DCSync
Descripción
Verificar privilegios de replicación de dominio
# PowerView
$sid = Convert-NameToSid <user>
Get-ObjectAcl "DC=ACME,DC=LOCAL" -ResolveGUIDs | ? { ($_.ObjectAceType -match 'Replication-Get')} | ?{$_.SecurityIdentifier -match $sid} | Select AceQualifier, ObjectDN, ActiveDirectoryRights, SecurityIdentifier, ObjectAceType | flAlmacenamiento de contraseña de cifrado reversible
Módulo ActiveDirectory PowerShell
Get-ADUser -Filter 'userAccountControl -band 128' -Properties userAccountControlPowerView
Impacket
Mimikatz
Invoke-Mimikatz
Última actualización