Agent Skills: hunting-for-dcsync-attacks

Detect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts.

UncategorizedID: plurigrid/asi/hunting-for-dcsync-attacks

Install this agent skill to your local

pnpm dlx add-skill https://github.com/plurigrid/asi/hunting-for-dcsync-attacks

Skill Files

Browse the full folder contents for hunting-for-dcsync-attacks.

Download Skill

Loading file tree…

Select a file to preview its contents.