Most Popular Detection 2026: DCSync Attack via Directory Replication Service Abuse (T1003.006)

This rule detects attempts to perform a DCSync attack by monitoring for Windows Event ID 4662 (Object Access) with specific Directory Replication Service (DRS) GUIDs. These GUIDs are used by attackers to request the replication of sensitive data, such as password hashes, from a Domain Controller without having direct access to it. This technique is commonly used by tools like Mimikatz and Impacket's secretsdump to extract credentials from Active Directory.