Detects DCSync credential extraction driven from an endpoint by Mimikatz or Invoke-Mimikatz, abusing the Directory Replication Service (DRSUAPI GetNCChanges) to pull secrets such as the krbtgt hash fo osquery query (read-only) — platform(s): windows, tables: process_events. This query IS the collection step: SELECT * FROM process_events WHERE (cmdline LIKE '%lsadump::dcsync%' ESCAPE '\' OR cmdline LIKE '%dcsync /user:%' ESCAPE '\');
For each returned row: