# T1003.006 DCSync

> As of 2026-10-05, T1003.006 (DCSync) appears in 13 tracked threats, first reported 2026-02-22 and most recently 2026-09-21, with linked actors including Scattered Spider, ALPHV, Qilin; it most often appears alongside T1018 (Remote System Discovery).

- **Tracked threats:** 13 (5 critical, 8 high)
- **First seen:** 2026-02-22
- **Last seen:** 2026-09-21
- **Threat actors:** 8
- **Detection rules:** 33 (counts only; Blue tier and above)

## Key facts

- **ID:** T1003.006
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1003
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1003/006/

## Activity timeline

T1003.006 first appeared in tracked threats on 2026-02-22 and was most recently reported on 2026-09-21. The busiest month was 2026-08 with 3 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1003.006 DCSync is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1003 OS Credential Dumping](https://intel.threadlinqs.com/technique/T1003). Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 5 critical, 8 high.

Threats that use T1003.006 most often also use [T1018 Remote System Discovery](https://intel.threadlinqs.com/technique/T1018) (8 threats), [T1021.001 Remote Desktop Protocol](https://intel.threadlinqs.com/technique/T1021.001) (8 threats), [T1087.002 Domain Account](https://intel.threadlinqs.com/technique/T1087.002) (7 threats), [T1053.005 Scheduled Task](https://intel.threadlinqs.com/technique/T1053.005) (6 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

8 tracked threat actors appear in the threats that use T1003.006; the most frequent are [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (2), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (1), [Qilin](https://intel.threadlinqs.com/actor/Qilin) (1), [SHADOW-EARTH-053](https://intel.threadlinqs.com/actor/SHADOW-EARTH-053) (1), [STORM-0501](https://intel.threadlinqs.com/actor/STORM-0501) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1003.006.

- [M1015 Active Directory Configuration](https://attack.mitre.org/mitigations/M1015/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)

## Data sources

Telemetry that can reveal T1003.006, per MITRE ATT&CK.

- Active Directory — Active Directory Object Access
- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 2
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 1
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 1
- [SHADOW-EARTH-053](https://intel.threadlinqs.com/actor/SHADOW-EARTH-053) — 1
- [STORM-0501](https://intel.threadlinqs.com/actor/STORM-0501) — 1
- [TA455](https://intel.threadlinqs.com/actor/TA455) — 1
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 1
- [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) — 1

## Tracked threats

13 tracked threats use T1003.006.

- [NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…](https://intel.threadlinqs.com/threat/TL-2026-2606) — critical — 2026-09-21
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — high — 2026-09-17
- [Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…](https://intel.threadlinqs.com/threat/TL-2026-2243) — high — 2026-08-30
- [CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…](https://intel.threadlinqs.com/threat/TL-2026-2161) — high — 2026-08-26
- [Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidents](https://intel.threadlinqs.com/threat/TL-2026-1938) — high — 2026-08-08
- [CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonation](https://intel.threadlinqs.com/threat/TL-2026-1675) — critical — 2026-07-24
- [Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattack](https://intel.threadlinqs.com/threat/TL-2026-1429) — high — 2026-07-17
- [UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting…](https://intel.threadlinqs.com/threat/TL-2026-0815) — high — 2026-06-16
- [Four Methods for Azure Blob Storage Ransomware: Client-Side Bulk Encryption, CPK, Encryption Scope, and CMK…](https://intel.threadlinqs.com/threat/TL-2026-2191) — high — 2026-06-15
- [SHADOW-EARTH-053 — China-Aligned Cyberespionage Campaign Exploiting Microsoft Exchange (ProxyLogon…](https://intel.threadlinqs.com/threat/TL-2026-0493) — high — 2026-05-11
- [Kyber Ransomware: Post-Quantum Hybrid Encryption Operation Targeting Windows & VMware ESXi](https://intel.threadlinqs.com/threat/TL-2026-0412) — critical — 2026-04-22
- [SolarWinds Web Help Desk Pre-Auth RCE Chain (CVE-2025-40552, CVE-2025-40553, CVE-2025-40554)](https://intel.threadlinqs.com/threat/TL-2026-1517) — critical — 2026-02-25
- [AI-Augmented FortiGate Mass Exploitation — Russian-Speaking Actor Breaches 600+ Firewalls Across 55…](https://intel.threadlinqs.com/threat/TL-2026-0131) — critical — 2026-02-22

## Related CVEs

CVEs referenced by the tracked threats that use T1003.006, most frequent first.

- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2019-0708](https://intel.threadlinqs.com/cve/CVE-2019-0708)
- [CVE-2019-7192](https://intel.threadlinqs.com/cve/CVE-2019-7192)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2025-2479](https://intel.threadlinqs.com/cve/CVE-2025-2479)
- [CVE-2025-24799](https://intel.threadlinqs.com/cve/CVE-2025-24799)
- [CVE-2025-40552](https://intel.threadlinqs.com/cve/CVE-2025-40552)
- [CVE-2025-40553](https://intel.threadlinqs.com/cve/CVE-2025-40553)
- [CVE-2025-40554](https://intel.threadlinqs.com/cve/CVE-2025-40554)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-54121](https://intel.threadlinqs.com/cve/CVE-2026-54121)

## Detection coverage

Threadlinqs maintains 33 detection rules mapped to T1003.006 (SPL 13, KQL 16, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.

33 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1003 OS Credential Dumping](https://intel.threadlinqs.com/technique/T1003) — 291 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1003.006
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
