For the complete documentation index, see llms.txt. This page is also available as Markdown.

NTDS.dit file written by an uncommon executable

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

OS Credential Dumping (T1003), OS Credential Dumping: NTDS (T1003.003)

Severity

Low

Description

The Active Directory database file was written by an uncommon process to a non-default location.

Attacker's Goals

Dump the sensitive contents of the database to masquerade as legitimate domain users.

Investigative actions

  • Investigate the nature of the process writing the sensitive file. Is it a standard backup procedure?

  • Check the path the file was written to. Is it local? Are there other relevant artifacts in this location?

Variations

NTDS.dit file written by a remote actor

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

OS Credential Dumping (T1003), OS Credential Dumping: NTDS (T1003.003)

Severity

High

Description

The Active Directory database file was written to the disk by a remote actor.

Attacker's Goals

Dump the sensitive contents of the database to masquerade as legitimate domain users.

Investigative actions

  • Investigate the nature of the process writing the sensitive file. Is it a standard backup procedure?

  • Check the path the file was written to. Is it local? Are there other relevant artifacts in this location?

NTDS.dit file written by a rare executable to a suspicious path

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

OS Credential Dumping (T1003), OS Credential Dumping: NTDS (T1003.003)

Severity

High

Description

The Active Directory database file was written by a rare process to a suspicious path.

Attacker's Goals

Dump the sensitive contents of the database to masquerade as legitimate domain users.

Investigative actions

  • Investigate the nature of the process writing the sensitive file. Is it a standard backup procedure?

  • Check the path the file was written to. Is it local? Are there other relevant artifacts in this location?

NTDS.dit file written by a rare executable

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

OS Credential Dumping (T1003), OS Credential Dumping: NTDS (T1003.003)

Severity

Medium

Description

The Active Directory database file was written by a rare process to a non-default location.

Attacker's Goals

Dump the sensitive contents of the database to masquerade as legitimate domain users.

Investigative actions

  • Investigate the nature of the process writing the sensitive file. Is it a standard backup procedure?

  • Check the path the file was written to. Is it local? Are there other relevant artifacts in this location?

Was this helpful?