NTDS.dit Active Directory Database Exfiltration via File or ntdsutil
Detects attempts to access or copy the Active Directory domain database (NTDS.dit) by monitoring for direct file access to the file or the execution of ntdsutil.exe with arguments intended to create an Install From Media (IFM) set, which is a known technique for exfiltrating the NTDS.dit file for offline password cracking.
SentinelOne

