Entra Connect / ADSync Sync Account & PTA Agent Compromise

This rule detects potentially malicious activity targeting Microsoft Entra Connect (formerly Azure AD Connect) servers. It identifies the execution of known credential harvesting tools like AADInternals or attempts to access/extract the ADSync database files and encryption components. Such actions indicate an attempt to gain unauthorized access to synchronized identities, local domain credentials, or cloud synchronization service accounts.