Akira - NTDS.dit Extraction via Shadow Copy for Domain Credential Theft

Detects attempts to access or copy the Active Directory domain database (NTDS.dit), which contains sensitive credential material. The rule monitors for the use of built-in administrative tools such as esentutl, ntdsutil, vssadmin, and wbadmin, as well as file copy utilities (robocopy, xcopy) when specifically targeting the NTDS directory or volume shadow copies containing the database file.