Thrilled to share my first blog at @splunk! @mhaggis.bsky.social and I take a deep dive into the weird & exciting world of SDDL and ACEs - what they are, how they work, and how attackers can abuse them.
Thrilled to share my first blog at @splunk! @mhaggis.bsky.social and I take a deep dive into the weird & exciting world of SDDL and ACEs - what they are, how they work, and how attackers can abuse them.
Windows permissions misconfigurations are a goldmine for attackers. SDDL (Security Descriptor Definition Language) remains overlooked yet highly exploitable. 🚨
@nasbench.bsky.social and I break it down -->
🧵 (1/)
Windows permissions misconfigurations are a goldmine for attackers. SDDL (Security Descriptor Definition Language) remains overlooked yet highly exploitable. 🚨
@nasbench.bsky.social and I break it down -->
🧵 (1/)
SddlString
SddlString
At #PSConfEU 2025, @it-pro-berlin.de showed how to scale #PowerShell with:
✔ OpenAD
✔ Indexed queries
✔ Smart group handling & SDDL tips
🎟️ Early bird 2026 → psconf.eu
#ActiveDirectory #Automation
At #PSConfEU 2025, @it-pro-berlin.de showed how to scale #PowerShell with:
✔ OpenAD
✔ Indexed queries
✔ Smart group handling & SDDL tips
🎟️ Early bird 2026 → psconf.eu
#ActiveDirectory #Automation
1️⃣ How attackers exploit SDDL—event log tampering, service hardening, & more
2️⃣ How to decode SDDL strings & analyze permissions, DACLs, and ACEs
3️⃣ How to defend against SDDL abuse with detections & Atomic Red Team tests
🧵 (3/)
1️⃣ How attackers exploit SDDL—event log tampering, service hardening, & more
2️⃣ How to decode SDDL strings & analyze permissions, DACLs, and ACEs
3️⃣ How to defend against SDDL abuse with detections & Atomic Red Team tests
🧵 (3/)
Link: github.com/WildByDesign/ACLViewer
Link: github.com/WildByDesign/ACLViewer
👉 https://thesddlmaker.streamlit.app/
📜 Read the full blog:
🔗 https://www.splunk.com/en_us/blog/security/windows-security-sddl-guide-access-control.html
🧵 (4/)
👉 https://thesddlmaker.streamlit.app/
📜 Read the full blog:
🔗 https://www.splunk.com/en_us/blog/security/windows-security-sddl-guide-access-control.html
🧵 (4/)
At #PSConfEU 2025, @it-pro-berlin.de showed how to scale #PowerShell with:
✔ OpenAD
✔ Indexed queries
✔ Smart group handling & SDDL tips
🎟️ Early bird 2026 → psconf.eu
#ActiveDirectory #Automation
At #PSConfEU 2025, @it-pro-berlin.de showed how to scale #PowerShell with:
✔ OpenAD
✔ Indexed queries
✔ Smart group handling & SDDL tips
🎟️ Early bird 2026 → psconf.eu
#ActiveDirectory #Automation
➡️ https://l.ici.fr/sddl
➡️ https://l.ici.fr/sddl
🔹 How attackers—from LockBit to RomCom—manipulate it for privilege escalation & defense evasion
🔹 How to detect & defend 🛡️
🧵 (2/)
🔹 How attackers—from LockBit to RomCom—manipulate it for privilege escalation & defense evasion
🔹 How to detect & defend 🛡️
🧵 (2/)
At #PSConfEU 2025, @it-pro-berlin.de showed how to scale #PowerShell with:
✔ OpenAD
✔ Indexed queries
✔ Smart group handling & SDDL tips
🎟️ Early bird 2026 → psconf.eu
#ActiveDirectory #Automation
At #PSConfEU 2025, @it-pro-berlin.de showed how to scale #PowerShell with:
✔ OpenAD
✔ Indexed queries
✔ Smart group handling & SDDL tips
🎟️ Early bird 2026 → psconf.eu
#ActiveDirectory #Automation
🔗 https://research.splunk.com/stories/defense_evasion_or_unauthorized_access_via_sddl_tampering/
🧠 Mind Map:
🔗 https://github.com/MHaggis/SDDLMaker/tree/main/MindMap
🧵 (5/)
🔗 https://research.splunk.com/stories/defense_evasion_or_unauthorized_access_via_sddl_tampering/
🧠 Mind Map:
🔗 https://github.com/MHaggis/SDDLMaker/tree/main/MindMap
🧵 (5/)
▶️ https://www.youtube.com/watch?v=uSYvHUVU8xY
🔄 RT/Reshare if you find this useful! 🚀
#WindowsSecurity #SDDL #Cybersecurity #Splunk #AtomicRedTeam
▶️ https://www.youtube.com/watch?v=uSYvHUVU8xY
🔄 RT/Reshare if you find this useful! 🚀
#WindowsSecurity #SDDL #Cybersecurity #Splunk #AtomicRedTeam
engineering.fb.com/2025/10/06/d...
engineering.fb.com/2025/10/06/d...
🌐 cyber[.]netsecops[.]io
🌐 cyber[.]netsecops[.]io
www.youtube.com/watch?v=sddl...
www.youtube.com/watch?v=sddl...