Incomplete information in dcsync logs [migrated]
I’ve enabled DS audits in domain controller group policy:
Then I perform dcsync attack with a normal user account, and check the logs in ELK:
Two logs were created and the DS-Replication-Get-Changes-All log is generated correctly, and no… Continue reading Incomplete information in dcsync logs [migrated]