Direct Access to NTDS.dit File

Detects instances where a process attempts to directly open or access the Active Directory domain database file (NTDS.dit). Direct access to this file is a strong indicator of credential dumping attempts, as the file contains sensitive password hashes and domain information.