Ransomware TTP Series: DCSync Credential Theft via Non-DC Replication Request (Qilin)
Detects Active Directory Directory Replication Service (DRSUAPI) GetNCChanges requests originating from a principal or host that is not recognized as a Domain Controller. This behavior is indicative of unauthorized DCSync operations used to dump NTDS.dit hashes, a common technique for credential harvesting associated with ransomware actors like Qilin.
YARA-L

