Windows Security: AD object replication attempted by non-machine account (Event ID 4662)

Alerts on AD replication-related object access events where the requester is not a machine account.

FreeReviewedSigma · Critical · v2
Product
windows
Service
security
Author
Roberto Rodriguez @Cyb3rWard0g (SigmaHQ), DRL 1.1
Published
2019-07-26
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies Windows Security events (4662) where access rights associated with Active Directory replication are requested using a non-machine account. An attacker could abuse replication permissions to obtain directory data that may help with credential access or further compromise. It relies on telemetry from Event ID 4662, including the access mask value and the object type GUIDs, and it excludes machine and MSOL account patterns from the subject username.

Related detections9 linkedT1003.006 — drag to rearrange
Malicious DCSync Domain Replication Credential Theft (via process_creation)
Malicious Exchange Group Membership Change to Perform DCsync Attack (via security)
Suspicious Computer Account Password Reset via net user by UNC1549
Malicious Active Directory Replication Request Indicating DCSync
Malicious Replication Privileges Accessed to Perform DCSync Attack (via security)
Windows PowerShell: DSInternals Get-ADReplAccount Enumeration
Windows Process Creation: Detect Mimikatz Tool and Module Command-Line Usage
Windows System Service Execution of Credential Dumping Tools (Service Control Manager Event 7045)
Windows Security EID 4697 Service Execution of Credential Dumping Tools
Windows Security: AD object replication attempted by non-machine account (Event ID 4662)
Pivot detection · T1003.006 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.