detecting-dcsync-attack-in-active-directory - Detect DCSync credential theft in Active Directory
Detect DCSync attacks by monitoring non-domain-controller accounts requesting Active Directory replication via DsGetNCChanges.
Tags
Updated: 2026-09-17Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Identify legitimate domain controllers
- Monitor replication rights access GUIDs
- Detect non-domain controller replication requests
- Correlate RPC network replication traffic
- Audit directory service access events
Inputs
- Windows Security Event ID 4662 logs
- Domain controller host inventory
- Advanced Audit Policy configuration
Outputs
- DCSync threat hunt report
- SIEM security alerts
Requirements
- Windows Event ID 4662 enabled
- Audit Directory Service Access enabled
- Domain controller event forwarding to SIEM
- SACL configured on domain object
