Potential NTDS Credential Dumping Activity
Detects various methods and tools used by adversaries to access, stage, or exfiltrate the Active Directory database (ntds.dit). This includes abuse of built-in Windows utilities such as ntdsutil, vssadmin, diskshadow, esentutl, and registry commands, as well as the use of known credential dumping tools like Impacket's SecretsDump and NinjaCopy.
Microsoft Sentinel (KQL)

