For the complete documentation index, see llms.txt. This page is also available as Markdown.

Possible DCSync from a non domain controller

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Palo Alto Networks Firewall traffic Logs OR XDR Agent with eXtended Threat Hunting (XTH)

Detector Tags

Impacket Analytics

ATT&CK Tactic

Credential Access (TA0006), Defense Impairment (TA0112)

ATT&CK Technique

OS Credential Dumping: DCSync (T1003.006), Rogue Domain Controller (T1207)

Severity

Low

Description

Attackers may pose a compromised host as a DC to replicate data to it (DCSync).

Attacker's Goals

An attacker is trying to retrieve Active Directory data, including password hashes.

Investigative actions

Check whether one of the machines is a new domain controller.

Variations

DCSync from a non domain controller from a non-standard process

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006), Defense Impairment (TA0112)

ATT&CK Technique

OS Credential Dumping: DCSync (T1003.006), Rogue Domain Controller (T1207)

Severity

High

Description

Attackers may pose a compromised host as a DC to replicate data to it (DCSync).

Attacker's Goals

An attacker is trying to retrieve Active Directory data, including password hashes.

Investigative actions

Check whether one of the machines is a new domain controller.

Large DCSync from a non domain controller by AppID

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006), Defense Impairment (TA0112)

ATT&CK Technique

OS Credential Dumping: DCSync (T1003.006), Rogue Domain Controller (T1207)

Severity

Medium

Description

Attackers may pose a compromised host as a DC to replicate data to it (DCSync).

Attacker's Goals

An attacker is trying to retrieve Active Directory data, including password hashes.

Investigative actions

Check whether one of the machines is a new domain controller.

Large DCSync from a non domain controller

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006), Defense Impairment (TA0112)

ATT&CK Technique

OS Credential Dumping: DCSync (T1003.006), Rogue Domain Controller (T1207)

Severity

Medium

Description

Attackers may pose a compromised host as a DC to replicate data to it (DCSync).

Attacker's Goals

An attacker is trying to retrieve Active Directory data, including password hashes.

Investigative actions

Check whether one of the machines is a new domain controller.

Possible DCSync from an internet-facing server

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006), Defense Impairment (TA0112)

ATT&CK Technique

OS Credential Dumping: DCSync (T1003.006), Rogue Domain Controller (T1207)

Severity

Medium

Description

Attackers may pose a compromised host as a DC to replicate data to it (DCSync).

Attacker's Goals

An attacker is trying to retrieve Active Directory data, including password hashes.

Investigative actions

Check whether one of the machines is a new domain controller.

DCSync from a non domain controller

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006), Defense Impairment (TA0112)

ATT&CK Technique

OS Credential Dumping: DCSync (T1003.006), Rogue Domain Controller (T1207)

Severity

Low

Description

Attackers may pose a compromised host as a DC to replicate data to it (DCSync).

Attacker's Goals

An attacker is trying to retrieve Active Directory data, including password hashes.

Investigative actions

Check whether one of the machines is a new domain controller.

Was this helpful?