NTDS.dit Extraction via Volume Shadow Copy Creation and Access

Detects the creation or abuse of Volume Shadow Copies specifically to access the NTDS.dit file or the SYSTEM registry hive, a common technique for offline Active Directory credential dumping.