DCSync Attacks
Active Directory (AD) DCSync attacks exploit the Directory Synchronization (DCSync) protocol to exfiltrate the NTDS.dit database, which contains all user accounts, passwords, and other sensitive information. This attack is often enabled by Unconstrained Delegation, where a service account is configured to delegate credentials without restrictions. Attackers use stolen credentials (e.g., via Kerberoasting or password spraying) to authenticate to a Domain Controller (DC) and perform DCSync operations, effectively copying the AD database.
Overview of DCSync¶
DCSync is a Kerberos-based protocol that allows a service to synchronize its directory data with a DC. By default, this is limited to domain controllers, but misconfigured Unconstrained Delegation grants attackers the ability to impersonate a DC and request directory data. The NTDS.dit file, stored on DCs, is the core of AD’s directory structure. Exfiltrating it provides attackers with a complete snapshot of the domain’s users, groups, and permissions. However, the hashes within NTDS.dit are encrypted using AES-KDP, not Kerberos. Kerberos enables authentication for DCSync operations, while the DC decrypts hashes during authentication using its own cryptographic mechanisms.
Exploitation via Unconstrained Delegation¶
Unconstrained Delegation is a critical enabler for DCSync attacks. When a service account (e.g., MSSQLSvc/DC01) is configured with this setting, it can request a Kerberos Ticket Granting Ticket (TGT) for itself and use it to impersonate the DC. Attackers exploit this by:
1. Obtaining service account credentials (e.g., via Kerberoasting or brute-force).
2. Using those credentials to authenticate to a DC and initiate DCSync.
3. Exfiltrating the NTDS.dit database via LDAP queries.
This process bypasses traditional authentication mechanisms, allowing attackers to access sensitive data without needing domain admin privileges. Kerberos tickets authenticate the request, but the DC decrypts AES-KDP-encrypted hashes during access, not Kerberos itself.
Attack Process¶
- Credential Harvesting: Attackers use tools like
kerberoastorcrackmapexecto extract service account hashes. - DCSync Execution: With stolen credentials, attackers use tools like Mimikatz to perform DCSync:
This command connects to the DC, authenticates with the stolen credentials, and retrieves directory data. - Data Exfiltration: The attacker extracts the NTDS.dit file, which contains AES-KDP-encrypted hashes, user passwords, and group memberships. Encryption ensures plaintext hashes are never exposed during exfiltration.
Tools and Commands¶
- Mimikatz: A popular tool for performing DCSync attacks. Example:
- BloodHound: Analyzes the attack graph to identify vulnerable service accounts.
- Kerberoast: Extracts service account hashes via Kerberos AS-REP roast.
Mitigation Strategies¶
- Disable Unconstrained Delegation: Ensure no service accounts have this setting enabled.
- Monitor for DCSync Requests: Use SIEM tools to detect LDAP queries from non-DC hosts.
- Limit Privileged Accounts: Restrict access to critical services and enforce strong password policies.
- Regular Audits: Validate delegation configurations and review service account permissions.
Key takeaways¶
- DCSync exploits Kerberos to authenticate DCSync requests, while NTDS.dit encryption uses AES-KDP. The DC decrypts hashes during authentication, not Kerberos itself.
- Attackers use stolen service account credentials to impersonate DCs and retrieve sensitive data through LDAP queries.
- Tools like Mimikatz and Kerberoast are critical for executing and detecting DCSync attacks.
- Mitigation requires strict delegation controls, monitoring, and regular audits.
- DCSync is a high-impact attack vector that compromises the entire AD environment.