跳到主要内容
知仓学习社ZHICANG

hunting-for-dcsync-attacks

Detect DCSync attacks (MITRE ATT&CK T1003.006) by analyzing Windows Event ID 4662 (AccessMask 0x100) for DS-Replication-Get-Changes and DS-Replicati…

执行命令写文件严重 0 · 高危 3mukul975/Anthropic-Cybersecurity-Skills

它会碰到什么

扫了多少4 个文本文件,28 KB
它会碰到什么执行命令写文件
命中总数4 处
命中统计严重 0 · 高 3 · 中 1 · 低 0
逐条看命中(3 条严重或高危)
  • scripts/agent.py:29exec-spawn
    result = subprocess.run(cmd, capture_output=True, text=True, timeout=120)
  • scripts/agent.py:55exec-spawn
    result = subprocess.run(cmd, capture_output=True, text=True, timeout=120)
  • scripts/agent.py:157exec-spawn
    result = subprocess.run(cmd, capture_output=True, text=True, timeout=120)

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Hunting for DCSync Attacks

When to Use

  • When hunting for DCSync credential theft (MITRE ATT&CK T1003.006)
  • After detecting Mimikatz or similar tools in the environment
  • During incident response involving Active Directory compromise
  • When monitoring for unauthorized domain replication requests
  • During purple team exercises testing AD attack detection

Prerequisites

  • Windows Security Event Log forwarding enabled (Event ID 4662)
  • Audit Directory Service Access enabled via Group Policy
  • Domain Computers SACL configured on Domain Object for machine account detection
  • SIEM with Windows event data ingested (Splunk, Elastic, Sentinel)
  • Knowledge of legitimate domain controller accounts and replication partners

Workflow

  1. Enable Auditing: Ensure Audit Directory Service Access is enabled on domain controllers.
  2. Collect Events: Gather Windows Event ID 4662 with AccessMask 0x100 (Control Access).
  3. Filter Replication GUIDs: Search for DS-Replication-Get-Changes and DS-Replication-Get-Changes-All.
  4. Identify Non-DC Sources: Flag events where SubjectUserName is not a domain controller machine account.
  5. Correlate with Network: Cross-reference source IPs against known DC addresses.
  6. Validate Findings: Exclude legitimate replication tools (Azure AD Connect, SCCM).
  7. Respond: Disable compromised accounts, reset krbtgt, investigate lateral movement.

Key Concepts

| Concept | Description |

|---------|-------------|

| DCSync | Technique abusing AD replication protocol to extract password hashes |

| Event ID 4662 | Directory Service Access audit event |

| DS-Replication-Get-Changes | GUID 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 |

| DS-Replication-Get-Changes-All | GUID 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2 |

| AccessMask 0x100 | Control Access right indicating extended rights verification |

| T1003.006 | OS Credential Dumping: DCSync |

Tools & Systems

| Tool | Purpose |

|------|---------|

| Windows Event Viewer | Direct event log analysis |

| Splunk | SIEM correlation of Event 4662 |

| Elastic Security | Detection rules for DCSync patterns |

| Mimikatz lsadump::dcsync | Attack tool used to perform DCSync |

| Impacket secretsdump.py | Python-based DCSync implementation |

| BloodHound | Identify accounts with replication rights |

Output Format

Hunt ID: TH-DCSYNC-[DATE]-[SEQ]
Technique: T1003.006
Domain Controller: [DC hostname]
Subject Account: [Account performing replication]
Source IP: [Non-DC IP address]
GUID Accessed: [Replication GUID]
Risk Level: [Critical/High/Medium/Low]
Recommended Action: [Disable account, reset krbtgt, investigate]

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。