1200KM / detection
T1003.003 NTDS — Detection Rules
Detection workspace for T1003.003 NTDS: 23 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Possible Impacket SecretDump Remote Activity - Zeek · test · high · {"product":"zeek","service":"smb_files"}
- Transferring Files with Credential Data via Network Shares - Zeek · test · medium · {"product":"zeek","service":"smb_files"}
- Ntdsutil Abuse · test · medium · {"product":"windows","service":"application"}
- Possible Impacket SecretDump Remote Activity · test · high · {"product":"windows","service":"security","definition":"The advanced audit policy setting \"Object Access > Audit Detailed File Share\" must be configured for Success/Failure"}
- Transferring Files with Credential Data via Network Shares · test · medium · {"product":"windows","service":"security"}
- Cred Dump Tools Dropped Files · test · high · {"category":"file_event","product":"windows"}
- NTDS.DIT Created · test · low · {"product":"windows","category":"file_event"}
- NTDS.DIT Creation By Uncommon Parent Process · test · high · {"product":"windows","category":"file_event","definition":"Requirements: The \"ParentImage\" field is not available by default on EID 11 of Sysmon logs. To be able to use this rule to the full extent you need to enrich the log with additional ParentImage data"}
- NTDS.DIT Creation By Uncommon Process · test · high · {"product":"windows","category":"file_event"}
- NTDS Exfiltration Filename Patterns · test · high · {"product":"windows","category":"file_event"}
- Suspicious Get-ADDBAccount Usage · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Create Volume Shadow Copy with Powershell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- VolumeShadowCopy Symlink Creation Via Mklink · stable · high · {"category":"process_creation","product":"windows"}
- Esentutl Gather Credentials · test · medium · {"category":"process_creation","product":"windows"}
- Copying Sensitive Files with Credential Data · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Usage Of Active Directory Diagnostic Tool (ntdsutil.exe) · test · medium · {"category":"process_creation","product":"windows"}
- Invocation of Active Directory Diagnostic Tool (ntdsutil.exe) · test · medium · {"category":"process_creation","product":"windows"}
- Sensitive File Dump Via Print.EXE · test · high · {"category":"process_creation","product":"windows"}
- PUA - DIT Snapshot Viewer · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Process Patterns NTDS.DIT Exfil · test · high · {"product":"windows","category":"process_creation"}
- Shadow Copies Creation Using Operating Systems Utilities · test · medium · {"category":"process_creation","product":"windows"}
- Sensitive File Dump Via Wbadmin.EXE · test · high · {"category":"process_creation","product":"windows"}
- Sensitive File Recovery From Backup Via Wbadmin.EXE · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0586 Detection of NTDS.dit Credential Dumping from Domain Controllers
AN1611 Analytic 1611
Detects credential dumping attempts targeting the NTDS.dit database by monitoring shadow copy creation, suspicious file access to %SystemRoot%\NTDS\ntds.dit, and the use of tooling like ntdsutil.exe or volume management APIs.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Sandworm Team · G0034
- Dragonfly · G0035
- FIN6 · G0037
- menuPass · G0045
- APT41 · G0096
- Wizard Spider · G0102
- Chimera · G0114
- Fox Kitten · G0117
- HAFNIUM · G0125
- Mustang Panda · G0129
- LAPSUS$ · G1004
- Scattered Spider · G1015
- FIN13 · G1016
- Volt Typhoon · G1017
- Medusa Group · G1051
- MirrorFace · G1054
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.