avatar

Gaurav Thakare

@gauravthakare
0 followers1 download22 copies1 like36 views

3 detections

Detects various methods and tools used by adversaries to access, stage, or exfiltrate the Active Directory database (ntds.dit). This includes abuse of built-in Windows utilities such as ntdsutil, vssadmin, diskshadow, esentutl, and registry commands, as well as the use of known credential dumping tools like Impacket's SecretsDump and NinjaCopy.
avatar
Gaurav Thakare@gauravthakare
avatar
Detections.ai Community
1 month ago
14015
Detects instances where sensitive Active Directory database files (NTDS.DIT) are accessed, correlated with the execution of common system administration utilities (ntdsutil, vssadmin, diskshadow, esentutl) known to be leveraged by adversaries to create volume shadow copies or extract data for offline credential harvesting.
avatar
Gaurav Thakare@gauravthakare
avatar
Detections.ai Community
1 month ago
4112
Detects instances where a process attempts to directly open or access the Active Directory domain database file (NTDS.dit). Direct access to this file is a strong indicator of credential dumping attempts, as the file contains sensitive password hashes and domain information.
avatar
Gaurav Thakare@gauravthakare
avatar
Detections.ai Community
1 month ago
409