AN1611
Analytic 1611
Windows
Detects credential dumping attempts targeting the NTDS.dit database by monitoring shadow copy creation, suspicious file access to %SystemRoot%\NTDS\ntds.dit, and the use of tooling like ntdsutil.exe or volume management APIs.
WinEventLog:Security
EventCode=4688
WinEventLog:Sysmon
EventCode=2
WinEventLog:Sysmon
EventCode=11
WinEventLog:Microsoft-Windows-VSS
Volume Shadow Copy Creation
[TargetFilePath]
Tunable for NTDS file location or backup paths if organization uses custom domain controller storage structure.
[ParentProcessName]
Can suppress backup-related parent processes to reduce false positives.
[TimeWindow]
Temporal correlation between shadow copy creation and NTDS file access (e.g., 5 min window).
[UserContext]
Tune based on expected privileged user/service account behavior.