Open cardosec

Case F614A7 · Identity & AD · L3 Applied

DCSync

Practise as: Explain it · Interview

Interview questionAn attacker ran DCSync. What rights did they need and how do you spot it?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Abuses directory replication (MS-DRSR DRSGetNCChanges) to request password hashes from a DC as if it were another DC
  2. Needs Replicating Directory Changes + Changes All rights: held by Domain/Enterprise Admins and DCs by default
  3. Detect: 4662 events with the replication GUIDs from a non-DC account, or DRSUAPI traffic from a workstation IP
  4. Prevent: audit who holds replication rights (BloodHound, ACL reviews) and keep that list to DCs and a few admins
  5. Treat as full domain compromise: krbtgt and privileged hashes are exposed, so plan krbtgt and admin resets

If the interviewer pushes back

  • Why is network-level detection of DRSUAPI from non-DCs often more reliable than 4662 alone?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.