Possible DCSync from a non domain controller
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall traffic Logs OR XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Impacket Analytics
ATT&CK Tactic
Credential Access (TA0006), Defense Impairment (TA0112)
ATT&CK Technique
OS Credential Dumping: DCSync (T1003.006), Rogue Domain Controller (T1207)
Severity
Low
Description
Attackers may pose a compromised host as a DC to replicate data to it (DCSync).
Attacker's Goals
An attacker is trying to retrieve Active Directory data, including password hashes.
Investigative actions
Check whether one of the machines is a new domain controller.
Variations
PreviousPossible data obfuscation
NextPossible Distributed File System Namespace Management (DFSNM) abuse
Was this helpful?
