Suspicious Usage Of Active Directory Diagnostic Tool (ntdsutil.exe)

 Original Source: [Sigma source]
Title: Suspicious Usage Of Active Directory Diagnostic Tool (ntdsutil.exe)
Status: test
Description:Detects execution of ntdsutil.exe to perform different actions such as restoring snapshots...etc.
References:
  -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731620(v=ws.11)
  -https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-09-14
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\ntdsutil.exe' OriginalFileName:'ntdsutil.exe'   selection_cli:
    - CommandLine|contains|all:
      - 'snapshot'
      - 'mount '
    - CommandLine|contains|all:
      - 'ac'
      - ' i'
      - ' ntds'
  condition:all of selection_*
Falsepositives:
  -Legitimate usage to restore snapshots
  -Legitimate admin activity
Level: medium