NTDS.dit Credential Dumping via ntdsutil
Detects the use of legitimate Windows system utilities (ntdsutil.exe, vssadmin.exe, esentutl.exe) to interact with the Active Directory database file (ntds.dit). This behavior is commonly associated with offline credential harvesting, where an attacker attempts to create a copy of the database to extract hashes offline.
Microsoft Sentinel (KQL)

