DCSync Attack via lsadump::dcsync, DRSUAPI, or secretsdump
This rule detects activities associated with credential dumping, specifically targeting techniques that abuse the Directory Replication Service (DRS) protocol, such as DCSync or the use of tools like secretsdump. It monitors both process execution command lines and network traffic for keywords indicative of these credential extraction behaviors, which are commonly used by attackers to obtain domain credentials.
SentinelOne

