DCSync Directory Replication Request (4662) by Non-Machine Account
Detects unauthorized access to the Directory Replication Service (DRS) using Event ID 4662. The rule looks for access requests to sensitive Active Directory replication objects (GUIDs 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 and 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2) initiated by accounts other than Domain Controller machine accounts, which is a signature behavior of tools like Mimikatz lsadump::dcsync or Impacket's secretsdump.py.
Microsoft Sentinel (KQL)

