Module 22 · DCShadow — Stealth Domain Replication Abuse

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
May 13, 2026
6 min read
Read as
100% Free

No signup. No paywall. No catch. One of our 10 most-requested practitioner modules — published in full so anyone can learn for free. We earn through consulting, not by gating knowledge.

See all 10 free modules →

Why this module exists. DCShadow is a Mimikatz technique that lets a privileged attacker register a temporary, rogue domain controller, push arbitrary changes into the directory via standard replication, then deregister — all without a trace in the standard DC audit log. The changes propagate to every real DC via legitimate replication. This module covers how DCShadow works, why standard logging misses it, and the detection patterns that catch it anyway.

Why this module exists. DCShadow is the textbook example of “stealth persistence”. An attacker with sufficient privileges does not need to keep dropping files, scheduling tasks, or modifying registry keys — they push the change into the directory itself via the replication protocol, and the change is now part of the canonical AD state. Defender tooling that audits “modifications via LDAP” misses it. This module is the practitioner-level walkthrough of how it works and how to catch it.

What DCShadow actually does

AD replication works between DCs over the Directory Replication Service (DRS) protocol. When DC1 has a change DC2 has not seen, DC2 pulls the change via DRS. The change is applied locally and audited as a replication event — not as a directory modification. DCShadow exploits this by making the attacker’s machine briefly act as if it were a DC: it registers an SPN, accepts a single replication pull from a real DC, pushes the change, and deregisters. The real DC applies the change and propagates it onward — believing it came from a legitimate replication partner.

Need a real pentest?

Get a VAPT scoping call

Senior practitioner-led VAPT — not a checklist run by juniors. CVSS-scored findings, free retest, attestation letter. India's SMBs and SaaS teams.

Book VAPT scoping call Replies in 4 working hrs · India-only · Senior consultants