NTDS.dit Extraction via wbadmin.exe Backup (Bumblebee/Akira)
Detects the use of the native Windows utility 'wbadmin.exe' to initiate a backup procedure targeting the Active Directory database (NTDS.dit) and associated registry hives (SYSTEM, SECURITY). This technique is utilized by adversaries for offline credential harvesting by extracting the directory database file. This behavior has been observed in intrusion campaigns involving ransomware actors like Akira.
Sigma

