Free kit

Free AI Tabletop Exercise Kit for SMBs

Sign up for the Cyber Defense & AI Brief and get it free.

Get the free kit

UC-L3-028

DCSync Attack Detection

Windows Security Event Log

Use case development / Protect Identity Infrastructure / Detect DCSync Attacks

sigma

Detection rule

title: DCSync Replication Request
status: experimental
description: Detects domain replication requests from non-DC systems
logsource:
  product: windows
  service: security
detection:
  selection:
    EventID: 4662
    AccessMask: '0x100'
    Properties|contains: 'Replicating Directory Changes'
  filter:
    SubjectUserName|endswith: '$'
  condition: selection and not filter
falsepositives:
  - Azure AD Connect
level: critical
tags:
  - attack.credential_access
  - attack.t1003.006

Test cases

  • Execute Mimikatz lsadump::dcsync

False positive guidance

Whitelist Azure AD Connect and legitimate replication sources.

ATT&CK

Detection course