{"id":"T1003.006","name":"DCSync","url":"https://attack.mitre.org/techniques/T1003/006","tactics":["credential-access"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0594","stix_id":"x-mitre-detection-strategy--3796aa06-65fe-4b9d-9d31-e6491b722632","name":"Detection of Unauthorized DCSync Operations via Replication API Abuse","url":"https://attack.mitre.org/detectionstrategies/DET0594","analytics":[{"id":"AN1632","stix_id":"x-mitre-analytic--9a68f1a7-65f0-4eef-a711-888bccbeb0d5","name":"Analytic 1632","description":"Detects unauthorized invocation of replication operations (DCSync) via Directory Replication Service (DRS), often executed by threat actors using Mimikatz or similar tools from non-DC endpoints.","url":"https://attack.mitre.org/detectionstrategies/DET0594#AN1632","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4662","data_component":"DC0071","data_component_name":"Active Directory Object Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4929","data_component":"DC0068","data_component_name":"Active Directory Object Deletion","log_source_slug":"wineventlog-security"},{"name":"NSM:Content","channel":"Traffic on RPC DRSUAPI","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-content"}],"mutable_elements":[{"field":"TimeWindow","description":"Defines the correlation window for unusual account access followed by DRSUAPI traffic."},{"field":"UserContext","description":"Allows tuning for specific accounts known to legitimately request replication."},{"field":"SourceIP","description":"Expected replication should only come from known DCs; this field allows excluding trusted DCs."}],"live":true,"detection_strategies":["DET0594"],"techniques":["T1003.006"]}],"live":true,"version":"1.0","techniques":["T1003.006"]}],"sigma_rules":[{"id":"060c3ef1-fd0a-4091-bf46-e7d625f60b73","title":"Suspicious Get-ADReplAccount","author":"frack113","status":"test","level":"medium","date":"2022-02-06","modified":null,"description":"The DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory.\nThese include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.\n","references":["https://www.powershellgallery.com/packages/DSInternals","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003.006/T1003.006.md#atomic-test-2---run-dsinternals-get-adreplaccount"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.credential-access","attack.t1003.006"],"path":"rules/windows/powershell/powershell_script/posh_ps_get_adreplaccount.yml","techniques":["T1003.006"],"cves":[]},{"id":"06d71506-7beb-4f22-8888-e2e5e2ca7fd8","title":"Mimikatz Use","author":"Florian Roth (Nextron Systems), David ANDRE (additional keywords)","status":"test","level":"high","date":"2017-01-10","modified":"2022-01-05","description":"This method detects mimikatz keywords in different Eventlogs (some of them only appear in older Mimikatz version that are however still used by different threat groups)","references":["https://tools.thehacker.recipes/mimikatz/modules"],"logsource":{"product":"windows"},"tags":["attack.s0002","attack.lateral-movement","attack.credential-access","car.2013-07-001","car.2019-04-004","attack.t1003.002","attack.t1003.004","attack.t1003.001","attack.t1003.006"],"path":"rules/windows/builtin/win_alert_mimikatz_keywords.yml","techniques":["T1003.002","T1003.004","T1003.001","T1003.006"],"cves":[]},{"id":"17d619c1-e020-4347-957e-1d1207455c93","title":"Active Directory Replication from Non Machine Account - DcSync Indicator","author":"Roberto Rodriguez @Cyb3rWard0g","status":"test","level":"medium","date":"2019-07-26","modified":"2026-07-30","description":"Detects potential abuse of Active Directory Replication Service (ADRS) from a non machine account to request credentials.","references":["https://threathunterplaybook.com/hunts/windows/180815-ADObjectAccessReplication/notebook.html","https://threathunterplaybook.com/library/windows/active_directory_replication.html","https://threathunterplaybook.com/hunts/windows/190101-ADModDirectoryReplication/notebook.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.t1003.006"],"path":"rules/windows/builtin/security/win_security_ad_replication_non_machine_account.yml","techniques":["T1003.006"],"cves":[]},{"id":"4976aa50-8f41-45c6-8b15-ab3fc10e79ed","title":"Credential Dumping Tools Service Execution - System","author":"Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community","status":"test","level":"high","date":"2017-03-05","modified":"2022-11-29","description":"Detects well-known credential dumping tools execution via service execution events","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","service":"system"},"tags":["attack.credential-access","attack.execution","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006","attack.t1569.002","attack.s0005"],"path":"rules/windows/builtin/system/service_control_manager/win_system_mal_creddumper.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006","T1569.002"],"cves":[]},{"id":"611eab06-a145-4dfa-a295-3ccc5c20f59a","title":"Suspicious Machine Account Replication - DcSync Indicator","author":"Benjamin Delpy, Florian Roth (Nextron Systems), Scott Dermett, Sorina Ionescu","status":"test","level":"medium","date":"2018-06-03","modified":"2026-07-30","description":"Detects suspicious Active Directory Replication Service (ADRS) requests originating from\na machine account (SubjectUserName ending in '$') rather than a legitimate Domain Controller.\n\nUnder normal operation, only Domain Controllers initiate replication requests carrying the\nDS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account\ncredentials — for example by abusing certificate-based authentication (PKINIT) to\nimpersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost),\nwhere a temporary machine account is created to request a DC certificate and then used to\nperform DCSync — they can dump all domain credential material including the krbtgt hash.\n","references":["https://twitter.com/gentilkiwi/status/1003236624925413376","https://gist.github.com/gentilkiwi/dcc132457408cf11ad2061340dcb53c2","https://blog.blacklanternsecurity.com/p/detecting-dcsync?s=r","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4662","https://github.com/aniqfakhrul/CVE-2026-54121"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.s0002","attack.t1003.006","cve.2026-54121"],"path":"rules/windows/builtin/security/win_security_ad_replication_machine_account.yml","techniques":["T1003.006"],"cves":["CVE-2026-54121"]},{"id":"a642964e-bead-4bed-8910-1bb4d63e3b4d","title":"HackTool - Mimikatz Execution","author":"Teymur Kheirkhabarov, oscd.community, David ANDRE (additional keywords), Tim Shelton","status":"test","level":"high","date":"2019-10-22","modified":"2023-02-21","description":"Detection well-known mimikatz command line arguments","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://tools.thehacker.recipes/mimikatz/modules"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006"],"path":"rules/windows/process_creation/proc_creation_win_hktl_mimikatz_command_line.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006"],"cves":[]},{"id":"f0d1feba-4344-4ca9-8121-a6c97bd6df52","title":"Credential Dumping Tools Service Execution - Security","author":"Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community","status":"test","level":"high","date":"2017-03-05","modified":"2022-11-29","description":"Detects well-known credential dumping tools execution via service execution events","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.execution","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006","attack.t1569.002","attack.s0005"],"path":"rules/windows/builtin/security/win_security_mal_creddumper.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006","T1569.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}