DC Sync

The dcsync command is a separate module from mimikatz. It runs inline and can be used with an impersonated token created with the make_token or impersonate command. This command takes one username argument as input. If no argument is provided, then it will request NTLM hashes for all the users in the domain. This command does not inject anything and all the DC replication requests are performed from the badger’s process itself.

It also takes an operator provided domain name to synchronize passwords against only a specific domain.