Skip to content

User Guide

CravateRouge edited this page Nov 4, 2023 · 25 revisions

Global Arguments

$ bloodyAD -h

usage: bloodyAD.py [-h] [-d DOMAIN] [-u USERNAME] [-p PASSWORD] [-k] [-c CERTIFICATE] [-s] [--host HOST] [-v {QUIET,INFO,DEBUG}] {add,get,remove,set} ...

AD Privesc Swiss Army Knife

options:
  -h, --help            show this help message and exit
  -d DOMAIN, --domain DOMAIN
                        Domain used for NTLM authentication
  -u USERNAME, --username USERNAME
                        Username used for NTLM authentication
  -p PASSWORD, --password PASSWORD
                        Cleartext password or LMHASH:NTHASH for NTLM authentication
  -k, --kerberos
  -c CERTIFICATE, --certificate CERTIFICATE
                        Certificate authentication, e.g: "path/to/key:path/to/cert"
  -s, --secure          Try to use LDAP over TLS aka LDAPS (default is LDAP)
  --host HOST           Hostname or IP of the DC (ex: my.dc.local or 172.16.1.3)
  -v {QUIET,INFO,DEBUG}, --verbose {QUIET,INFO,DEBUG}
                        Adjust output verbosity

Commands:
  {add,get,remove,set}
    add                 [ADD] function category
    get                 [GET] function category
    remove              [REMOVE] function category
    set                 [SET] function category

Commands Arguments

get Commands

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -c ":bloodyadmin.pem" -s get -h

usage: bloodyAD get [-h] {children,dnsDump,membership,object,search,writable} ...

options:
  -h, --help            show this help message and exit

get commands:
  {children,dnsDump,membership,object,search,writable}
    children            Lists children for a given target object
    dnsDump             Retrieves DNS records of the Active Directory readable/listable by the user
    membership          Retrieves SID and SAM Account Names of all groups a target belongs to
    object              Retrieves LDAP attributes for the target object provided, binary data will be outputed in base64
    search              Searches in LDAP database, binary data will be outputed in base64
    writable            Retrieves objects writable by client

get children

get dnsDump

get membership

get object

get search

get writable

set Commands

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -c ":bloodyadmin.pem" -s set -h

usage: bloodyAD set [-h] {object,owner,password} ...

options:
  -h, --help            show this help message and exit

set commands:
  {object,owner,password}
    object              Add/Replace/Delete target's attribute
    owner               Changes target ownership with provided owner (WriteOwner permission required)
    password            Change password of a user/computer

set object

set owner

set password

$ bloodyAD --host 172.16.1.15 -d bloody.local -u jane.doe -p :70016778cb0524c799ac25b439bd6a31 set password -h
usage: bloodyAD.py set password [-h] [--oldpass OLDPASS] target newpass

positional arguments:
  target             sAMAccountName, DN, GUID or SID of the target
  newpass            new password for the target

options:
  -h, --help         show this help message and exit
  --oldpass OLDPASS  old password of the target, mandatory if you don't have "change password" permission on the target (default: None)

add Commands

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -c ":bloodyadmin.pem" -s add -h
usage: bloodyAD add [-h] {computer,dcsync,dnsRecord,genericAll,groupMember,rbcd,shadowCredentials,uac,user} ...

options:
  -h, --help            show this help message and exit

add commands:
  {computer,dcsync,dnsRecord,genericAll,groupMember,rbcd,shadowCredentials,uac,user}
    computer            Adds new computer
    dcsync              Adds DCSync right on domain to provided trustee (Requires to own or to have WriteDacl on domain object)
    dnsRecord           This function adds a new DNS record into an AD environment.
    genericAll          Gives full control to trustee on target (you must own the object or have WriteDacl)
    groupMember         Adds a new member (user, group, computer) to group
    rbcd                Adds Resource Based Constraint Delegation for service on target, used to impersonate a user on target with service (Requires
                        "Write" permission on target's msDS-AllowedToActOnBehalfOfOtherIdentity and Windows Server >= 2012)
    shadowCredentials   Adds Key Credentials to target, used to impersonate target with added credentials
    uac                 Adds property flags altering user/computer object behavior
    user                Adds a new user

add computer

add dcsync

add dnsRecord

add genericAll

add groupMember

add rbcd

add shadowCredentials

add uac

add user

remove Commands

$ bloodyAD --host 10.1.0.4 -d bloody -u bloodyAdmin -c ":bloodyadmin.pem" -s remove -h

usage: bloodyAD remove [-h] {dcsync,dnsRecord,genericAll,groupMember,object,rbcd,shadowCredentials,uac} ...

options:
  -h, --help            show this help message and exit

remove commands:
  {dcsync,dnsRecord,genericAll,groupMember,object,rbcd,shadowCredentials,uac}
    dcsync              Removes DCSync right for provided trustee
    dnsRecord           Removes a DNS record of an AD environment.
    genericAll          Removes full control of trustee on target
    groupMember         Removes member (user, group, computer) from group
    object              Removes object (user, group, computer, organizational unit, etc)
    rbcd                Removes Resource Based Constraint Delegation for service on target
    shadowCredentials   Removes Key Credentials from target
    uac                 Removes property flags altering user/computer object behavior

remove dcsync

remove dnsRecord

remove genericAll

remove groupMember

remove object

remove rbcd

remove shadowCredentials

remove uac

Cheatsheet

# Get group members
bloodyAD -u john.doe -d bloody -p Password512! --host 192.168.10.2 get object Users --attr member 

# Get minimum password length policy
bloodyAD -u john.doe -d bloody -p Password512! --host 192.168.10.2 get object 'DC=bloody,DC=local' --attr minPwdLength

# Get AD functional level
bloodyAD -u Administrator -d bloody -p Password512! --host 192.168.10.2 get object 'DC=bloody,DC=local' --attr msDS-Behavior-Version

# Get all users of the domain
bloodyAD -u john.doe -d bloody -p Password512! --host 192.168.10.2 get children 'DC=bloody,DC=local' --type user

# Get all computers of the domain
bloodyAD -u john.doe -d bloody -p Password512! --host 192.168.10.2 get children 'DC=bloody,DC=local' --type computer

# Get all containers of the domain
bloodyAD -u john.doe -d bloody -p Password512! --host 192.168.10.2 get children 'DC=bloody,DC=local' --type container

# Enable DONT_REQ_PREAUTH for ASREPRoast
bloodyAD -u Administrator -d bloody -p Password512! --host 192.168.10.2 add uac john.doe DONT_REQ_PREAUTH

# Disable ACCOUNTDISABLE
bloodyAD -u Administrator -d bloody -p Password512! --host 192.168.10.2 remove uac john.doe ACCOUNTDISABLE

# Get UserAccountControl flags
bloodyAD -u Administrator -d bloody -p Password512! --host 192.168.10.2 get object john.doe --attr userAccountControl

# Read GMSA account password
bloodyAD -u john.doe -d bloody -p Password512 --host 192.168.10.2 get object 'gmsaAccount$' --attr msDS-ManagedPassword

# Read LAPS password
bloodyAD -u john.doe -d bloody -p Password512 --host 192.168.10.2 get object 'COMPUTER$' --attr ms-Mcs-AdmPwd

# Read quota for adding computer objects to domain
bloodyAD -u john.doe -d bloody -p Password512! --host 192.168.10.2 get object 'DC=bloody,DC=local' --attr ms-DS-MachineAccountQuota

# Add a new DNS entry
bloodyAD -u stan.dard -p Password123! -d bloody.local --host 192.168.10.2 add dnsRecord my_machine_name 192.168.10.48

# Remove a DNS entry
bloodyAD -u stan.dard -p Password123! -d bloody.local --host 192.168.10.2 remove dnsRecord my_machine_name 192.168.10.48

# Get AD DNS records
bloodyAD -u stan.dard -p Password123! -d bloody.local --host 192.168.10.2 get dnsDump

Clone this wiki locally