NTDS.dit File Access by Untrusted Process
Detects instances where the Active Directory domain database file (ntds.dit) is accessed by processes other than known legitimate tools such as lsass.exe or ntdsutil.exe. This activity is a strong indicator of credential dumping attempts to extract Active Directory hashes.
Microsoft Sentinel (KQL)

