DCSync Attack - Directory Replication Service Abuse

This rule detects unauthorized attempts to perform a DCSync attack by monitoring for Active Directory Event ID 4662. It triggers when an account that is not a recognized domain controller (which typically end with a '$' sign) successfully requests replication data using the Directory Replication Service (DRS) GetNCChanges rights. This behavior is a common indicator of credential dumping via tools like Mimikatz.