Skip to content

Hide Navigation Hide TOC

NTDS.DIT Creation By Uncommon Parent Process (4e7050dd-e548-483f-b7d6-527ab4fa784d)

Detects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon parent process or directory

Cluster A Galaxy A Cluster B Galaxy B Level
NTDS - T1003.003 (edf91964-b26e-4b4a-9600-ccacd7d7df24) Attack Pattern NTDS.DIT Creation By Uncommon Parent Process (4e7050dd-e548-483f-b7d6-527ab4fa784d) Sigma-Rules 1
NTDS - T1003.003 (edf91964-b26e-4b4a-9600-ccacd7d7df24) Attack Pattern OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) Attack Pattern 2