Possible DCSync Attack (56fda488-113e-4ce9-8076-afc2457922c3)
Detects remote RPC calls to MS-DRSR from non DC hosts, which could indicate DCSync / DCShadow attacks.
| Cluster A | Galaxy A | Cluster B | Galaxy B | Level | 
|---|---|---|---|---|
| Possible DCSync Attack (56fda488-113e-4ce9-8076-afc2457922c3) | Sigma-Rules | System Owner/User Discovery - T1033 (03d7999c-1f4c-42cc-8373-e7690d318104) | Attack Pattern | 1 |