Analytics BIOC
Low
✕
NTDS.dit file written by an uncommon executable
The Active Directory database file was written by an uncommon process to a non-default location.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003) OS Credential Dumping: NTDS (T1003.003)
Attacker's goals:
Dump the sensitive contents of the database to masquerade as legitimate domain users.
Investigative actions:
Investigate the nature of the process writing the sensitive file. Is it a standard backup procedure? Check the path the file was written to. Is it local? Are there other relevant artifacts in this location?
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
3 variations:
- NTDS.dit file written by a remote actor High (parent: Low)
- NTDS.dit file written by a rare executable to a suspicious path High (parent: Low)
- NTDS.dit file written by a rare executable Medium (parent: Low)