πΎ - π DRSUAPI DsGetDomainControllerInfo - Possible Mimikatz DCSync attack π₯· - T1003.006 - Check if source is a legit πͺ Domain Controler
Sourcepawpatrules
CreatedMay 30, 2024
UpdatedAugust 21, 2025
Classificationattempted-recon
alert tcp-pkt any any -> $HOME_NET any (msg:"πΎ - π DRSUAPI DsGetDomainControllerInfo - Possible Mimikatz DCSync attack π₯· - T1003.006 - Check if source is a legit πͺ Domain Controler"; flow:to_server, stateless; content:"|05 00 00|"; depth:3; content:"|03 00 00 00 50 00 00 00 00 00 10 00|"; fast_pattern; content:"|09 06 00 00|"; reference:url,https://attack.mitre.org/techniques/T1003/006/; reference:url,https://github.com/gentilkiwi/mimikatz; reference:url,https://adsecurity.org/?p=1729; metadata:created_at 2024_05_30, updated_at 2025_08_21, signature_severity Major, attack_target Server_Endpoint, affected_product Windows_Server_32_64_Bit, mitre_tactic_id TA0006, mitre_tactic_name Credential_Access, mitre_technique_id T1003_006, mitre_technique_name OS_Credential_Dumping_DCSync; sid:3321275; rev:2; classtype:attempted-recon;)
References
Metadata
created at2024_05_30
updated at2025_08_21
signature severityMajor
attack targetServer_Endpoint
affected productWindows_Server_32_64_Bit
mitre tactic idTA0006
mitre tactic nameCredential_Access
mitre technique idT1003_006
mitre technique nameOS_Credential_Dumping_DCSync
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!