A Detection Researcher Mindset — DCSYNC T1003.006
ID: 46e8f9ac-322c-5b32-a26b-d6651973ab02
STIX ID: report--46e8f9ac-322c-5b32-a26b-d6651973ab02
Feed Name: Detect FYI
Threat Score
**Executive summary:** This document explains the DCSync technique in Active Directory, describing normal domain controller replication behavior, how to distinguish legitimate vs suspicious DCSync activity (it should originate from domain controllers), and emphasizing that very high privileges (domain admin / extended rights) are required; it recommends limiting accounts and systems with those rights to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
