T1003.003 NTDS
Sub-technique of T1003 OS Credential Dumping
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in %SystemRoot%\NTDS\Ntds.dit of a domain controller.(Citation: Wikipedia Active Directory) In addition to looking…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Potential Russian APT Credential Theft Activitycriticalstable · windows
- VolumeShadowCopy Symlink Creation Via Mklinkhighstable · windows
- Copying Sensitive Files with Credential Datahightest · windows
- Create Volume Shadow Copy with Powershellhightest · windows
- Cred Dump Tools Dropped Fileshightest · windows
- NTDS Exfiltration Filename Patternshightest · windows
- NTDS.DIT Creation By Uncommon Parent Processhightest · windows
- NTDS.DIT Creation By Uncommon Processhightest · windows
- PUA - DIT Snapshot Viewerhightest · windows
- Possible Impacket SecretDump Remote Activityhightest · windows
- Possible Impacket SecretDump Remote Activity - Zeekhightest · zeek
- Sensitive File Dump Via Print.EXEhightest · windows
- Sensitive File Dump Via Wbadmin.EXEhightest · windows
- Sensitive File Recovery From Backup Via Wbadmin.EXEhightest · windows
- Suspicious Get-ADDBAccount Usagehightest · windows
- Suspicious Process Patterns NTDS.DIT Exfilhightest · windows
- Esentutl Gather Credentialsmediumtest · windows
- Invocation of Active Directory Diagnostic Tool (ntdsutil.exe)mediumtest · windows
- Ntdsutil Abusemediumtest · windows
- Shadow Copies Creation Using Operating Systems Utilitiesmediumtest · windows
- Suspicious Usage Of Active Directory Diagnostic Tool (ntdsutil.exe)mediumtest · windows
- Transferring Files with Credential Data via Network Sharesmediumtest · windows
- Transferring Files with Credential Data via Network Shares - Zeekmediumtest · zeek
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.