Domain Controller Notes
By default, Titanis connects to the dynamic TCP endpoint for the LSA service. On domain controllers, this usually results in ERROR_ACCESS_DENIED. To work around this, specify -PreferSmb to connect to the named pipe instead.
Whoami
Lsa whoami lumon-fs1
The result is printed as <domain>\<user>
Lookup SID for Name
This command accepts domain users, local users, or well-known security principals.
Lsa lookupname lumon-dc1 milchick, administrator, system -PreferSmb
Lookup Name for SID
Lsa lookupsid lumon-dc1 S-1-5-21-1718252288-3416168337-1457700507-1104, S-1-5-18 -PreferSmb
Enumerate Policy Accounts
This command enumerates accounts for which a policy set. This is not a list of all accounts on the computer.
Lsa enumaccounts lumon-dc1 -PreferSmb
List Privileged Accounts
This command queries the policy with accounts that hold a specified privilege. Only explicitly-specified privileges are concerned. Group membership is not considered.
Lsa enumprivaccounts lumon-fs1 -Privilege SeBackupPrivilege
Query Account Privileges
Queries the privileges assigned to a policy account. Group membership is not considered.
By Name
Lsa getprivs lumon-fs1 -ByName Administrator
By SID
Lsa getprivs lumon-fs1 -BySid S-1-5-32-544
Create a Policy Account
Lsa createaccount lumon-fs1 S-1-5-21-1718252288-3416168337-1457700507-1104
Grant a Privilege
Before granting a privilege to a policy account, the policy account must exist.
By Name
Lsa addpriv lumon-fs1 -Privileges SeBackupPrivilege -ByName milchick
By SID
Lsa addpriv lumon-fs1 -Privileges SeBackupPrivilege -BySid S-1-5-21-1718252288-3416168337-1457700507-1104
Revoke a Privilege
By Name
Lsa rmpriv lumon-fs1 -Privileges SeBackupPrivilege -ByName milchick
By SID
Lsa rmpriv lumon-fs1 -Privileges SeBackupPrivilege -BySid S-1-5-21-1718252288-3416168337-1457700507-1104
Get System Access Rights
By Name
Lsa getsysaccess lumon-fs1 -ByName milchick
By SID
Lsa rmpriv lumon-fs1 -Privileges SeBackupPrivilege -BySid S-1-5-21-1718252288-3416168337-1457700507-1104