{"id":13389744,"url":"https://github.com/HarmJ0y/DAMP","last_synced_at":"2025-03-13T14:31:55.688Z","repository":{"id":44454128,"uuid":"128475490","full_name":"HarmJ0y/DAMP","owner":"HarmJ0y","description":"The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification","archived":false,"fork":false,"pushed_at":"2019-07-25T21:18:37.000Z","size":28,"stargazers_count":377,"open_issues_count":5,"forks_count":78,"subscribers_count":19,"default_branch":"master","last_synced_at":"2025-02-28T11:42:22.472Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"PowerShell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-3-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/HarmJ0y.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2018-04-06T22:13:58.000Z","updated_at":"2025-02-16T11:50:35.000Z","dependencies_parsed_at":"2022-08-04T02:00:21.849Z","dependency_job_id":null,"html_url":"https://github.com/HarmJ0y/DAMP","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/HarmJ0y%2FDAMP","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/HarmJ0y%2FDAMP/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/HarmJ0y%2FDAMP/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/HarmJ0y%2FDAMP/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/HarmJ0y","download_url":"https://codeload.github.com/HarmJ0y/DAMP/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":243422600,"owners_count":20288488,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-07-30T13:01:29.842Z","updated_at":"2025-03-13T14:31:55.389Z","avatar_url":"https://github.com/HarmJ0y.png","language":"PowerShell","funding_links":[],"categories":["PowerShell","PowerShell (153)"],"sub_categories":[],"readme":"# DAMP\nThe Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.\n\nThis project contains several files that implement host-based security descriptor \"backdoors\" that facilitate the abuse of various remotely accessible services for arbitrary trustees/security principals.\n\n__tl;dr__ - this grants users/groups (local, domain, or 'well-known' like 'Everyone') of an attacker's choosing the ability to perform specific administrative actions on a modified host without needing membership in the local administrators group.\n\n__Note:__ to implement these backdoors, you need the right to change the security descriptor information for the targeted service, which in stock configurations nearly always means membership in the local administrators group.\n\nMore information:\n\n* [An ACE in the Hole - Stealthy Host Persistence via Security Descriptors](https://www.slideshare.net/harmj0y/an-ace-in-the-hole-stealthy-host-persistence-via-security-descriptors)\n* [The Unintended Risks of Trusting Active Directory ](https://www.slideshare.net/harmj0y/the-unintended-risks-of-trusting-active-directory)\n\n__Authors:__ [@tifkin_](https://twitter.com/tifkin\\_), [@enigma0x3](https://twitter.com/enigma0x3), and [@harmj0y](https://twitter.com/harmj0y).\n\n__License:__ BSD 3-Clause\n\n## Remote Registry\n\n### Add-RemoteRegBackdoor.ps1\n\n#### Add-RemoteRegBackdoor\n\nImplements a new remote registry backdoor that allows for the remote retrieval of a system's machine and local account hashes, as well as its domain cached credentials.\n\n### RemoteHashRetrieval.ps1\n\n#### Get-RemoteMachineAccountHash\n\nAbuses the ACL backdoor set by Add-RemoteRegBackdoor to remotely retrieve the local machine account hash for the specified machine.\n\n#### Get-RemoteLocalAccountHash\n\nAbuses the ACL backdoor set by Add-RemoteRegBackdoor to remotely retrieve the local SAM account hashes for the specified machine.\n\n#### Get-RemoteCachedCredential\n\nAbuses the ACL backdoor set by Add-RemoteRegBackdoor to remotely retrieve the domain cached credentials for the specified machine.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FHarmJ0y%2FDAMP","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FHarmJ0y%2FDAMP","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FHarmJ0y%2FDAMP/lists"}