NTDS.dit file written by an uncommon executable
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
OS Credential Dumping (T1003), OS Credential Dumping: NTDS (T1003.003)
Severity
Low
Description
The Active Directory database file was written by an uncommon process to a non-default location.
Attacker's Goals
Dump the sensitive contents of the database to masquerade as legitimate domain users.
Investigative actions
Investigate the nature of the process writing the sensitive file. Is it a standard backup procedure?
Check the path the file was written to. Is it local? Are there other relevant artifacts in this location?
Variations
Was this helpful?
