Cross-source coverage
T1003.003 / ATT&CK
OS Credential Dumping: NTDS
41 rules across 6 sources.
1 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in %SystemRoot%\NTDS\Ntds.dit of a domain controller.
In addition to looking for NTDS files on active Domain Controllers, adversaries may search for backups that contain the same or similar information.
The following tools and techniques can be used to enumerate the NTDS file and the contents of the entire Active Directory hashes.
- Volume Shadow Copy
- secretsdump.py
- Using the in-built Windows tool, ntdsutil.exe
- Invoke-NinjaCopy
- Tactics
- Credential Access
- Platforms
- Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:SysmonWinEventLog:Microsoft-Windows-VSS
How MITRE says to detect it DET0586
Detection of NTDS.dit Credential Dumping from Domain Controllers
Windows Analytic 1611
Detects credential dumping attempts targeting the NTDS.dit database by monitoring shadow copy creation, suspicious file access to %SystemRoot%\NTDS\ntds.dit, and the use of tooling like ntdsutil.exe or volume management APIs.
WinEventLog:SecurityEventCode=4688WinEventLog:SysmonEventCode=2WinEventLog:SysmonEventCode=11WinEventLog:Microsoft-Windows-VSSVolume Shadow Copy Creation
SigmaHQ/sigma
24 rules| Detection | Severity | Format |
|---|---|---|
| Potential Russian APT Credential Theft Activity | Critical | Sigma |
| Copying Sensitive Files with Credential Data | High | Sigma |
| Create Volume Shadow Copy with Powershell | High | Sigma |
| Cred Dump Tools Dropped Files | High | Sigma |
| NTDS.DIT Creation By Uncommon Parent Process | High | Sigma |
| NTDS.DIT Creation By Uncommon Process | High | Sigma |
| NTDS Exfiltration Filename Patterns | High | Sigma |
| Possible Impacket SecretDump Remote Activity | High | Sigma |
| Possible Impacket SecretDump Remote Activity - Zeek | High | Sigma |
| PUA - DIT Snapshot Viewer | High | Sigma |
+ 14 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
6 rules| Detection | Severity | Format |
|---|---|---|
| Creation or Modification of Domain Backup DPAPI private key | High | Elastic TOML |
| NTDS or SAM Database File Copied | High | Elastic TOML |
| Potential Credential Access via Windows Utilities | High | Elastic TOML |
| PowerShell Invoke-NinjaCopy script | High | Elastic TOML |
| NTDS Dump via Wbadmin | Medium | Elastic TOML |
| Symbolic Link to Shadow Copy Created | Medium | Elastic TOML |
splunk/security_content
6 rules| Detection | Severity | Format |
|---|---|---|
| Creation of Shadow Copy | Undefined | SPL |
| Creation of Shadow Copy with wmic and powershell | Undefined | SPL |
| Credential Dumping via Copy Command from Shadow Copy | Undefined | SPL |
| Credential Dumping via Symlink to Shadow Copy | Undefined | SPL |
| Ntdsutil Export NTDS | Undefined | SPL |
| SecretDumps Offline NTDS Dumping Tool | Undefined | SPL |
chronicle/detection-rules
2 rules| Detection | Severity | Format |
|---|---|---|
| rw_utilities_associated_with_ntdsdit_T1003_003 | High | YARA-L |
| wmic_ntds_dit_T1003_003_cisa_report | High | YARA-L |
elastic/protections-artifacts
2 rules| Detection | Severity | Format |
|---|---|---|
| Credential Access via Known Utilities | Undefined | Elastic TOML |
| Suspicious Access to Active Directory Database File | Undefined | Elastic TOML |
socfortress/Wazuh-Rules
1 rule| Detection | Severity | Format |
|---|---|---|
| Powershell script: Volume Shadow Copy access detected | High | Wazuh XML |