NTDS.dit extraction from VSS shadow copy after vssadmin/wmic/diskshadow
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy the Active Directory database file (ntds.dit) from the shadow copy. This pattern is commonly used by adversaries to perform offline credential dumping.
Microsoft Sentinel (KQL)

