Bumblebee/Akira - wbadmin.exe NTDS.dit and SYSTEM Hive Backup for Credential Harvesting

Detects the use of the native Windows wbadmin.exe utility to initiate a backup that targets sensitive system files, such as the Active Directory database (ntds.dit) or registry hives (SYSTEM, SECURITY). This behavior is characteristic of an attempt to stage sensitive credentials or system configuration data for offline analysis or exfiltration, often performed as part of a credential dumping effort.