Exploit Active Directory replication privileges (DS-Replication-Get-Changes) to perform a DCSync attack, allowing an attacker to impersonate a Domain Controller and extract password hashes (like the krbtgt hash for Golden Tickets) without code execution on a DC.
インストール
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
Exploit Active Directory replication privileges (DS-Replication-Get-Changes) to perform a DCSync attack, allowing an attacker to impersonate a Domain Controller and extract password hashes (like the krbtgt hash for Golden Tickets) without code execution on a DC.
When an attacker has compromised an account or group with the highly privileged DS-Replication-Get-Changes and DS-Replication-Get-Changes-All rights (often Domain Admins or maliciously delegated accounts).
To stealthily extract NTLM hashes (including the krbtgt account hash) directly from Active Directory over the network, avoiding the need to execute code or drop malware directly on a Domain Controller.
Prerequisites
Authorized scope and rules of engagement for the target environment
Appropriate tools installed on the attack/analysis platform
Understanding of the target technology stack and architecture
Documentation template ready for findings and evidence capture
Workflow
Phase 1: Identifying the Target (krbtgt) and Access Rights