AD同步攻击检测

原名:detecting-dcsync-attack-in-active-directory

检测DCSync攻击(MITRE T1003.006),通过审计Event ID 4662中的DS-Replication-Get-Changes GUIDs,标记非域控账户发起的DsGetNCChanges RPC调用,用于发现Mimikatz或Impacket凭据窃取行为。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-09-07
TRACE 评分
3.4 / 5

内容概览

- When hunting for credential theft in Active Directory environments - After compromise of accounts with Replicating Directory Changes permissions - When investigating suspected use of Mimikatz or Impacket secretsdump - During incident response involving lateral movement with domain admin credentials - When auditing AD replication permissions as part of security hardening - Windows Security Event Logs with Event ID 4662 (Object Access) enabled - Advanced Audit Policy: Audit Directory Service Access enabled - Domain Controller event forwarding to SIEM - Knowledge of legitimate domain controller hostnames and IPs - Directory Service Access auditing with SACL on domain object 1. Identify Legitimate Replication Sources : Document all domain controllers in the environment by hostname, IP, and computer account. Only these should perform directory replication. 2. Enable Required Auditing : Conf…

查看 SKILL 详情