OT Infrastructure Attack - Volt Typhoon LOTL Credential Harvesting via ntdsutil

Detects the use of the built-in Windows tool 'ntdsutil.exe' to perform an Install from Media (IFM) operation, which creates a copy of the Active Directory database (NTDS.dit). The rule specifically flags when this output is directed to suspicious paths like 'C:\Windows\Temp' or 'C:\Users\Public', which are common locations used by adversaries to stage files for exfiltration.