Case F614A7 · Identity & AD · L3 Applied
DCSync
Practise as: Explain it · Interview
Interview questionAn attacker ran DCSync. What rights did they need and how do you spot it?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Abuses directory replication (MS-DRSR DRSGetNCChanges) to request password hashes from a DC as if it were another DC
- Needs Replicating Directory Changes + Changes All rights: held by Domain/Enterprise Admins and DCs by default
- Detect: 4662 events with the replication GUIDs from a non-DC account, or DRSUAPI traffic from a workstation IP
- Prevent: audit who holds replication rights (BloodHound, ACL reviews) and keep that list to DCs and a few admins
- Treat as full domain compromise: krbtgt and privileged hashes are exposed, so plan krbtgt and admin resets
If the interviewer pushes back
- Why is network-level detection of DRSUAPI from non-DCs often more reliable than 4662 alone?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.