AD-DACL-09 - Privileged allow ACE count should be retrievable
Overviewβ
Allow ACEs that grant GenericAll, WriteDacl, WriteOwner, or ExtendedRight can enable high-impact control over Active Directory objects. These permissions are commonly involved in privilege escalation and persistence paths.
- GenericAll: Grants broad control over the object.
- WriteDacl / WriteOwner: Enables permission tampering or ownership takeover.
- ExtendedRight: May allow sensitive control-access operations depending on object type.
Security Recommendationβ
Limit privileged rights to tightly controlled administrative groups. Investigate unexpected identities or objects that accumulate these permissions.
How the Test Worksβ
This test reads DaclEntries from Get-MtADDomainState, filters to allow ACEs, and counts entries where ActiveDirectoryRights includes GenericAll, WriteDacl, WriteOwner, or ExtendedRight.
Related Testsβ
Test-MtAdDaclPrivilegedAllowAceDetailsTest-MtAdDaclPrivilegedExtendedRightCountTest-MtAdDaclDistinctIdentityCount
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DACL-09 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DACL |
| PowerShell test | Test-MtAdDaclPrivilegedAllowAceCount |
| Tags | AD, AD-DACL-09, AD.DACL |
Sourceβ
- Pester test:
tests/ad/dacl/Test-MtAdDaclPrivilegedAllowAceCount.Tests.ps1 - PowerShell source:
powershell/public/ad/dacl/Test-MtAdDaclPrivilegedAllowAceCount.ps1

