DCSync
1. View Group Membership of a Specific User
Command:
Get-DomainUser -Identity adunn | select samaccountname,objectsid,memberof,useraccountcontrol | fl2. Check User's Replication Rights
Command:
$sid= "S-1-5-21-3842939050-3880317879-2865463114-1164"
Get-ObjectAcl "DC=inlanefreight,DC=local" -ResolveGUIDs | ? { ($_.ObjectAceType -match 'Replication-Get')} | ?{$_.SecurityIdentifier -match $sid} | select AceQualifier, ObjectDN, ActiveDirectoryRights,SecurityIdentifier,ObjectAceType | fl3. Extract NTLM Hashes from NTDS.dit
Command:
4. Perform a DCSync Attack Using Mimikatz
Command:
Last updated