Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0586 — Detection of NTDS.dit Credential Dumping from Domain Controllers
DET0586

Detection of NTDS.dit Credential Dumping from Domain Controllers

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1611 Analytic 1611
Windows

Detects credential dumping attempts targeting the NTDS.dit database by monitoring shadow copy creation, suspicious file access to %SystemRoot%\NTDS\ntds.dit, and the use of tooling like ntdsutil.exe or volume management APIs.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=2 WinEventLog:Sysmon EventCode=11 WinEventLog:Microsoft-Windows-VSS Volume Shadow Copy Creation
[TargetFilePath] Tunable for NTDS file location or backup paths if organization uses custom domain controller storage structure.
[ParentProcessName] Can suppress backup-related parent processes to reduce false positives.
[TimeWindow] Temporal correlation between shadow copy creation and NTDS file access (e.g., 5 min window).
[UserContext] Tune based on expected privileged user/service account behavior.

Detected Techniques

1

Credential Access (1)

Details

MITRE ID
DET0586
STIX ID
x-mitre-detection-strategy--a97fe87f-e9be-4f71-8530-af5d70eaddf3
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.