Closed
Description
https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse#self-self-membership-on-group
Self (Self-Membership) - ability to add yourself to a group
In Security Settings:
Permission: Add/remove self as member
Permission: All validated writes
This could be hidden privilege as a "member of a privileged group" and be missed in BloodHound path tracing.
In dsacls.exe, it comes up as:
SPECIAL ACCESS
WRITE SELF
Metadata
Metadata
Assignees
Labels
No labels