Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • NTDS.dit file written by an uncommon executable Low 3 variations

    The Active Directory database file was written by an uncommon process to a non-default location.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: OS Credential Dumping (T1003) OS Credential Dumping: NTDS (T1003.003)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Dump the sensitive contents of the database to masquerade as legitimate domain users.
    Investigative actions: Investigate the nature of the process writing the sensitive file. Is it a standard backup procedure? Check the path the file was written to. Is it local? Are there other relevant artifacts in this location?

    Variations

    NTDS.dit file written by a remote actor

    High overridden

    The Active Directory database file was written to the disk by a remote actor. overridden

    NTDS.dit file written by a rare executable to a suspicious path

    High overridden

    The Active Directory database file was written by a rare process to a suspicious path. overridden

    NTDS.dit file written by a rare executable

    Medium overridden

    The Active Directory database file was written by a rare process to a non-default location. overridden