How to get URL link on X (Twitter) App
https://twitter.com/snovvcrash/status/1571945256383582211
https://twitter.com/_nwodtuhs/status/1469770310077620235🧵 (2/) The rule triggers when a bunch of SMB requests are followed by all this DRSUAPI stuff. Unlike #mimikatz or #DSInternals DCSync, the sequence of SMB+DRSUAPI traffic is unique for secretsdump[.]py attack, thus it becomes an IOC and can be fingerprinted ⬇️