Skip to content

Instantly share code, notes, and snippets.

What would you like to do?
DCSync detection
alert tcp any any -> [!<domaincontrollers to exclude here] [49152:65535] (msg:"Possible DCSync Detected"; flow:to_server,established; flags:PA; content:"|00 03 10 00 00 00|"; depth:8; content:"|03 00|"; distance:14; classtype:attempted-admin; sid:20166316;)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment