< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Hackers exploit Active Directory replication to steal password hashes

Cybersecurity threats involving the DCSync attack technique are gaining attention as attackers exploit legitimate Active Directory replication processes to steal sensitive credential data.

By impersonating a domain controller, threat actors can use the Directory Replication Service Remote Protocol (DRSUAPI) to request password hashes and Kerberos material from legitimate servers. This method is particularly dangerous because it does not require the deployment of malware directly onto a domain controller, making it difficult to distinguish from authorized synchronization traffic.

Once attackers compromise an account with sufficient replication permissions or Domain Admin privileges, they can obtain NTLM password hashes and Kerberos keys. A critical risk involves the theft of the KRBTGT account hash, which can allow attackers to create ‘Golden Tickets,’ providing persistent, high-level access to the entire domain that remains even after initial compromised passwords are changed.

Entities

Active Directory · Impacket · Microsoft · Mimikatz