DCSync Attack Detected on Domain Controller
Detects unauthorized or non-standard attempts to replicate directory data from a Domain Controller, specifically looking for Directory Replication Service (DRS) GetChanges and GetChangesAll access requests. This behavior is indicative of a DCSync attack, often used by adversaries to dump credentials from the NTDS.dit database.
Microsoft Sentinel (KQL)

