DCSync Attack Detection Hunt Template
Hunt Metadata
| Field |
Value |
| Hunt ID |
TH-DCSYNC-YYYY-MM-DD-NNN |
| Analyst |
|
| Date |
|
| Status |
[ ] In Progress / [ ] Complete |
Hypothesis
An adversary with elevated AD privileges is performing DCSync to extract password hashes from Active Directory by replicating directory data from a non-domain-controller machine.
Pre-Hunt Checklist
DCSync Detection Findings
| # |
Timestamp |
Subject Account |
Source Machine |
Target DC |
Replication Rights |
Severity |
| 1 |
|
|
|
|
|
|
Accounts with Replication Rights Audit
| Account |
Type |
Rights |
Legitimate |
Justification |
|
User/Service/Computer |
Get-Changes / Get-Changes-All |
Yes/No |
|
Post-DCSync Impact Assessment
| Check |
Status |
Notes |
| KRBTGT hash potentially compromised |
|
|
| Domain Admin hashes extracted |
|
|
| Service account credentials at risk |
|
|
| Golden Ticket creation possible |
|
|
Response Actions
- Disable: [Compromised accounts]
- Reset: [KRBTGT password -- twice, 12 hours apart]
- Revoke: [Unauthorized replication rights]
- Investigate: [Source machine forensics]
- Monitor: [Subsequent credential abuse attempts]