Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org
Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API) to simulate the replication process from a remote domain controller using a technique called DCSync.
Members of the Administrators, Domain Admins, and Enterprise Admin groups or computer accounts on the domain controller are able to run DCSync to pull password data from Active Directory, which may include current and historical hashes of potentially useful accounts such as KRBTGT and Administrators. The hashes can then in turn be used to create a Golden Ticket for use in Pass the Ticket or change an account's password as noted in Account Manipulation.
DCSync functionality has been included in the "lsadump" module in Mimikatz. Lsadump also includes NetSync, which performs DCSync over a legacy replication protocol.
Rules on DetectionCode tagged with T1003.006.
| Rule | Level | Log source |
|---|---|---|
| Credential Dumping Tools Service Execution - Security | high | windows / NULL |
| Credential Dumping Tools Service Execution - System | high | windows / NULL |
| HackTool - Mimikatz Execution | high | windows / process_creation |
| Mimikatz Use | high | windows / NULL |
| Active Directory Replication from Non Machine Account - DcSync Indicator | medium | windows / NULL |
| Suspicious Get-ADReplAccount | medium | windows / ps_script |
| Suspicious Machine Account Replication - DcSync Indicator | medium | windows / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows AD Replication Request Initiated by User Account | TTP | NULL | Windows Event Log Security 4662, Windows Event Log Security 4624 |
| Windows AD Replication Request Initiated from Unsanctioned Location | TTP | NULL | Windows Event Log Security 4662, Windows Event Log Security 4624 |
| Windows AD Replication Service Traffic | TTP | NULL |
| Used by | Procedure example |
|---|---|
| GroupEarth Lusca | Earth Lusca has used a |
| GroupLAPSUS$ | LAPSUS$ has used DCSync attacks to gather credentials for privilege escalation routines. |
| GroupMustang Panda | Mustang Panda has leveraged Mimikatz DCSync feature to obtain user credentials. |
| GroupStorm-0501 | Storm-0501 has utilized DCSync to extract credentials from victims. |
| Used by | Procedure example |
|---|---|
| ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DCSync/NetSync. |
| Used by | Procedure example |
|---|---|
| CampaignC0027 | During C0027, Scattered Spider performed domain replication. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used Mimikatz's DCSync to dump credentials from the memory of the targeted system. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.