Theory
Controllers synchronize the database between themselves via the replication protocol (DRSUAPI). To request replication you need a special right: (and in practice also Replicating Directory Changes All) on the domain object.
exploits this: the attacker impersonates a DC and asks the real DC to «replicate the data to me». In response they receive the password hashes of every account — including KRBTGT (the basis for a ) and Administrator. Everything happens over the network, without copying the NTDS.dit file and without running code on the DC.
Who holds these rights by default? Admins, Enterprise Admins, Administrators, and the DCs themselves. The problem starts when the right is mistakenly delegated to groups or service accounts — and that happens surprisingly often.
Practice — lab only
Detection
- Event ID 4662 on the DC — access to the domain object with the replication GUIDs: 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 and 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2.
- The suspicion: 4662 with these GUIDs from an account that is not a — legitimate DCs replicate all the time, users do not.
- Replication originating from an IP address that is not a DC — almost always .
- Dedicated Sigma rules exist — search for «» in the catalog.
Mitigation
- Rights audit: who holds / All on the domain? In : the GetChanges / GetChangesAll edges.
- Remove the rights from anyone who is not a DC or an infrastructure account that truly requires them — every such account is an «extra DC» you do not know about.
- Protect the privileged accounts with Tiering and PAW — they are equivalent to Admin.
- After a suspected compromise: reset the KRBTGT password twice, with an interval — otherwise existing Golden Tickets keep working.