logo

The Tale of the Lost, but not Forgotten, Undocumented NetSync: Part 1

ID: 34ff405b-ba16-5d78-9fe9-09c1ccb3f267

STIX ID: report--34ff405b-ba16-5d78-9fe9-09c1ccb3f267

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-03-24

Date Updated: 2026-05-01

...
...

This blog post analyzes NetSync, a lesser-documented Mimikatz lsadump capability that uses MS-NRPC (Netlogon) to impersonate machine accounts and retrieve NTLM machine-account hashes (including DC$), explains how it differs from DCSync, breaks down the protocol interactions, lists required inputs and demonstrates practical attack paths (spooler RPC coercion and DAMP-based remote registry access), with defensive detection and mitigation to be covered in a subsequent Part 2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.