
Hackers Impersonate Domain Controllers to Steal Active Directory Password Hashes
Threat actors are increasingly abusing a stealthy Active Directory technique known as DCSync to impersonate domain controllers and extract password hashes from enterprise networks. Documented by Trellix, DCSync differs from noisy attacks that exploit a vulnerable server or deploy visible malware; it abuses the normal replication process Windows domain controllers use to synchronize directory data […]
The post Hackers Impersonate Domain Controllers to Steal Active Directory Password Hashes appeared first on Cyber Security News.