mimikatz DCShadow

mimikatz # lsadump::dcshadow /object:<user> /attribute:<attr> /value:<value>

Registers a rogue domain controller to modify AD objects without leaving direct audit logs.

When you have credentials for a user with replication permissions and want to modify AD without raising alerts (e.g., adding a user to Domain Admins). DCShadow registers a fake DC that replicates changes, avoiding direct modification logs.

If the EDR monitors the creation of new domain controllers or changes in AD. Also if the domain has advanced DCShadow detections (e.g., Microsoft Defender ATP flags it).