Active Directory is the beating heart of identity in most enterprises, and its single most valuable secret is the password hash of every user, service, and machine account. A DCSync attack lets an adversary walk out with those hashes without ever logging into a domain controller, dropping a tool on it, or reading the NTDS.dit database off disk. Instead, the attacker simply asks a domain controller to hand the secrets over, using the very same replication protocol that domain controllers use to synchronize with one another. Technically, DCSync impersonates a domain controller and issues a directory-replication request over the Microsoft Directory Replication Service Remote Protocol (MS-DRSR). The stages of a DCSync attack, from...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!