definition: Requirements: A SACL must be configured on the domain NC root object (e.g. DC=domain,DC=com)
to generate Event 4662. Add via ADSI Edit: navigate to the domain NC root → Properties →
Security → Advanced → Auditing → add an ACE for Everyone, Type: Success, Applies to:
This object only, rights: DS-Replication-Get-Changes and DS-Replication-Get-Changes-All.
The OS audit subcategory must also be enabled:
auditpol /set /subcategory:"Directory Service Access" /success:enable
SubjectUserName|endswith:
'$' filter_main_subject_usersid: SubjectUserSid|startswith:
'S-1-5-18' condition:selection and not 1 of filter_main_* Falsepositives:
-Valid DC Sync that is not covered by the filters; please report Level:medium