1.What specific permissions does DCSync require?
2.Why does the replication protocol not verify that the requester is a domain controller?
3.Why is the krbtgt hash the highest-value target for DCSync?
4.How does DCSync differ from extracting credentials from LSASS?
5.Why are directory synchronization service accounts (like Azure AD Connect) high-value targets in the context of DCSync?
6.What is the primary detection method for DCSync activity?