Archives: Security

List of Cmdlets in the DSInternals Module

September 29, 2015 | Michael Grafnetter | 12 Comments on List of Cmdlets in the DSInternals Module

Here is the list of cmdlets currently contained in the DSInternals PowerShell module: Online operations with the Active Directory database Get-ADReplAccount – Reads one or more accounts through the DRSR protocol, including secret attributes. Set-SamAccountPasswordHash – Sets NT and LM hashes of an account through the SAMR protocol. Get-ADReplBackupKey – Reads the DPAPI backup keys through the DRSR protocol. Offline operations with the Active Directory database Get-ADDBAccount – • Read More »

Tags: , , , , ,

New version of the DSInternals module released

September 5, 2015 | Michael Grafnetter | No Comments on New version of the DSInternals module released

I have released a new version of the DSInternals PowerShell module. This is mainly a bugfix release. You can grab it from the Downloads section. Or, if you have PowerShell 5, you can install the module from the PowerShell Gallery by running this command:

Tags: , , ,

Retrieving Active Directory Passwords Remotely

August 4, 2015 | Michael Grafnetter | 86 Comments on Retrieving Active Directory Passwords Remotely

I have finally finished work on the Get-ADReplAccount cmdlet, the newest addition to my DSInternals PowerShell Module, that can retrieve reversibly encrypted plaintext passwords, password hashes and Kerberos keys of all user accounts from remote domain controllers. This is achieved by simulating the behavior of the dcromo tool and creating a replica of Active Directory database through the MS-DRSR protocol. Furthermore, it has these properties: It does not even need the Domain Admins group membership. • Read More »

Tags: , ,