What protocol does DCSync exploit to replicate credentials?

DCSync exploits the Directory Replication Service (DRS) protocol, specifically the IDL_DRSGetNCChanges method, to request replication of user credentials from a domain controller. This protocol is normally used by domain controllers to synchronize directory information. --- **Related reading:** - [Domain Penetration - DCSync](/news/domain-penetration-dcsync) — original article - [An interesting way of bypassing Windows Attachment Manager](/news/an-interesting-way-of-bypassing-windows-attachment-manager) - [Penetration Techniques - Exploitation of Nine Windows Privileges](/news/penetration-techniques-exploitation-of-nine-windows-privileges) - [Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin Mode)](/news/penetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode)