Glossary
DCSync
DCSync is a technique that abuses AD replication rights to pull password hashes directly from a domain controller without local access.
DCSync leverages the same Directory Replication Service (DRS) remote protocol that domain controllers use to replicate directory data among themselves. An account holding replication permissions — most notably Replicating Directory Changes and Replicating Directory Changes All — can request password hashes and other secrets for any account, including krbtgt, by impersonating a domain controller in a replication request, without ever logging on to a DC directly.
This matters because it turns an often-overlooked ACL misconfiguration into full domain compromise: whoever holds these rights can silently dump every credential in the domain. Defenders should treat the Replicating Directory Changes permissions as tier-0 sensitive, strictly limit which principals hold them, and monitor for replication requests originating from non-DC hosts, which are a strong indicator of this technique.