NTDS.dit Access or Credential Dumping Activity
This rule detects suspicious activity related to accessing or dumping the NTDS.dit file, which contains Active Directory credential information. It looks for process creation events involving tools commonly used for NTDS.dit extraction (e.g., ntdsutil, secretsdump), file access events on NTDS.dit paths, and privilege use (SeBackupPrivilege, SeRestorePrivilege, SeDebugPrivilege) often associated with credential dumping.
Microsoft Sentinel (KQL)

