← All Lessons
Premium

TechniqueActive Directory

DCShadow Persistence

DCShadow lets a high-privileged attacker impersonate a domain controller and push attribute changes into Active Directory through legitimate replication, leaving no modification record on any real DC. This lesson explains how the rogue-DC trick works, why the change is invisible to host audit logs, what it buys an attacker, and how to explain and detect it.

Sign in or upgrade to unlock the full premium library.

What you'll learn

  • Rogue domain controller
  • DC-to-DC replication (MS-DRSR / DRSUAPI)
  • No object-modification event
  • SIDHistory
  • Minimal replication rights
  • AdminSDHolder persistence

What premium includes

  • All 78 lessons: AD techniques, professional skills, each with interview answers and study kits
  • Complete study kit for every lesson: quizzes, flashcards, and briefs
  • Every learning track with full structured progression
  • All 12 attack paths: full compromise walkthroughs for interviews and reports
  • New lessons and attack paths added regularly

Continue with free content

DCShadow Persistence — ExplainTheHack