mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-30 16:06:52 +03:00
Initial commit - 611 cybersecurity skills across all subdomains
This commit is contained in:
@@ -0,0 +1,26 @@
|
||||
# Standards and References - DCSync Domain Persistence
|
||||
|
||||
## MITRE ATT&CK References
|
||||
|
||||
| Technique ID | Name | Tactic |
|
||||
|-------------|------|--------|
|
||||
| T1003.006 | OS Credential Dumping: DCSync | Credential Access |
|
||||
| T1558.001 | Steal or Forge Kerberos Tickets: Golden Ticket | Credential Access |
|
||||
| T1222.001 | File and Directory Permissions Modification | Defense Evasion |
|
||||
| T1098 | Account Manipulation | Persistence |
|
||||
| T1078.002 | Valid Accounts: Domain Accounts | Persistence |
|
||||
|
||||
## Key Research
|
||||
|
||||
- MITRE ATT&CK T1003.006: https://attack.mitre.org/techniques/T1003/006/
|
||||
- Netwrix: DCSync Attack Using Mimikatz Detection
|
||||
- JumpCloud: What Is DCSync? Critical AD Attack Explained
|
||||
- The Hacker Recipes: DCSync technique documentation
|
||||
- Atomic Red Team T1003.006 test procedures
|
||||
|
||||
## Threat Actor Usage
|
||||
|
||||
- APT28 (Fancy Bear) - DCSync for credential harvesting
|
||||
- APT29 (Cozy Bear) - SolarWinds campaign used DCSync
|
||||
- FIN6 - Financial cybercrime group
|
||||
- Wizard Spider - Ryuk ransomware campaigns
|
||||
@@ -0,0 +1,38 @@
|
||||
# Workflows - DCSync Domain Persistence
|
||||
|
||||
## DCSync Attack Chain
|
||||
|
||||
```
|
||||
1. Prerequisites
|
||||
├── Domain Admin or account with replication rights
|
||||
├── Network access to Domain Controller (TCP/135, dynamic RPC)
|
||||
└── Tool: Mimikatz (Windows) or secretsdump.py (Linux)
|
||||
|
||||
2. Credential Extraction
|
||||
├── Extract KRBTGT hash (Golden Ticket capability)
|
||||
├── Extract Administrator hash (immediate DA access)
|
||||
├── Extract all domain hashes (comprehensive dump)
|
||||
└── Extract service account hashes (lateral movement)
|
||||
|
||||
3. Golden Ticket Persistence
|
||||
├── Forge Golden Ticket with KRBTGT hash
|
||||
├── Set arbitrary user, SID, and group memberships
|
||||
├── Import ticket into current session
|
||||
└── Access any resource in the domain
|
||||
|
||||
4. DCSync Rights Persistence
|
||||
├── Create low-profile account in AD
|
||||
├── Grant DS-Replication-Get-Changes-All rights
|
||||
├── Verify rights with ACL enumeration
|
||||
└── Account can now perform DCSync independently
|
||||
```
|
||||
|
||||
## Golden Ticket Lifecycle
|
||||
|
||||
```
|
||||
Creation: KRBTGT hash + Domain SID → Golden Ticket (10-year validity)
|
||||
Usage: Import ticket → Access any service in domain
|
||||
Survival: Persists through password resets (except double KRBTGT reset)
|
||||
Detection: Anomalous TGT lifetime, non-existent users, impossible SIDs
|
||||
Cleanup: Double KRBTGT password reset (with 10+ hour gap between resets)
|
||||
```
|
||||
Reference in New Issue
Block a user