DC Sync
#mimikatz
DC Sync requires only two rights on the domain object.
Replicating Directory Changes
Replicating Directory Changes All
Replicating Directory Changes in Filtered Set (Optional maybe)
Changes to the ACL of the
domain object
will be logged.
Replication Rights
We can give our user replication rights, using powerview.ps1
Mimikatz
Requires "Domain Admins" privs.
Last updated