
Gaurav Thakare
@gauravthakare0 followers1 download22 copies1 like36 views
3 detections
Filters
Last updated
All Time
Detection languages
3
Categories
3
2
2
1
Platforms
3
Products / Services
3
MITRE Techniques
3
1
1
1
1
Detects various methods and tools used by adversaries to access, stage, or exfiltrate the Active Directory database (ntds.dit). This includes abuse of built-in Windows utilities such as ntdsutil, vssadmin, diskshadow, esentutl, and registry commands, as well as the use of known credential dumping tools like Impacket's SecretsDump and NinjaCopy.
Detects instances where sensitive Active Directory database files (NTDS.DIT) are accessed, correlated with the execution of common system administration utilities (ntdsutil, vssadmin, diskshadow, esentutl) known to be leveraged by adversaries to create volume shadow copies or extract data for offline credential harvesting.
Detects instances where a process attempts to directly open or access the Active Directory domain database file (NTDS.dit). Direct access to this file is a strong indicator of credential dumping attempts, as the file contains sensitive password hashes and domain information.
