Skip to main content
AD Academy
Attacks on AD
Advanced16 minLast updated: Topic 6 of 7

DCSync — «I am a Domain Controller too»

Forged AD replication: anyone with Replicating Directory Changes rights asks the DC for all the hashes — without touching NTDS.dit.

Not read

What you will learn here

  • How AD replication works and why it is permission-based
  • What DCSync does and which rights it requires
  • How to detect DCSync in the logs and how to block it

Worth reading first:Pass-the-Hash and Pass-the-TicketKerberoasting

Theory

Controllers synchronize the database between themselves via the replication protocol (DRSUAPI). To request replication you need a special right: (and in practice also Replicating Directory Changes All) on the domain object.

exploits this: the attacker impersonates a DC and asks the real DC to «replicate the data to me». In response they receive the password hashes of every account — including KRBTGT (the basis for a ) and Administrator. Everything happens over the network, without copying the NTDS.dit file and without running code on the DC.

Who holds these rights by default? Admins, Enterprise Admins, Administrators, and the DCs themselves. The problem starts when the right is mistakenly delegated to groups or service accounts — and that happens surprisingly often.

Practice — lab only

# DCSync with Mimikatz — dumping hash of KRBTGT
mimikatz # lsadump::dcsync /domain:corp.local /user:krbtgt
# or specific account:
mimikatz # lsadump::dcsync /domain:corp.local /user:Administrator
powershell
# Same operation from Linux with impacket
secretsdump.py corp.local/attacker:'Password123'@dc01.corp.local -just-dc-user krbtgt
bash

Detection

  • Event ID 4662 on the DC — access to the domain object with the replication GUIDs: 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 and 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2.
  • The suspicion: 4662 with these GUIDs from an account that is not a — legitimate DCs replicate all the time, users do not.
  • Replication originating from an IP address that is not a DC — almost always .
  • Dedicated Sigma rules exist — search for «» in the catalog.

Mitigation

  • Rights audit: who holds / All on the domain? In : the GetChanges / GetChangesAll edges.
  • Remove the rights from anyone who is not a DC or an infrastructure account that truly requires them — every such account is an «extra DC» you do not know about.
  • Protect the privileged accounts with Tiering and PAW — they are equivalent to Admin.
  • After a suspected compromise: reset the KRBTGT password twice, with an interval — otherwise existing Golden Tickets keep working.

Check yourself

Which rights does a DCSync attack require?

What is DCSync's advantage over stealing NTDS.dit?

Which Event ID is the main indicator of DCSync?

What do you do after discovering the KRBTGT hash was exposed?

Was this page helpful?