Direct Access to NTDS.dit File
Detects instances where a process attempts to directly open or access the Active Directory domain database file (NTDS.dit). Direct access to this file is a strong indicator of credential dumping attempts, as the file contains sensitive password hashes and domain information.
Microsoft Sentinel (KQL)

