hunting-for-dcsync-attacks
Detect DCSync attacks (MITRE ATT&CK T1003.006) by analyzing Windows Event ID 4662 (AccessMask 0x100) for DS-Replication-Get-Changes and DS-Replication-Get-Changes-All requests issued by non-domain-controller accounts. Use when hunting for DCSync credential theft, after detecting Mimikatz-class tooling, or during incident response and purple-team exercises involving Active Directory replication abuse.
Source facts
- Repository
- mukul975/Anthropic-Cybersecurity-Skills
- Last source activity
- August 2, 2026 at 16:32
- Detected SKILL.md language
- English
- Stars
- 27,732
- Forks
- 3,366
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.