NTDS.dit File Access by Untrusted Process

Detects instances where the Active Directory domain database file (ntds.dit) is accessed by processes other than known legitimate tools such as lsass.exe or ntdsutil.exe. This activity is a strong indicator of credential dumping attempts to extract Active Directory hashes.