DCSync (T1003.006)

View on ATT&CK

In Playbook

Associated Tactics

  • Credential Access

Credential Access (TA0006)

The adversary is trying to steal account names and passwords. Credential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.

View on ATT&CK

Procedure Examples

Description Source(s)
Deply, B., Le Toux, V. (2016, June 5). module ~ lsadump. Retrieved August 7, 2017. GitHub Mimikatz lsadump Module
Metcalf, S. (2015, September 25). Mimikatz DCSync Usage, Exploitation, and Detection. Retrieved August 7, 2017. ADSecurity Mimikatz DCSync
Metcalf, S. (2015, September 25). Mimikatz DCSync Usage, Exploitation, and Detection. Retrieved December 4, 2017. AdSecurity DCSync Sept 2015
Microsoft. (2017, December 1). MS-DRSR Directory Replication Service (DRS) Remote Protocol. Retrieved December 4, 2017. Microsoft DRSR Dec 2017
Microsoft. (2017, December 1). MS-NRPC - Netlogon Remote Protocol. Retrieved December 6, 2017. Microsoft NRPC Dec 2017
Microsoft. (n.d.). IDL_DRSGetNCChanges (Opnum 3). Retrieved December 4, 2017. Microsoft GetNCCChanges
Microsoft. (n.d.). MS-SAMR Security Account Manager (SAM) Remote Protocol (Client-to-Server) - Transport. Retrieved December 4, 2017. Microsoft SAMR
SambaWiki. (n.d.). DRSUAPI. Retrieved December 4, 2017. Samba DRSUAPI
Schroeder, W. (2015, September 22). Mimikatz and DCSync and ExtraSids, Oh My. Retrieved December 4, 2017. Harmj0y DCSync Sept 2015
Schroeder, W. (2015, September 22). Mimikatz and DCSync and ExtraSids, Oh My. Retrieved September 23, 2024. Harmj0y Mimikatz and DCSync
Warren, J. (2017, July 11). Manipulating User Passwords with Mimikatz. Retrieved December 4, 2017. InsiderThreat ChangeNTLM July 2017
Wine API. (n.d.). samlib.dll. Retrieved December 4, 2017. Wine API samlib.dll