-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathdcsync.yaml
87 lines (87 loc) · 1.93 KB
/
dcsync.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
---
title: T1003.006 - DCSYNC
tactic:
- TA0006
technique: T1003.006
techniquename: DCSYNC
description:
header:
name: T1003.006 - DCSYNC
colspan: 4
rows:
- Row1:
name: Tools
style:
- red: 230
- green: 159
- blue: 0
entries:
- Mimikatz:
name: Mimikatz lsadump::dcsync
attributes:
- colspan: 1
- Empire:
name: Empire Invoke-DCSync.ps1
attributes:
- colspan: 1
- Impacket:
name: Impacket secretdump.py
attributes:
- colspan: 1
- Row2:
name: Extended Rights
style:
- red: 86
- green: 180
- blue: 233
entries:
- extendedrights:
# yamllint disable-line rule:line-length
name: 0x100 - Control Access </br> {19195a5b-6da0–11d0-afd3–00c04fd930c9} — Domain-DNS Class(Object) </br> {1131f6ad-9c07–11d1-f79f-00c04fc2dcd2}- DS-Replication-Get-Changes-All(Extended Right)
attributes:
- colspan: 3
- Row3:
name: RPC Protocol
style:
- red: 0
- green: 158
- blue: 115
entries:
- rpc:
name: Directory Replication Service
attributes:
- colspan: 3
- Row4:
name: RPC Interface
style:
- red: 240
- green: 228
- blue: 66
entries:
- rpcinterface:
# yamllint disable-line rule:line-length
name: DRSUAPI (e3514235-4b06-11d1-ab04-00c04fc2dcd2) </br> C:\windows\system32\ntdsai.dll </br> C:\windows\system32\ntdsapi.dll
attributes:
- colspan: 3
- Row5:
name: RPC Method
style:
- red: 213
- green: 94
- blue: 0
entries:
- rpcmethod:
name: GetNCChanges REQ/REPLY
attributes:
- colspan: 3
- Row6:
name: Behavior
style:
- red: 204
- green: 121
- blue: 167
entries:
- behavior:
name: Replication of a NC Replica
attributes:
- colspan: 3