Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0594 — Detection of Unauthorized DCSync Operations via Replication API Abuse
DET0594

Detection of Unauthorized DCSync Operations via Replication API Abuse

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1632 Analytic 1632
Windows

Detects unauthorized invocation of replication operations (DCSync) via Directory Replication Service (DRS), often executed by threat actors using Mimikatz or similar tools from non-DC endpoints.

WinEventLog:Security EventCode=4662 WinEventLog:Security EventCode=4929 NSM:Content Traffic on RPC DRSUAPI
[TimeWindow] Defines the correlation window for unusual account access followed by DRSUAPI traffic.
[UserContext] Allows tuning for specific accounts known to legitimately request replication.
[SourceIP] Expected replication should only come from known DCs; this field allows excluding trusted DCs.

Detected Techniques

1

Credential Access (1)

Details

MITRE ID
DET0594
STIX ID
x-mitre-detection-strategy--3796aa06-65fe-4b9d-9d31-e6491b722632
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.