Directory.Replication.Service.Remote.Protocol.DSGetNCChanges
Description
This indicates detection of a DRSUAPI DSGetNCChanges request.Directory Replication Service Remote Protocol (DRSUAPI) is used by domain controllers to replicate Active Directory objects between controllers. A DSGetNCChanges request starts the replication process.
Please note: if a DSGetNCChanges request comes from a source that's not a domain controller, then this is most likely a DCSync attack.
DCSync is a technique to steal credentials through DSGetNCChanges requests for domain replication.
Affected Products
Windows domain networks
Impact
Unexpected network communication
Technology
Network-Protocol
Behavior
- Other
Version Updates
| Date | Version | Status | Detail |
|---|---|---|---|
| 2023-08-31 | 25.631 |
New
|