1200KM / simulation
T1003.003 NTDS — Attack Simulation
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in %SystemRoot%\NTDS\Ntds.dit of a domain controller. In addition to looking for NTDS files on active Domain Controllers, adversaries may search for backups that…
Technique description
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in %SystemRoot%\NTDS\Ntds.dit of a domain controller. In addition to looking for NTDS files on active Domain Controllers, adversaries may search for backups that…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Create Symlink to Volume Shadow Copy
Procedure 21748c28-2793-4284-9e07-d6d028b66702; elevation required; cleanup not declared. Not executed or individually validated.
- Create Volume Shadow Copy remotely (WMI) with esentutl
Procedure 21c7bf80-3e8b-40fa-8f9d-f5b194ff2865; elevation required; cleanup not declared. Not executed or individually validated.
- Create Volume Shadow Copy with WMI
Procedure 224f7de0-8f0a-4a94-b5d8-989b036c86da; elevation required; cleanup not declared. Not executed or individually validated.
- Dump Active Directory Database with NTDSUtil
Procedure 2364e33d-ceab-4641-8468-bfb1d7cc2723; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create Volume Shadow Copy with Powershell
Procedure 542bb97e-da53-436b-8e43-e0a7d31a6c24; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create Volume Shadow Copy with diskshadow
Procedure b385996c-0e7d-4e27-95a4-aca046b119a7; elevation required; cleanup not declared. Not executed or individually validated.
- Copy NTDS.dit from Volume Shadow Copy
Procedure c6237146-9ea6-4711-85c9-c56d263a6b03; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Copy NTDS in low level NTFS acquisition via fsutil
Procedure c7be89f7-5d06-4321-9f90-8676a77e0502; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create Volume Shadow Copy remotely with WMI
Procedure d893459f-71f0-484d-9808-ec83b2b64226; elevation required; cleanup not declared. Not executed or individually validated.
- Create Volume Shadow Copy with vssadmin
Procedure dcebead7-6c28-4b4b-bf3c-79deb1b1fc7f; elevation required; cleanup not declared. Not executed or individually validated.
- Copy NTDS in low level NTFS acquisition via MFT parsing
Procedure f57cb283-c131-4e2f-8a6c-363d575748b2; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Sandworm Team · G0034
- Dragonfly · G0035
- FIN6 · G0037
- menuPass · G0045
- APT41 · G0096
- Wizard Spider · G0102
- Chimera · G0114
- Fox Kitten · G0117
- HAFNIUM · G0125
- Mustang Panda · G0129
- LAPSUS$ · G1004
- Scattered Spider · G1015
- FIN13 · G1016
- Volt Typhoon · G1017
- Medusa Group · G1051
- MirrorFace · G1054
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.