BigHugger
sk Skill · mukul975

hunting-for-dcsync-attacks

Detect DCSync attacks (MITRE ATT&CK T1003.006) by analyzing Windows Event ID 4662 (AccessMask 0x100) for DS-Replication-Get-Changes and DS-Replication-Get-Changes-All requests issued by non-domain-controller accounts. Use when hunting for DCSync credential theft, after detecting Mimikatz-class tooling, or during incident response and purple-team exercises involving Active Directory replication abuse.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythondfirwindowsmimikatzt1003.006credential-accessactive-directorydcsyncthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python