DSRM
General
DSRM is Directory Services Restore Mode
There is a local administrator on every DC called "Administrator" whose password is the DSRM password
DSRM password (SafeModePassword) is required when a server is promoted to a DC and it is rarely changed
After altering the configuration on the DC, it is possible to pass the NTLM hash of this user to access the DC
Exploitation
Detection
Event IDs:
4657: Audit creation/change of HKLM:\SYSTEM\CurrentControlSet\Control\Lsa\ DsrmAdminLogonBehavior
4624: Account Logon
4634: Account Logoff
4672: Admin Logon
Last updated