Potential DCSync Attack Attempt
This rule detects multiple attempts by a user account to perform a Directory Synchronization (DirSync) operation, which is a common indicator of a DCSync attack. The rule specifically looks for Event ID 4662 with properties containing 'DS-DirSync' or '131072', filters for user accounts, excludes known service accounts, and triggers if there are 5 or more attempts from the same account and computer.
Microsoft Sentinel (KQL)

