Analytics BIOC Low

NTDS.dit file written by an uncommon executable

The Active Directory database file was written by an uncommon process to a non-default location.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003) OS Credential Dumping: NTDS (T1003.003)
Attacker's goals:

Dump the sensitive contents of the database to masquerade as legitimate domain users.

Investigative actions:

Investigate the nature of the process writing the sensitive file. Is it a standard backup procedure? Check the path the file was written to. Is it local? Are there other relevant artifacts in this location?

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • NTDS.dit file written by a remote actor High (parent: Low)
  • NTDS.dit file written by a rare executable to a suspicious path High (parent: Low)
  • NTDS.dit file written by a rare executable Medium (parent: Low)