AN1632
Analytic 1632
Windows
Detects unauthorized invocation of replication operations (DCSync) via Directory Replication Service (DRS), often executed by threat actors using Mimikatz or similar tools from non-DC endpoints.
WinEventLog:Security
EventCode=4662
WinEventLog:Security
EventCode=4929
NSM:Content
Traffic on RPC DRSUAPI
[TimeWindow]
Defines the correlation window for unusual account access followed by DRSUAPI traffic.
[UserContext]
Allows tuning for specific accounts known to legitimately request replication.
[SourceIP]
Expected replication should only come from known DCs; this field allows excluding trusted DCs.