<aside> 🎯

Access Control List (ACL) Abuse Primer

</aside>

ACLs are lists that define a) who has access to which asset/resource and b) the level of access they are provisioned. The settings themselves in an ACL are called Access Control Entries (ACEs).

There are two types of ACLs:

  1. Discretionary Access Control List (DACL) - defines which security principals are granted or denied access to an object. DACLs are made up of ACEs that either allow or deny access. When someone attempts to access an object, the system will check the DACL for the level of access that is permitted. If a DACL does not exist for an object, all who attempt to access the object are granted full rights. If a DACL exists, but does not have any ACE entries specifying specific security settings, the system will deny access to all users, groups, or processes attempting to access it.
  2. System Access Control Lists (SACL) - allow administrators to log access attempts made to secured objects.

🎯Access Control Entries (ACEs)

There are three main types of ACEs that can be applied to all securable objects in AD:

ACE Description
Access denied ACE Used within a DACL to show that a user or group is explicitly denied access to an object
Access allowed ACE Used within a DACL to show that a user or group is explicitly granted access to an object
System audit ACE Used within a SACL to generate audit logs when a user or group attempts to access an object. It records whether access was granted or not and what type of access occurred

Each ACE is made up of the following four components:

  1. The security identifier (SID) of the user/group that has access to the object (or principal name graphically)
  2. A flag denoting the type of ACE (access denied, allowed, or system audit ACE)
  3. A set of flags that specify whether or not child containers/objects can inherit the given ACE entry from the primary or parent object
  4. An access mask which is a 32-bit value that defines the rights granted to an object

image.png

  1. The security principal is Angela Dunn ([email protected])
  2. The ACE type is Allow
  3. Inheritance applies to the "This object and all descendant objects,” meaning any child objects of the forend object would have the same permissions granted
  4. The rights granted to the object, again shown graphically in this example