Ciberseguridad desde Málaga · Redes, anzuelos y amenazas

← Amenazas
Técnica MITRE ATT&CK · Acceso a credenciales

T1003.003 NTDS

Subtécnica de T1003 OS Credential Dumping

Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in %SystemRoot%\NTDS\Ntds.dit of a domain controller.(Citation: Wikipedia Active Directory) In addition to looking…

Ficha en MITRE ATT&CK ↗

Quién la usa · con noticias en Jábega

Reglas Sigma para cazarla

Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.