Active Directory Replication from Non Machine Account - DcSync Indicator

 Original Source: [Sigma source]
Title: Active Directory Replication from Non Machine Account - DcSync Indicator
Status: test
Description:Detects potential abuse of Active Directory Replication Service (ADRS) from a non machine account to request credentials.
References:
  -https://threathunterplaybook.com/hunts/windows/180815-ADObjectAccessReplication/notebook.html
  -https://threathunterplaybook.com/library/windows/active_directory_replication.html
  -https://threathunterplaybook.com/hunts/windows/190101-ADModDirectoryReplication/notebook.html
Author: Roberto Rodriguez @Cyb3rWard0g
Date: 2019-07-26
modified:2026-07-30
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.006'
Logsource:
  • product: windows
  • service: security
  • definition: Requirements: A SACL must be configured on the domain NC root object (e.g. DC=domain,DC=com) to generate Event 4662. Add via ADSI Edit: navigate to the domain NC root → Properties → Security → Advanced → Auditing → add an ACE for Everyone, Type: Success, Applies to: This object only, rights: DS-Replication-Get-Changes and DS-Replication-Get-Changes-All. The OS audit subcategory must also be enabled: auditpol /set /subcategory:"Directory Service Access" /success:enable
Detection:
  selection:
    EventID: '4662'
    Properties|contains:
      -'1131f6ad-9c07-11d1-f79f-00c04fc2dcd2'
      -'1131f6aa-9c07-11d1-f79f-00c04fc2dcd2'
      -'9923a32a-3607-11d2-b9be-0000f87a36b2'
      -'89e95b76-444d-4c62-991a-0facbeda640c'

  filter_main_machine_accounts:
    SubjectUserName|endswith: '$'
  filter_optional_subject_domain:
    SubjectDomainName: 'Window Manager'
  filter_optional_subject_usersid:
    SubjectUserName|startswith:
      -'NT AUT'
      -'MSOL_'

  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: medium