Skip to content
REDMAW

Internal Infrastructure

DCSync

An identity with replication-related privileges can request password-related directory data in a way that imitates domain-controller replication behavior.

RedMaw

Definition

Domain controllers replicate directory data among themselves, including credential material. An identity holding the relevant replication privileges can make the same request, obtaining that material without touching a domain controller's disk or memory.

Why it is the end of the path

Access to domain credential material is effectively domain compromise. It is not a step toward privilege. It is the privilege, and remediation is considerably more involved than resetting a password.

Why the privilege is often present

The rights involved are granted legitimately to domain controllers, and sometimes to synchronization, backup or migration tooling. Those grants persist after the tool is retired, and they are not visible in a review that looks only at group membership.

Where it leads
  1. Privileged Identity
  2. Directory Replication Rights
  3. Credential Material
  4. Domain Control

Each hop validated by successful exploitation

Tags

  • active directory
  • credentials
  • domain compromise

Validation

How RedMaw validates this attack

Validation runs only inside authorized scope, with agreed exploitation limits.

  1. 01Enumerate identities holding replication-related rights
  2. 02Identify grants held by retired or non-human tooling
  3. 03Establish whether those rights are still required
  4. 04Report the grant and its consequence rather than exercising it

Stop assuming you are secure. Prove it.

Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.