Possible DCSync Attack (56fda488-113e-4ce9-8076-afc2457922c3)
Detects remote RPC calls to MS-DRSR from non DC hosts, which could indicate DCSync / DCShadow attacks.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Possible DCSync Attack (56fda488-113e-4ce9-8076-afc2457922c3) | Sigma-Rules | System Owner/User Discovery - T1033 (03d7999c-1f4c-42cc-8373-e7690d318104) | Attack Pattern | 1 |