Key Credentials from target
    uac                 Removes property flags altering user/computer object behavior

remove dcsync

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody remove dcsync -h
usage: bloodyAD remove dcsync [-h] trustee

positional arguments:
  trustee     sAMAccountName, DN, GUID or SID of the trustee

options:
  -h, --help  show this help message and exit

remove dnsRecord

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody remove dnsRecord -h
usage: bloodyAD remove dnsRecord [-h] [--dnstype {A,AAAA,CNAME,MX,PTR,SRV,TXT}] [--zone ZONE] [--ttl TTL] [--preference PREFERENCE] [--port PORT]
                                 [--priority PRIORITY] [--weight WEIGHT] [--forest]
                                 name data

positional arguments:
  name                  name of the dnsNode object (hostname) which contains the record
  data                  DNS record data

options:
  -h, --help            show this help message and exit
  --dnstype {A,AAAA,CNAME,MX,PTR,SRV,TXT}
                        DNS record type (default: A)
  --zone ZONE           DNS zone (default: CurrentDomain)
  --ttl TTL             DNS record TTL (default: None)
  --preference PREFERENCE
                        DNS MX record preference (default: None)
  --port PORT           listening port of the service in a DNS SRV record (default: None)
  --priority PRIORITY   priority of a DNS SRV record against concurrent (default: None)
  --weight WEIGHT       weight of a DNS SRV record against concurrent (default: None)
  --forest              if set, will fetch the dns record in forest instead of domain (default: False)

The options must be used if:

  • The record is not an A type (you must provide other options depending of the type but TTL is always optional)
  • The record is not in the DOMAIN zone
  • The record is in the Forest DNS Partition and Not the Domain DNS Partition Simplest usage:
$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody remove dnsRecord test.bloody.local 8.8.8.8

remove genericAll

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody remove genericAll -h
usage: bloodyAD remove genericAll [-h] target trustee

positional arguments:
  target      sAMAccountName, DN, GUID or SID of the target
  trustee     sAMAccountName, DN, GUID or SID of the trustee

options:
  -h, --help  show this help message and exit

remove groupMember

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody remove groupMember -h
usage: bloodyAD remove groupMember [-h] group member

positional arguments:
  group       sAMAccountName, DN, GUID or SID of the group
  member      sAMAccountName, DN, GUID or SID of the member

options:
  -h, --help  show this help message and exit

remove object

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody remove object -h
usage: bloodyAD remove object [-h] target

positional arguments:
  target      sAMAccountName, DN, GUID or SID of the target

options:
  -h, --help  show this help message and exit

remove rbcd

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody remove rbcd -h
usage: bloodyAD remove rbcd [-h] target service

positional arguments:
  target      sAMAccountName, DN, GUID or SID of the target
  service     sAMAccountName, DN, GUID or SID of the service account

options:
  -h, --help  show this help message and exit

remove shadowCredentials

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody remove shadowCredentials -h
usage: bloodyAD remove shadowCredentials [-h] [--key KEY] target

positional arguments:
  target      sAMAccountName, DN, GUID or SID of the target

options:
  -h, --help  show this help message and exit
  --key KEY   RSA key of Key Credentials to remove from the target, removes all if key not specified (default: None)

remove uac

$ bloodyAD --host 10.1.0.4 -u bloodyAdmin -p 'Password123!' -d bloody remove uac -h
usage: bloodyAD remove uac [-h] [-f F] target

positional arguments:
  target      sAMAccountName, DN, GUID or SID of the target

options:
  -h, --help  show this help message and exit
  -f F        name of property flag to remove, can be called multiple times if multiple flags to remove (e.g -f LOCKOUT -f ACCOUNTDISABLE) (default: None)

Clone this wiki locally