Exploit Active Directory replication privileges (DS-Replication-Get-Changes) to perform a DCSync attack, allowing an attacker to impersonate a Domain Controller and extract password hashes (like the krbtgt hash for Golden Tickets) without code execution on a DC.
Installation
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Exploit Active Directory replication privileges (DS-Replication-Get-Changes) to perform a DCSync attack, allowing an attacker to impersonate a Domain Controller and extract password hashes (like the krbtgt hash for Golden Tickets) without code execution on a DC.
When an attacker has compromised an account or group with the highly privileged DS-Replication-Get-Changes and DS-Replication-Get-Changes-All rights (often Domain Admins or maliciously delegated accounts).
To stealthily extract NTLM hashes (including the krbtgt account hash) directly from Active Directory over the network, avoiding the need to execute code or drop malware directly on a Domain Controller.
Prerequisites
Authorized scope and rules of engagement for the target environment
Appropriate tools installed on the attack/analysis platform
Understanding of the target technology stack and architecture
Documentation template ready for findings and evidence capture
Workflow
Phase 1: Identifying the Target (krbtgt) and Access Rights