Agent Skills: detecting-dcsync-attack-in-active-directory

Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes by monitoring for non-domain-controller accounts requesting directory replication via DsGetNCChanges.

UncategorizedID: plurigrid/asi/detecting-dcsync-attack-in-active-directory

Install this agent skill to your local

pnpm dlx add-skill https://github.com/plurigrid/asi/detecting-dcsync-attack-in-active-directory

Skill Files

Browse the full folder contents for detecting-dcsync-attack-in-active-directory.

Download Skill

Loading file tree…

Select a file to preview its contents.