Analytics BIOC Informational

Potential DCSync by an unusual user

Attackers may leverage the domain replication process to extract sensitive information (DCSync).

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005) Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping: DCSync (T1003.006) Rogue Domain Controller (T1207)
Attacker's goals:

An attacker is trying to retrieve Active Directory data, including password hashes.

Investigative actions:

Check whether the replicating account is an account that should initiate a DC synchronization.* Check the role of the account, and see if it should initiate a DC synchronization.* Check if the account performing the DCSync is related to a new DC.* Find the source host of the DCSync (correlate between event 4662 and 4624 based on the field 'Logon ID').* Check if the account was recently added to an administrative groups/had new sensitive privileges assigned to it.* Monitor suspicious traffic to/from the host to identify lateral movement or access to sensitive resources.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Possible DCSync by an unusual user Low (parent: Informational)