Ntdsutil Abuse

 Original Source: [Sigma source]
Title: Ntdsutil Abuse
Status: test
Description:Detects potential abuse of ntdsutil to dump ntds.dit database
References:
  -https://twitter.com/mgreen27/status/1558223256704122882
  -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/jj574207(v=ws.11)
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-14
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.003'
Logsource:
  • product: windows
  • service: application
Detection:
  selection:
    Provider_Name: 'ESENT'
    EventID:
      -'216'
      -'325'
      -'326'
      -'327'

    Data|contains: 'ntds.dit'
  condition:selection
Falsepositives:
  -Legitimate backup operation/creating shadow copies
Level: medium