⬩ PASTE & ANALYZE
// DACL PASTE & ANALYZE

Paste DACL / ACE Output — Get Attack Paths

Drop in a file or paste below. Accepts raw Get-DomainObjectAcl console output (PowerView, -ResolveGUIDs optional), Export-Csv, ConvertTo-Json, and now Excel/CSV permission exports that use friendly names (Object Path / Permissions / Account Name, e.g. Netwrix, ADManager, ADUC) — those are translated to the AD rights enum automatically. All analysis is client-side — nothing leaves your browser, and the .xlsx reader is built in, with no third-party library.

// INPUT — ACE DATA
⚖ TIER 0 BASELINE — expected grants collapsed
My baseline — service accounts and delegated groups that are expected in this environment
Paste ACE data above to begin
Finds GenericAll / WriteDacl / WriteOwner, RBCD, Shadow Credentials, DCSync, LAPS disclosure, Self-Membership, GPO hijack, and more