AD同步攻击检测
原名:detecting-dcsync-attack-in-active-directory
检测DCSync攻击(MITRE T1003.006),通过审计Event ID 4662中的DS-Replication-Get-Changes GUIDs,标记非域控账户发起的DsGetNCChanges RPC调用,用于发现Mimikatz或Impacket凭据窃取行为。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-09-07
- TRACE 评分
- 3.4 / 5
内容概览
- When hunting for credential theft in Active Directory environments - After compromise of accounts with Replicating Directory Changes permissions - When investigating suspected use of Mimikatz or Impacket secretsdump - During incident response involving lateral movement with domain admin credentials - When auditing AD replication permissions as part of security hardening - Windows Security Event Logs with Event ID 4662 (Object Access) enabled - Advanced Audit Policy: Audit Directory Service Access enabled - Domain Controller event forwarding to SIEM - Knowledge of legitimate domain controller hostnames and IPs - Directory Service Access auditing with SACL on domain object 1. Identify Legitimate Replication Sources : Document all domain controllers in the environment by hostname, IP, and computer account. Only these should perform directory replication. 2. Enable Required Auditing : Conf…