NTDS.dit Credential Dumping via ntdsutil

Detects the use of legitimate Windows system utilities (ntdsutil.exe, vssadmin.exe, esentutl.exe) to interact with the Active Directory database file (ntds.dit). This behavior is commonly associated with offline credential harvesting, where an attacker attempts to create a copy of the database to extract hashes offline.