DCSync

T1003.006

Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org

About this technique

Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API) to simulate the replication process from a remote domain controller using a technique called DCSync.

Members of the Administrators, Domain Admins, and Enterprise Admin groups or computer accounts on the domain controller are able to run DCSync to pull password data from Active Directory, which may include current and historical hashes of potentially useful accounts such as KRBTGT and Administrators. The hashes can then in turn be used to create a Golden Ticket for use in Pass the Ticket or change an account's password as noted in Account Manipulation.

DCSync functionality has been included in the "lsadump" module in Mimikatz. Lsadump also includes NetSync, which performs DCSync over a legacy replication protocol.

Detection rules10

Rules on DetectionCode tagged with T1003.006.

Sigma7

Splunk3

RuleTypeRiskData source
Windows AD Replication Request Initiated by User AccountTTPNULLWindows Event Log Security 4662, Windows Event Log Security 4624
Windows AD Replication Request Initiated from Unsanctioned LocationTTPNULLWindows Event Log Security 4662, Windows Event Log Security 4624
Windows AD Replication Service TrafficTTPNULL

Groups4

Software1

Campaigns3

Procedure examples8

Groups4

Used byProcedure example
GroupEarth Lusca

Earth Lusca has used a DCSync command with Mimikatz to retrieve credentials from an exploited controller.

GroupLAPSUS$

LAPSUS$ has used DCSync attacks to gather credentials for privilege escalation routines.

GroupMustang Panda

Mustang Panda has leveraged Mimikatz DCSync feature to obtain user credentials.

GroupStorm-0501

Storm-0501 has utilized DCSync to extract credentials from victims.

Software1

Used byProcedure example
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DCSync/NetSync.

Campaigns3

Used byProcedure example
CampaignC0027

During C0027, Scattered Spider performed domain replication.

CampaignOperation Wocao

During Operation Wocao, threat actors used Mimikatz's DCSync to dump credentials from the memory of the targeted system.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers.

References9

  1. ADSecurity Mimikatz DCSync Open source
    Metcalf, S. (2015, September 25). Mimikatz DCSync Usage, Exploitation, and Detection. Retrieved August 7, 2017.
  2. GitHub Mimikatz lsadump Module Open source
    Deply, B., Le Toux, V. (2016, June 5). module ~ lsadump. Retrieved August 7, 2017.
  3. Harmj0y Mimikatz and DCSync Open source
    Schroeder, W. (2015, September 22). Mimikatz and DCSync and ExtraSids, Oh My. Retrieved September 23, 2024.
  4. InsiderThreat ChangeNTLM July 2017 Open source
    Warren, J. (2017, July 11). Manipulating User Passwords with Mimikatz. Retrieved December 4, 2017.
  5. Microsoft DRSR Dec 2017 Open source
    Microsoft. (2017, December 1). MS-DRSR Directory Replication Service (DRS) Remote Protocol. Retrieved December 4, 2017.
  6. Microsoft GetNCCChanges Open source
    Microsoft. (n.d.). IDL_DRSGetNCChanges (Opnum 3). Retrieved December 4, 2017.
  7. Microsoft NRPC Dec 2017 Open source
    Microsoft. (2017, December 1). MS-NRPC - Netlogon Remote Protocol. Retrieved December 6, 2017.
  8. Samba DRSUAPI Open source
    SambaWiki. (n.d.). DRSUAPI. Retrieved December 4, 2017.
  9. Wine API samlib.dll Open source
    Wine API. (n.d.). samlib.dll. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.