finds.dev← search

// the find

notsoshant/DCSyncer

★ 156 · C · updated Nov 2024

Perform DCSync operation without mimikatz

DCSyncer is a small C tool for Windows that runs a DCSync against a domain controller and dumps NTLM hashes for every account, without loading mimikatz. It is an attack tool, so it is for authorized red team work and lab environments where you already hold replication rights and want to see how the DRSUAPI path works.

The codebase is small enough to read in one sitting. The file names (drsr.c, rpc.c, crypto.c) separate the DRS replication calls, the RPC binding, and the crypto, which makes it a usable reference for how DCSync works on the wire. The linked write-up explains the mechanics, so the repo and the article work as a pair. The README is upfront that the code is rough, and that honesty is useful when you decide how much to trust it.

It dumps every account at once, with no single-user option, so a targeted run still pulls the whole directory. It is 64-bit only, and the Visual Studio project depends on a vendored msasn1 static library in lib/, so building with another toolchain takes some work. The tree shows no test project, so correctness of the crypto and RPC paths depends on running it against a lab domain. The last push was November 2024 and the author says the code may look amateurish, so plan to patch it rather than adopt it as is.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →