DCSync - Unauthorized Directory Replication via Computer Account
Detects directory replication requests (Event ID 4662) using DS-Replication-Get-Changes or DS-Replication-Get-Changes-All GUIDs initiated by a computer account that is not a recognized domain controller. This behavior is indicative of a DCSync attack, where an adversary attempts to pull sensitive credential data directly from Active Directory.
Microsoft Sentinel (KQL)

