Cross-source coverage

T1003.003 / ATT&CK

OS Credential Dumping: NTDS

41 rules across 6 sources.

1 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in %SystemRoot%\NTDS\Ntds.dit of a domain controller.

In addition to looking for NTDS files on active Domain Controllers, adversaries may search for backups that contain the same or similar information.

The following tools and techniques can be used to enumerate the NTDS file and the contents of the entire Active Directory hashes.

  • Volume Shadow Copy
  • secretsdump.py
  • Using the in-built Windows tool, ntdsutil.exe
  • Invoke-NinjaCopy
Platforms
Windows
Telemetry
WinEventLog:SecurityWinEventLog:SysmonWinEventLog:Microsoft-Windows-VSS

How MITRE says to detect it DET0586

Detection of NTDS.dit Credential Dumping from Domain Controllers

Windows Analytic 1611

Detects credential dumping attempts targeting the NTDS.dit database by monitoring shadow copy creation, suspicious file access to %SystemRoot%\NTDS\ntds.dit, and the use of tooling like ntdsutil.exe or volume management APIs.

  • WinEventLog:Security EventCode=4688
  • WinEventLog:Sysmon EventCode=2
  • WinEventLog:Sysmon EventCode=11
  • WinEventLog:Microsoft-Windows-VSS Volume Shadow Copy Creation

SigmaHQ/sigma

24 rules
Detection Severity Format
Potential Russian APT Credential Theft Activity Critical Sigma
Copying Sensitive Files with Credential Data High Sigma
Create Volume Shadow Copy with Powershell High Sigma
Cred Dump Tools Dropped Files High Sigma
NTDS.DIT Creation By Uncommon Parent Process High Sigma
NTDS.DIT Creation By Uncommon Process High Sigma
NTDS Exfiltration Filename Patterns High Sigma
Possible Impacket SecretDump Remote Activity High Sigma
Possible Impacket SecretDump Remote Activity - Zeek High Sigma
PUA - DIT Snapshot Viewer High Sigma

+ 14 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

6 rules
Detection Severity Format
Creation or Modification of Domain Backup DPAPI private key High Elastic TOML
NTDS or SAM Database File Copied High Elastic TOML
Potential Credential Access via Windows Utilities High Elastic TOML
PowerShell Invoke-NinjaCopy script High Elastic TOML
NTDS Dump via Wbadmin Medium Elastic TOML
Symbolic Link to Shadow Copy Created Medium Elastic TOML

splunk/security_content

6 rules
Detection Severity Format
Creation of Shadow Copy Undefined SPL
Creation of Shadow Copy with wmic and powershell Undefined SPL
Credential Dumping via Copy Command from Shadow Copy Undefined SPL
Credential Dumping via Symlink to Shadow Copy Undefined SPL
Ntdsutil Export NTDS Undefined SPL
SecretDumps Offline NTDS Dumping Tool Undefined SPL

chronicle/detection-rules

2 rules
Detection Severity Format
rw_utilities_associated_with_ntdsdit_T1003_003 High YARA-L
wmic_ntds_dit_T1003_003_cisa_report High YARA-L

elastic/protections-artifacts

2 rules
Detection Severity Format
Credential Access via Known Utilities Undefined Elastic TOML
Suspicious Access to Active Directory Database File Undefined Elastic TOML

socfortress/Wazuh-Rules

1 rule
Detection Severity Format
Powershell script: Volume Shadow Copy access detected High Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.