T1003.003 NTDS
Subtécnica de T1003 OS Credential Dumping
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in %SystemRoot%\NTDS\Ntds.dit of a domain controller.(Citation: Wikipedia Active Directory) In addition to looking…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Potential Russian APT Credential Theft Activitycriticalstable · windows
- VolumeShadowCopy Symlink Creation Via Mklinkhighstable · windows
- Copying Sensitive Files with Credential Datahightest · windows
- Create Volume Shadow Copy with Powershellhightest · windows
- Cred Dump Tools Dropped Fileshightest · windows
- NTDS Exfiltration Filename Patternshightest · windows
- NTDS.DIT Creation By Uncommon Parent Processhightest · windows
- NTDS.DIT Creation By Uncommon Processhightest · windows
- PUA - DIT Snapshot Viewerhightest · windows
- Possible Impacket SecretDump Remote Activityhightest · windows
- Possible Impacket SecretDump Remote Activity - Zeekhightest · zeek
- Sensitive File Dump Via Print.EXEhightest · windows
- Sensitive File Dump Via Wbadmin.EXEhightest · windows
- Sensitive File Recovery From Backup Via Wbadmin.EXEhightest · windows
- Suspicious Get-ADDBAccount Usagehightest · windows
- Suspicious Process Patterns NTDS.DIT Exfilhightest · windows
- Esentutl Gather Credentialsmediumtest · windows
- Invocation of Active Directory Diagnostic Tool (ntdsutil.exe)mediumtest · windows
- Ntdsutil Abusemediumtest · windows
- Shadow Copies Creation Using Operating Systems Utilitiesmediumtest · windows
- Suspicious Usage Of Active Directory Diagnostic Tool (ntdsutil.exe)mediumtest · windows
- Transferring Files with Credential Data via Network Sharesmediumtest · windows
- Transferring Files with Credential Data via Network Shares - Zeekmediumtest · zeek
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.