DCSync
Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API)(Citation: Microsoft DRSR Dec 2017) (Citation: Microsoft GetNCCChanges) (Citation: Samba DRSUAPI) (Citation: Wine API samlib.dll) to simulate the replication process from a remote domain controller using a technique called DCSync. Members of the Administrators, Domain Admins, and Enterprise Admin groups or computer accounts on the domain c...
BY SOURCE
PROCEDURES (10)
Auto-extracted: 3 detections for service
Auto-extracted: 2 detections for dcsync
Auto-extracted: 2 detections for privilege
Auto-extracted: 1 detections for mimikatz
Auto-extracted: 1 detections for dcsync
Auto-extracted: 1 detections for powershell
Auto-extracted: 1 detections for powershell
Auto-extracted: 1 detections for exfiltrat
Auto-extracted: 1 detections for mimikatz
Auto-extracted: 1 detections for mimikatz