Potential DCSync Replication Abuse

This rule detects potential DCSync replication abuse by monitoring Security Event ID 4662, specifically looking for access to 'domainDNS' or user objects with the GUID '1131f6aa-9c07-11d1-f79f-00c04fc2dcd2', which is associated with Directory Replication Service (DRS) permissions. It filters out machine accounts to reduce false positives.