Cypher: Principals With DCSync Rights

Find every principal that holds DS-Replication-Get-Changes / DS-Replication-Get-Changes-All on the domain object — i.e. anyone able to DCSync. Often surfaces forgotten service accounts and over-permissioned groups.

Tool
MATCH
Category
Enumeration / BloodHound Cypher Queries
Platform
cross-platform
Requires
no credentials

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

MATCH p=(u)-[:DCSync|GetChanges|GetChangesAll|GetChangesInFilteredSet]->(d:Domain) RETURN p

Examples

MATCH p=(u)-[:DCSync|GetChanges|GetChangesAll|GetChangesInFilteredSet]->(d:Domain) RETURN p

Tags

bloodhound cypher dcsync replication

References