DCSync: Directory Replication Request from Non-DC, Non-Allowlisted Principal
Detects Active Directory DCSync attempts by monitoring for Windows Security Event ID 4662 where the object properties contain GUIDs associated with directory replication services (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes-In-Filtered-Set). The rule excludes domain controller machine accounts and known legitimate service accounts used for synchronization or backup operations.
Microsoft Sentinel (KQL)

