NTDS.dit Extraction - Active Directory Database Credential Dump
This rule detects various methods used to copy or access the Active Directory database (NTDS.dit), a common technique used by attackers to dump domain credentials. The rule monitors for the use of ntdsutil with 'ifm' (install from media) arguments, vssadmin to create volume shadow copies of the NTDS file, esentutl directly interacting with the NTDS database path, and common file copy utilities attempting to copy the NTDS.dit file.
Microsoft Sentinel (KQL)

