Direct Volume Access & Offline Credential Dumping (T1006/T1003.003)

Detects potential credential dumping activities and unauthorized access to sensitive system files. The rule monitors for three primary indicators: raw disk device access (often associated with volume shadow copy dumping), suspicious DiskShadow utility execution, and NTDS.dit extraction using ntdsutil. Known administrative and backup software processes are excluded to minimize noise.