Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapNTDS.dit file written by an uncommon executable Low 3 variations
The Active Directory database file was written by an uncommon process to a non-default location.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: OS Credential Dumping (T1003) OS Credential Dumping: NTDS (T1003.003)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Dump the sensitive contents of the database to masquerade as legitimate domain users.Investigative actions: Investigate the nature of the process writing the sensitive file. Is it a standard backup procedure? Check the path the file was written to. Is it local? Are there other relevant artifacts in this location?Variations
NTDS.dit file written by a remote actor
High overridden
The Active Directory database file was written to the disk by a remote actor. overridden
NTDS.dit file written by a rare executable to a suspicious path
High overridden
The Active Directory database file was written by a rare process to a suspicious path. overridden
NTDS.dit file written by a rare executable
Medium overridden
The Active Directory database file was written by a rare process to a non-default location. overridden