Exploit Active Directory replication privileges (DS-Replication-Get-Changes) to perform a DCSync attack, allowing an attacker to impersonate a Domain Controller and extract password hashes (like the krbtgt hash for Golden Tickets) without code execution on a DC.
설치
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
Exploit Active Directory replication privileges (DS-Replication-Get-Changes) to perform a DCSync attack, allowing an attacker to impersonate a Domain Controller and extract password hashes (like the krbtgt hash for Golden Tickets) without code execution on a DC.
When an attacker has compromised an account or group with the highly privileged DS-Replication-Get-Changes and DS-Replication-Get-Changes-All rights (often Domain Admins or maliciously delegated accounts).
To stealthily extract NTLM hashes (including the krbtgt account hash) directly from Active Directory over the network, avoiding the need to execute code or drop malware directly on a Domain Controller.
Prerequisites
Authorized scope and rules of engagement for the target environment
Appropriate tools installed on the attack/analysis platform
Understanding of the target technology stack and architecture
Documentation template ready for findings and evidence capture
Workflow
Phase 1: Identifying the Target (krbtgt) and Access Rights